Summary

Microsoft’s May 2026 Patch Tuesday addresses 118 vulnerabilities across its product ecosystem, with 16 rated critical and 102 rated important. The update includes fixes for remote code execution, privilege escalation, and authentication bypass flaws spanning Windows, Exchange, Dynamics 365, and enterprise integrations.

The most severe vulnerability is CVE-2026-41089, a critical remote code execution flaw in the Windows Netlogon component carrying a CVSS score of 9.8. This vulnerability affects servers acting as domain controllers and could allow an unauthenticated attacker to execute arbitrary code on the domain controller — effectively handing over the keys to an entire Active Directory environment.

Other critical fixes include CVE-2026-41096, a Windows DNS Client RCE exploitable via specially crafted DNS responses; CVE-2026-41103, an elevation of privilege bug in Microsoft’s SSO Plugin for Jira and Confluence that could bypass authentication entirely; and CVE-2026-42898, a critical RCE in Dynamics 365 on-premise version 9.1.

Sources

Commentary

The Netlogon RCE at CVSS 9.8 is the headline here, and for good reason. Domain controllers are the crown jewels of any Windows enterprise environment. An unauthenticated RCE against Netlogon is reminiscent of Zerologon (CVE-2020-1472), and organizations should be treating this with the same urgency — patch immediately, no exceptions.

The SSO Plugin vulnerability for Jira and Confluence is also worth highlighting because it targets the exact integration points that development and operations teams rely on daily. An authentication bypass in these tools could give an attacker lateral movement into CI/CD pipelines, source code repositories, and internal documentation. Combined with the Chaotic Eclipse zero-day drops that landed right after this Patch Tuesday, May 2026 is shaping up to be one of the most hostile months for Windows administrators in recent memory.

By Allan