Microsoft, Apple, Google, Mozilla, Oracle Release Major Security Patches—118 CVEs Fixed on Patch Tuesday
Patch all Windows Server 2012+ to fix CVE‑2026‑41089, CVE‑2026‑41096, CVE‑2026‑41103; update Chrome to the latest build to resolve 127 CVEs; back up data before applying any vendor patches.
Patch all Windows Server 2012+ to address CVE‑2026‑41089, CVE‑2026‑41096, CVE‑2026‑41103; update Chrome to the latest build; back up data before applying any vendor patches.
Summary
Microsoft’s Patch Tuesday released 118 security fixes, including 16 critical vulnerabilities, with no zero‑day or previously disclosed flaws—an anomaly for the first time in nearly two years. The critical CVEs include CVE‑2026‑41089, a stack‑based buffer overflow in Windows Netlogon that grants SYSTEM on domain controllers; CVE‑2026‑41096, a critical RCE in the Windows DNS client; and CVE‑2026‑41103, an elevation of privilege that lets attackers forge credentials to bypass Entra ID.
Apple shipped updates for 52 vulnerabilities, backporting fixes all the way to iPhone 6s and iOS 15. Mozilla’s Firefox 150 fixed 271 vulnerabilities discovered by Anthropic’s Project Glasswing and has moved to a weekly security cadence. Oracle addressed 450 flaws, 300 of which were remotely exploitable, and announced a monthly critical patch cycle. Google Chrome rolled out 127 CVEs, auto‑downloading updates that require a full browser restart.
Key changes
- Microsoft Patch Tuesday fixed 118 vulnerabilities, 16 critical, with no zero‑day or previously disclosed flaws
- CVE‑2026‑41089: stack‑based buffer overflow in Windows Netlogon grants SYSTEM on domain controllers, affecting Windows Server 2012+
- CVE‑2026‑41096: critical RCE in Windows DNS client, exploitation less likely but still critical
- CVE‑2026‑41103: elevation of privilege via forged credentials bypassing Entra ID, exploitation more likely
- Apple shipped 52 vulnerabilities, backported to iPhone 6s and iOS 15
- Mozilla Firefox 150 fixed 271 vulnerabilities discovered by Project Glasswing, now on weekly cadence
- Oracle addressed 450 flaws, 300 remotely exploitable, and switched to monthly critical patch cycle
- Google Chrome rolled out 127 CVEs, auto‑downloaded but requiring full browser restart