Microsoft May 2026 Patch Tuesday — 137 CVEs, 31 Critical (16 RCE) Including CVE-2026-41089 Pre-Auth Netlogon Stack Overflow on Domain Controllers — Threadlinqs Intelligence
As of 2026-05-30, Microsoft May 2026 Patch Tuesday — 137 CVEs, 31 Critical (16 RCE) Including CVE-2026-41089 Pre-Auth Netlogon Stack Overflow on Domain Controllers is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0504 · Severity: HIGH · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Microsoft's May 2026 Patch Tuesday addresses 137 vulnerabilities (120 Microsoft-only per BleepingComputer after excluding Mariner/Azure/Copilot/Teams/Partner Center entries), with 31 rated Critical
## Patch Tuesday Composition
Microsoft's May 2026 security update batch resolves 137 unique CVEs across the Microsoft product portfolio. After filtering out Mariner Linux distribution, Azure dataplane, Copilot, Teams, and Partner Center advisories — the slice BleepingComputer counts separately — the core Microsoft surface accounts for 120 vulnerabilities. The severity composition is heavily weighted toward privilege escalation (61 EoP) but the operationally relevant slice for external defenders is the 31 Critical entries, 16 of which permit Remote Code Execution and a handful of which are reachable without authentication. Cisco Talos confirms that none of the disclosed vulnerabilities were observed in active exploitation at release, and Microsoft tagged no entries with Exploited:Yes in MSRC. This drops the immediate urgency below the historical 'pure CRITICAL' bar reserved for in-the-wild zero-days while preserving HIGH urgency due to the pre-auth Netlogon and DNS Client RCEs.
## CVE-2026-41089 — Netlogon Pre-Auth Stack Overflow (CRITICAL, CVSS 9.8)
A stack-based buffer overflow (CWE-121) in the Windows Netlogon service permits an unauthenticated network attacker to execute code on a Windows server operating as a domain controller via a specially crafted Netlogon network request. The flaw is structurally similar to the historical Zerologon (CVE-2020-1472) and Netlogon RPC family of issues that have repeatedly been weaponized for domain takeover. The CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H vector indicates a complete pre-auth network compromise primitive: any unauthenticated host with network reachability to the DC's RPC interface (typically tcp/445 SMB, tcp/135 EPM, tcp/49152-65535 dynamic RPC) can trigger the overflow. Stack overflows in lsass-hosted services on modern Windows still face mitigations (stack cookies/GS, CFG, ASLR, DEP), but successful exploitation results in code execution in the security context of the Netlogon service — effectively SYSTEM on the DC, equating to immediate Domain Admin equivalence. The Talos write-up explicitly highlights this as the headline flaw of the release. Cisco published Snort coverage in SIDs 1:66438-1:66445 and 1:66451-1:66460 (Snort 2) and 1:301494-1:301497 / 1:301500-1:301506 (Snort 3) covering the May batch network-protocol primitives, with overlapping detection logic for the Netlogon, DNS, and SharePoint RCEs.
## CVE-2026-41096 — Windows DNS Client Heap Overflow (CRITICAL, CVSS 9.8)
A heap-based buffer overflow (CWE-122) in the Windows DNS Client triggers when the client parses a maliciously crafted DNS response. The attack model: any system path that causes the target Windows host to perform a DNS resolution against an attacker-controlled or attacker-influenced authoritative server — including environments where DNS resolution can be coerced (link resolution in Office documents, MoTW-bypassing URLs, captive portals, attacker-poisoned LAN with rogue DHCP supplying a malicious DNS server) — results in heap corruption inside dnsapi/dnsrslvr code paths and unauthenticated code execution. Because the DNS Client is invoked transparently during virtually every networked operation, the exposure is exceptionally broad. Pre-auth network attack vector with no user interaction (AV:N/UI:N) and SYSTEM-level service host context elevate this to the same operational risk band as the Netlogon flaw, though exploitation requires the target to issue a DNS request the attacker can answer.
## CVE-2026-35421 — Windows GDI EMF Heap Overflow (CRITICAL, CVSS 7.8)
A heap-based buffer overflow (CWE-122) in the Windows GDI subsystem is reachable when a user opens or otherwise processes a specially crafted Enhanced Metafile (EMF) using Microsoft Paint. Local AV:L with UI:R reduces the headline CVSS, but EMF parsing surfaces also include the Explorer thumbnail pipeline and Office image insertion paths, broadening practical exposure beyond Paint. Successful exploitation grants code execution in the
Weaknesses (CWE)
CWE-121, CWE-122, CWE-416, CWE-362, CWE-94, CWE-843, CWE-822, CWE-1220, CWE-284, CWE-20
Target sectors: government, financial, healthcare, education, manufacturing, energy, retail, technology, critical-infrastructure, defense-industrial-base
Target regions: Global, North America, Europe, Asia Pacific, Latin America, Middle East
Related threats
- Microsoft's MDASH AI Scanning Harness Uncovers 16 Windows CVEs, Including Four Critical RCE Flaws in TCP/IP, IKEv2, Netlogon, and DNS
- Windows Netlogon 0-Click RCE CVE-2026-41089 — Active Exploitation in the Wild (Domain Controller Takeover)
- Microsoft April 2026 Patch Tuesday — 163 CVEs / 88 Advisories (CVE-2026-32201 SharePoint Zero-Day Exploited In-The-Wild, CVE-2026-33825 Defender EoP Public PoC, CVE-2026-33824 IKE RCE CVSS 9.8, CVE-2026-33827 TCP/IP Wormable RCE)
- Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164)
- Chrome 150 Security Update Fixes 15 Vulnerabilities Including Two Critical Use-After-Free Flaws in Ozone (CVE-2026-15764, CVE-2026-15765)
- BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege Dominates (CVE-2025-55241, CVE-2025-62557, CVE-2025-62554)
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-41089, CVE-2026-41096, CVE-2026-35421, CVE-2026-40365, CVE-2026-32161, CVE-2026-40403, CVE-2026-40402, CVE-2026-33109, CVE-2026-33844, CVE-2026-40358, T1595, T1590, T1587.004, T1588.005, T1190, T1133, T1566.001, T1566.002, T1203, T1204.002