{"id":61102,"date":"2026-06-27T05:16:20","date_gmt":"2026-06-27T09:16:20","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=61102"},"modified":"2026-06-27T05:16:20","modified_gmt":"2026-06-27T09:16:20","slug":"may-patch-tuesday-record-vulnerabilities","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/may-patch-tuesday-record-vulnerabilities\/","title":{"rendered":"May Patch Tuesday Fixes Record 1,018 Security Vulnerabilities"},"content":{"rendered":"<p><a href=\"https:\/\/overcentral.com\/en\/chaos-piece-may-2026-codes\/\" title=\"Chaos Piece Drops May 2026 Codes with Revamp &amp; 2x Gems\" data-iacss-internal=\"1\">May 2026<\/a> Patch Tuesday shattered records across the software industry, with major vendors including Microsoft, Apple, Google, Mozilla, and <a href=\"https:\/\/overcentral.com\/en\/oracle-peoplesoft-shinyhunters-zero-day\/\" title=\"Oracle confirms PeopleSoft zero-day exploited by ShinyHunters\" data-iacss-internal=\"1\">Oracle<\/a> releasing updates that collectively address more than 1,018 security vulnerabilities. The unprecedented volume of fixes is being attributed in large part to <a href=\"https:\/\/www.anthropic.com\/research\/project-glasswing\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Project Glasswing<\/a>, an artificial intelligence system developed by Anthropic that has proven remarkably effective at unearthing flaws in human-written code.<\/p>\n<p>Microsoft led the monthly update cycle with patches for at least 118 vulnerabilities across Windows and its product ecosystem. Notably, this is the first Patch Tuesday in nearly two years that does not include any fixes for actively exploited zero-day flaws, nor any previously disclosed vulnerabilities that could give attackers a head start. Sixteen of the bugs received Microsoft&#8217;s most severe &#8220;critical&#8221; rating, meaning they can be exploited remotely with minimal user interaction. Among the most concerning is <strong>CVE-2026-41089<\/strong>, a critical stack-based buffer overflow in Windows Netlogon that grants an attacker SYSTEM privileges on domain controllers without requiring authentication or user interaction. The flaw affects all Windows Server versions from 2012 onward. Also critical is <strong>CVE-2026-41096<\/strong>, a <a href=\"https:\/\/overcentral.com\/en\/splunk-critical-rce-bug\/\" title=\"Critical Splunk Enterprise Bug Allows Unauthenticated Remote Code Execution\" data-iacss-internal=\"1\">remote code execution<\/a> vulnerability in the Windows DNS client, and <strong>CVE-2026-41103<\/strong>, an elevation of privilege bug that Microsoft expects will be actively exploited because it allows an unauthorized attacker to bypass Entra ID by presenting forged credentials.<\/p>\n<h2>Apple, Mozilla, and Google Follow With Record Patch Volumes<\/h2>\n<p>Apple shipped updates on May 11 addressing at least 52 vulnerabilities, notably backporting fixes to devices as old as the iPhone 6s running iOS 15. This more than doubles the company&#8217;s typical monthly average of around 20 security patches for iOS. Mozilla&#8217;s Firefox 150 release resolved a stunning 271 vulnerabilities, the majority of which were discovered during the Project Glasswing evaluation. Since that release, Mozilla has maintained an aggressive weekly cadence for security updates, with Firefox 150.0.3 arriving on Patch Tuesday itself and addressing between three and five CVEs per release. Google rolled out Chrome updates on May 8 that fixed 127 security flaws, up sharply from just 30 the previous month. Chrome downloads updates automatically, but a full browser restart is required to apply them.<\/p>\n<h2>Oracle Accelerates Patch Cycle<\/h2>\n<p>Oracle, another Project Glasswing participant, addressed more than 450 flaws in its most recent quarterly patch update, including over 300 remotely exploitable, unauthenticated vulnerabilities. In response to the surge of findings, Oracle announced at the end of April that it will now issue security updates on a monthly cadence for critical issues, rather than its traditional quarterly schedule. This shift mirrors the broader industry trend toward faster patch cycles driven by AI-assisted vulnerability discovery.<\/p>\n<p>May&#8217;s Patch Tuesday marks a welcome reprieve from April, when Microsoft alone fixed a near-record 167 security flaws. The combined volume across all major vendors this month underscores the transformative impact of AI on vulnerability research. While Project Glasswing is still in limited preview, its ability to surface flaws at scale is already reshaping how the industry approaches patch management.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>Users across the US, UK, Australia, and Canada should prioritize installing updates from all affected vendors without delay. For Windows users, that means checking Windows Update or using enterprise management tools to deploy the May 2026 patches. Chrome and Firefox users should restart their browsers to complete automatic updates. Apple device owners should navigate to Settings &gt; General &gt; Software Update and apply the latest iOS or macOS release. Organizations relying on Oracle products should begin evaluating the April quarterly update and prepare for the new monthly cadence going forward. As always, back up critical data and system images before applying patches, and verify that endpoint protection software is active and updated. For a detailed list of the Microsoft updates released today, consult the <a href=\"https:\/\/isc.sans.edu\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">SANS Internet Storm Center<\/a> inventory. Readers encountering issues with any of these updates are encouraged to report them so the community can track installation problems effectively.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>May 2026 Patch Tuesday shattered records across the software industry, with major vendors including Microsoft, Apple, Google, Mozilla, and Oracle releasing updates that collectively address more than 1,018 security vulnerabilities. The unprecedented volume of fixes is being attributed in large part to Project Glasswing, an artificial intelligence system developed by Anthropic that has proven remarkably [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":85132,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/61102.png","fifu_image_alt":"May Patch Tuesday Fixes Record 1,018 Security Vulnerabilities","footnotes":""},"categories":[349],"tags":[],"class_list":["post-61102","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/61102.png","fifu_image_alt":"May Patch Tuesday Fixes Record 1,018 Security Vulnerabilities","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/61102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=61102"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/61102\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/85132"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=61102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=61102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=61102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}