Home › Microsoft Patch Tuesday › May 2026

Microsoft Patch Tuesday, May 2026

·

Microsoft's May 2026 security release, published May 12, 2026: 69 updates fixing 100 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 1 CVE from this release is on the Senserva hot list today (as of 2026-09-27), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
69
Updates (KBs)
100
CVEs fixed
2
On the CISA KEV list
1
Ransomware-linked
19
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2026-45659Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 8.8ExploitedRansomware Hot now
CVE-2026-42897Microsoft Exchange Server Spoofing VulnerabilityCVSS 8.1Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2026-42898Microsoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityCVSS 9.9
CVE-2026-41089Windows Netlogon Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-41096Windows DNS Client Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-40402Windows Hyper-V Elevation of Privilege VulnerabilityCVSS 9.3
CVE-2026-42833Microsoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityCVSS 9.1
CVE-2026-33110Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2026-33112Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2026-35439Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2026-40357Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2026-40365Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8
CVE-2026-23669RPC Runtime Library Remote Code Execution VulnerabilityCVSS 8.8
CVE-2026-25177Active Directory Domain Services Elevation of Privilege VulnerabilityCVSS 8.8

Products fixed this month

Windows Server 2022 (3)Windows Server 2022 (Server Core installation) (3)Microsoft SharePoint Enterprise Server 2016 (2)Microsoft SharePoint Server 2019 (2)Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (2)Microsoft Office 2016 (32-bit edition) (2)Microsoft Office 2016 (64-bit edition) (2)Microsoft SharePoint Server Subscription Edition (1)Microsoft Exchange Server 2016 Cumulative Update 23 (1)Microsoft Exchange Server 2019 Cumulative Update 14 (1)

Every update in this release

All 59 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5002868 Exploited RansomwareHigh8.89Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002870 Exploited RansomwareHigh8.89Microsoft SharePoint Server 2019Support · Catalog
KB5002863 Exploited RansomwareHigh8.89Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5094144 ExploitedHigh8.11Microsoft Exchange Server 2016 Cumulative Update 23Support · Catalog
KB5094142 ExploitedHigh8.11Microsoft Exchange Server 2019 Cumulative Update 14Support · Catalog
KB5094140 ExploitedHigh8.11Microsoft Exchange Server 2019 Cumulative Update 15Support · Catalog
KB5094139 ExploitedHigh8.11Microsoft Exchange Server Subscription Edition RTMSupport · Catalog
KB5078943Critical9.93Microsoft Dynamics 365 (on-premises) version 9.1, Microsoft Dynamics 365 (on-premises) version 9.0Support · Catalog
KB5087538Critical9.855Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5087545Critical9.858Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5087420Critical9.856Windows 11 Version 23H2 for ARM64-based SystemsSupport · Catalog
KB5087541Critical9.858Windows Server 2022, 23H2 Edition (Server Core installation)Support · Catalog
KB5087424Critical9.856Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5087537Critical9.847Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016Support · Catalog
KB5087470Critical9.839Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5087471Critical9.842Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5078737High8.842Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5087544High8.854Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5089899High8.81Microsoft SQL Server 2025 for x64-based Systems (CU4)Support · Catalog
KB5089900High8.81Microsoft SQL Server 2022 for x64-based Systems (CU 24)Support · Catalog
KB5090347High8.81Microsoft SQL Server 2017 for x64-based Systems (GDR)Support · Catalog
KB5090408High8.81Microsoft SQL Server 2019 for x64-based Systems (GDR)Support · Catalog
KB5089271High8.81Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)Support · Catalog
KB5089270High8.81Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackSupport · Catalog
KB5090354High8.81Microsoft SQL Server 2017 for x64-based Systems (CU 31)Support · Catalog
KB5091158High8.81Microsoft SQL Server 2022 for x64-based Systems (GDR)Support · Catalog
KB5091223High8.81Microsoft SQL Server 2025 for x64-based Systems (GDR)Support · Catalog
KB5090407High8.81Microsoft SQL Server 2019 for x64-based Systems (CU 32)Support · Catalog
KB5002858High8.46Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)Support · Catalog
KB5002869High8.41Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002872High8.41Microsoft SharePoint Server 2019Support · Catalog
KB5002866High8.42Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002871High7.83Office Online ServerSupport · Catalog
KB5002865High7.83Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5093780High7.81Microsoft Dynamics 365 Business Central 2026 Release Wave 1Support · Catalog
KB5086069High7.81Microsoft Dynamics 365 Business Central Release Wave 1 2025Support · Catalog
KB5086070High7.81Microsoft Dynamics 365 Business Central Release Wave 2 2025Support · Catalog
KB5086068High7.81Microsoft Dynamics 365 Business Central 2024 Release Wave 2Support · Catalog
KB5093446High7.54.NET 10.0 installed on Windows, .NET 10.0 installed on Mac OS, .NET 10.0 installed on LinuxSupport · Catalog
KB5093447High7.54.NET 8.0 installed on Windows, .NET 8.0 installed on Mac OS, .NET 8.0 installed on LinuxSupport · Catalog
KB5093448High7.54.NET 9.0 installed on Windows, .NET 9.0 installed on Linux, .NET 9.0 installed on Mac OSSupport · Catalog
KB5087065High7.32Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016Support · Catalog
KB5087067High7.32Microsoft .NET Framework 4.8 on Windows Server 2012Support · Catalog
KB5087069High7.31Microsoft .NET Framework 4.8 on Windows Server 2012 R2Support · Catalog
KB5087066High7.32Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019Support · Catalog
KB5087068High7.32Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022Support · Catalog
KB5087064High7.32Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based SystemsSupport · Catalog
KB5087061High7.32Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019Support · Catalog
KB5087062High7.31Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012Support · Catalog
KB5087063High7.32Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2Support · Catalog
KB5087059High7.32Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022Support · Catalog
KB5087053High7.32Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 22H2 for ARM64-based SystemsSupport · Catalog
KB5087051High7.32Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025Support · Catalog
KB5087055High7.32Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 26H1 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 26H1 for ARM64-based SystemsSupport · Catalog
KB5087058High7.32Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based SystemsSupport · Catalog
KB5087054High7.32Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5087048High7.32Microsoft .NET Framework 3.5 on Windows Server 2012Support · Catalog
KB5087049High7.32Microsoft .NET Framework 3.5 on Windows Server 2012 R2Support · Catalog
KB5002578Medium6.71Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
Take this release to your AI

Composed from the May 2026 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.