Articles from May 2026
Browse all Windows news articles published in May 2026
CVE-2026-41088: Microsoft Patches AFD.sys Elevation of Privilege Vulnerability in May 2026 Patch Tuesday
Microsoft shipped a security update on May 12, 2026, to plug a local elevation-of-privilege hole in the Windows Ancillary Function Driver for Winsock (AFD.sys). The vulnerability, tracked as...
Microsoft Word Flaw CVE-2026-40421: Why It’s More Dangerous Than It Looks and How to Fix It
On May 12, 2026, Microsoft disclosed a new information disclosure vulnerability in Word, tracked as CVE-2026-40421, that could allow attackers to read sensitive data from documents. The company has...
Microsoft Confirms Business Central Weak Authentication Bug; ERP Admins Must Patch to Block SYSTEM Takeover
Microsoft published a security advisory on May 12, 2026, confirming an elevation-of-privilege vulnerability in Dynamics 365 Business Central that lets a low‑privileged local attacker gain full...
Microsoft Patches Office Flaw That Could Let Attackers Seize Full Windows Control
Microsoft disclosed on May 12, 2026, that a vulnerability in the Office Click-To-Run service could hand a low-privileged attacker complete control of a Windows machine. The flaw, tracked as...
CVE-2026-40415: Patch Critical Windows TCP/IP RCE Flaw Now
Microsoft disclosed a critical remote code execution vulnerability in the Windows TCP/IP stack on May 12, 2026, assigned CVE-2026-40415. The flaw, detailed in the monthly Security Update Guide, sits...
CVE-2026-40414: Microsoft Fixes Important TCP/IP Null Pointer DoS Flaw in May 2026 Patch Tuesday
Microsoft's May 2026 Patch Tuesday landed with a notable fix for CVE-2026-40414, an Important-rated denial-of-service vulnerability in the Windows TCP/IP stack. The flaw, caused by a NULL pointer...
CVE-2026-40410: Critical Windows SMB Client Use-After-Free Privilege Escalation Flaw Patched
Microsoft has released an emergency security update to address a newly discovered elevation-of-privilege vulnerability in the Windows SMB Client, tracked as CVE-2026-40410. Rated Important with a...
Windows WAN ARP Driver Use-After-Free Flaw Grants SYSTEM Access
Microsoft disclosed CVE-2026-40408 on May 12, 2026, as part of its monthly Patch Tuesday security updates. This Important-rated elevation-of-privilege vulnerability resides in the Windows WAN ARP...
Windows CLFS Zero-Day Gets Critical Patch: May 2026 Tuesday Fix Now Live
Microsoft's May 2026 Patch Tuesday brought a fix for CVE-2026-40407, a local privilege escalation vulnerability in the Windows Common Log File System (CLFS) driver. The flaw, rated Important, allows...
Patch now: Windows 11 and Server 2025 crash risk from single TCP/IP packet
Microsoft’s May 2026 Patch Tuesday brought a fix for a critical denial-of-service vulnerability in the Windows TCP/IP stack that could allow unauthenticated attackers to crash affected systems with...
CVE-2026-40406 Windows TCP/IP Leak: Patch Now Despite Sparse Details
Microsoft's Security Response Center (MSRC) dropped a brief advisory on May 12, 2026, for CVE-2026-40406, an information disclosure vulnerability buried in the Windows TCP/IP stack. Details are...
Patch Now: CVE-2026-40399 Windows TCP/IP Flaw Grants SYSTEM Access
Microsoft’s May 2026 Patch Tuesday release includes a fix for CVE-2026-40399, a local elevation-of-privilege vulnerability in the Windows TCP/IP stack rated Important with a CVSS 3.1 score of 7.8....