
Microsoft on Tuesday released patches for 138 security vulnerabilities spanning its product portfolio, although none of them have been listed as publicly known or under active attack.
Of the 138 flaws, 30 are rated Critical, 104 are rated Important, three are rated Moderate, and one is rated Low in severity. As many as 61 vulnerabilities are classified as privilege escalation bugs, followed by 32 remote code execution, 15 information disclosure, 14 spoofing, eight denial-of-service, six security feature bypass, and two tampering flaws.
The update list also includes a vulnerability that was patched by AMD (CVE-2025-54518, CVSS score: 7.3) this month. It relates to a case of improper isolation of shared resources within the CPU operation cache on Zen 2-based products that could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
The patches are also in addition to 127 security flaws that Google has addressed in Chromium, which forms the basis for Microsoft’s Edge browser.
One of the most severe vulnerabilities patched by Redmond is CVE-2026-41096 (CVSS score: 9.8), a heap-based buffer overflow flaw impacting Windows DNS that could allow an unauthorized attacker to execute code over a network.
“An attacker could exploit this vulnerability by sending a specially crafted DNS response to a vulnerable Windows system, causing the DNS Client to incorrectly process the response and corrupt memory,” Microsoft said. “In certain configurations, this could allow the attacker to run code remotely on the affected system without authentication.”
Also fixed by Microsoft are several Critical- and Important-rated flaws –
“This critical elevation of privilege vulnerability allows an unauthorized attacker to impersonate an existing user by presenting forged credentials, thus bypassing Entra ID,” Adam Barnett, lead software engineer at Rapid7, said about CVE-2026-41103.
Jack Bicer, director of vulnerability research at Action1, described CVE-2026-42898 as a critical flaw that allows an authenticated attacker with low privileges to run arbitrary code over the network by manipulating process session data within Dynamics CRM.
“With no user interaction required, and the potential to impact systems beyond the vulnerable component’s original security scope, this vulnerability poses serious enterprise risk: an attacker with only basic access could turn a business application server into a remote execution platform,” Bicer said.
“Compromise of Dynamics 365 infrastructure can expose customer records, operational workflows, financial information, and integrated business systems. Since CRM environments often connect with identity services, databases, and enterprise applications, successful exploitation could lead to broader organizational compromise and operational disruption.”
Organizations are also advised to update Windows Secure Boot certificates to their 2023 counterparts ahead of next month, when the 2011-issued certificates are set to expire. Microsoft first announced the change in November 2025.
“The most critical non-CVE update involves the mandatory rollout of updated Secure Boot certificates,” Rain Baker, senior incident response specialist at Nightwing, said. “Devices failing to receive these updates before the June 26 deadline face ‘catastrophic boot-level security failures’ or degraded security states. Ensure your entire fleet successfully rotates to the new trust anchors before the June 26, 2026, deadline.”
According to Satnam Narang, senior staff research engineer at Tenable, Microsoft has already patched over 500 CVEs five months into the year. This large volume of fixes reflects a broader industry trend where vulnerability discovery has scaled new highs, with a chunk of them flagged via artificial intelligence (AI)-powered approaches.
Microsoft, in a report published Tuesday, said AI-assisted vulnerability discovery is expected to increase the scale of Patch Tuesday releases in the coming months, adding 16 of the flaws fixed this month across the Windows networking and authentication stack were identified through its new multi-model AI-driven vulnerability discovery system, codenamed MDASH (short for multi-model agentic scanning harness).
“In this month’s release, a greater share of the issues addressed were discovered by Microsoft, compared to prior months,” Tom Gallagher, vice president of engineering at Microsoft Security Response Center, said. “Many of these were surfaced through AI investments and investigations across our engineering and research teams, including the use of Microsoft’s new multi-model AI-driven scanning harness.”
Microsoft also emphasized that the scale and speed of vulnerability discovery brought about by AI can raise operational demands and requires a consistent, disciplined approach to risk management in order to ensure that issues are mitigated quickly and fixed in a timely fashion.
“Stay current on supported operating systems, products, and patches, and revisit the speed and consistency of your patching cadence,” Gallagher said. “Triage by exposure and impact, not raw count.”
Other recommendations outlined by Microsoft include reducing unnecessary internet exposure, improving configuration hygiene, removing legacy authentication, enabling multi-factor authentication (MFA), enforcing strong access controls, segmenting environments to contain incidents, and investing in detection and response.
“The work of finding and fixing vulnerabilities continues to get faster, broader, and more rigorous across the industry,” the tech giant said. “What we encourage in turn is a thoughtful look at whether the practices that worked well for the patching landscape of a few years ago are still well matched to where the landscape is heading.”
“The fundamentals have not changed. The pace at which they need to be applied is changing, and the organizations that adjust with it will be the ones best positioned for what comes next.”
#138 #and #dns #flaws #including #microsoft #netlogon #news #patches #rce #vulnerabilities — News
© Bulletproof Servers. All rights reserved.