Patch Tuesday May 2026: what Microsoft shipped
Microsoft published its security updates on Tuesday, 12 May 2026.
On the day, the briefing reads Microsoft's advisories and this page lists what carried a flag. It stays here afterwards as the record.
Which flaws were flagged?
3 flagged by Microsoft as exploited at release.
3 flagged by Microsoft as publicly disclosed.
4 are in the CISA KEV catalog.
- CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability Exploited at release · Publicly disclosed · In KEV
- CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability Exploited at release · Publicly disclosed · In KEV
- CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability Exploited at release · In KEV
- CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability Publicly disclosed
- CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability In KEV
What PlainSec published
What the last cycles held
April 2026: 3 flagged.
March 2026: 2 flagged.
February 2026: 6 flagged.
We hold 12 CVEs from Microsoft's 2026-May document. That is what our records reach, not the size of the release: it grows for weeks after the day.