TLP:CLEAR
Microsoft May 2026 Threat & Deployment BriefZero-Day-Free, Wormable Netlogon 9.8, Structural Risk

May is the year's only zero-day-free Patch Tuesday so far — yet deploy the Windows client and server cumulative on an emergency change anyway, for two unauthenticated CVSS-9.8 remote-code-execution bugs: a wormable Netlogon flaw on domain controllers (CVE-2026-41089) and a DNS Client flaw (CVE-2026-41096).

Deploy first
Windows client and server monthly security update
Act units
1
Release
Microsoft 2026-05-12
CVEs
118–138 (by counter)
KEV read
2026-07-17
Report
ITS-EXV-2026-0512

Zero exploitation is not zero urgency — that is the whole lesson of this cycle. No May CVE was exploited or publicly disclosed at release (the first zero-day-free month since June 2024, confirmed against the primary MSRC source and six counters). And yet the Windows cumulative is still an Act / 72-hour change, because two unauthenticated 9.8 remote-code-execution flaws pass the structural gate. Absence of an attacker today does not lower a wormable, pre-authentication remote hole.

CVE-2026-41089 — Netlogon RCE, 9.8, wormable on domain controllers. An unauthenticated attacker (AV:N/PR:N/UI:N) triggers a stack overflow in Netlogon, reachable on every domain controller. ZDI and SecurityAffairs flag wormable potential. This is the single highest-consequence item in the release: a DC-to-DC self-propagating RCE is the definition of a structural emergency, exploited or not.

CVE-2026-41096 — DNS Client RCE, 9.8, unauthenticated. A heap overflow reachable through a crafted DNS response, again unauthenticated. It rides the same cumulative as Netlogon, so one deployment closes both — but it is a second independent 9.8, not a footnote to the first.

The genuinely huge scores are cloud, and Microsoft already handled them. The CVSS-10.0 items (Azure DevOps, Entra ID, Power Pages, Azure Local, Orbital) and CVSS-9.9 Azure services are cloud-side fixes with no customer package, and the 9.9 Dynamics 365 on-prem RCE (CVE-2026-42898) requires authentication and is rated Exploitation Unlikely. None of them displaces the two on-prem 9.8s as the deployment priority.

Do not confuse the May-12 release with the out-of-band items that followed. The exploited/KEV names people associate with May — Exchange CVE-2026-42897 (KEV 15 May), Defender CVE-2026-41091 and CVE-2026-45498 (KEV 20 May) — are all separate out-of-band releases dated 19–21 May, not part of this Patch Tuesday. They are real and worth patching on their own emergency tracks; they are simply not in this cycle.

The worklist

1

Windows client and server monthly security update

Per-product servicing — see table
ACT · structural
≤5 days

Why now. Two unauthenticated CVSS-9.8 remote-code-execution flaws ship in this cumulative. CVE-2026-41089 is a stack overflow in Netlogon reachable on every domain controller with wormable potential — a self-propagating RCE against the identity core is the highest-consequence shape a Windows flaw takes. CVE-2026-41096 is an independent heap overflow in the DNS Client, also unauthenticated. Neither is exploited, and both are rated Exploitation Less/Unlikely — but the structural lane exists precisely for the pre-authentication, network-reachable, wormable hole that has not been used yet. You do not wait for the evidence when the architecture is this exposed.

This unit cannot slip. Assessed to cut 0 of the identified chains — see the cut section, where this is labelled as a judgement rather than a finding.

ProductPackageCarries
Windows 11 25H2 / 24H2KB5089549CVE-2026-41089, CVE-2026-41096
Windows 11 23H2KB5087420CVE-2026-41089, CVE-2026-41096
Windows 10 22H2 / 21H2 (ESU)KB5087544CVE-2026-41089, CVE-2026-41096
Windows Server 2025KB5087539CVE-2026-41089, CVE-2026-41096
Windows Server 2022KB5087545CVE-2026-41089, CVE-2026-41096
Windows Server 2019KB5087538CVE-2026-41089, CVE-2026-41096
Windows Server 2016KB5087537CVE-2026-41089, CVE-2026-41096

Also inside: The same cumulative includes CVE-2026-40415 (TCP/IP RCE, 8.1) and CVE-2026-35421 (Graphics/GDI RCE, 7.8, rated Critical). Separately, CVE-2026-41103 (9.1, rated 'Exploitation More Likely') affects a Microsoft SSO integration; it is not part of the Windows cumulative and is not exploited, but its 'more likely' rating makes it worth confirming against your own inventory.

Then. Deploy the per-product package for your build and reboot, starting with domain controllers for the Netlogon flaw. As interim mitigation, ensure Netlogon (RPC) and DNS are not reachable from untrusted networks. Note that Windows Server 2025 (KB5087539, build 26100.32860) uses a build-minor sequence far from the 24H2 client (26100.8457) despite the shared 26100 base — do not treat the client KB as covering the server. The Server 2019/2016 KBs (KB5087538 / KB5087537) are taken from the MSRC Netlogon remediation data, high-confidence but not double-sourced against their own support pages.

The soft call in this unit

The judgement is Act-structural versus Prioritise on an unexploited flaw. A zero-day-free month tempts a normal-cycle decision, and Microsoft's 'Exploitation Less/Unlikely' index supports deferral — but an unauthenticated wormable RCE on domain controllers is exactly the case the structural lane refuses to defer. If your DCs and DNS clients are firewalled from untrusted networks, the exposure narrows and Prioritise becomes defensible; internet-adjacent estates should hold at Act.

The cut — why the top unit cannot slip

Confidence: moderate-high — analytic judgement, not vendor-attested

A zero-day-free May still requires an Act / emergency change, because two unauthenticated wormable 9.8 RCEs pass the structural gate — absence of exploitation does not lower a pre-authentication remote hole.

Basis. The primary MSRC CVRF source and six counters confirm no May-12 CVE was exploited or disclosed at release, and the MSRC vector strings confirm CVE-2026-41089 and CVE-2026-41096 are unauthenticated (PR:N, UI:N) network RCEs at 9.8. The structural lane's impact gate (network vector AND RCE impact class on core infrastructure) is passed by both, which forces Act independent of any exploitation evidence.

What would lower this. Microsoft rates both flaws Exploitation Less/Unlikely, and neither has a public PoC as of the read date; a fully firewalled DC/DNS estate genuinely narrows the exposure and would support Prioritise. The judgement would weaken if the Netlogon flaw proves non-wormable in practice or requires preconditions the advisory does not state.

What is not urgent — and why

1

Microsoft Dynamics 365 (on-premises)

Per-product servicing — see table
TRACK
normal cycle

Why now. It is not now, despite the 9.9. CVE-2026-42898 is a Dynamics 365 on-premises RCE, but it requires an authenticated user (PR:L), Microsoft rates it Exploitation Unlikely, and Dynamics is a business application rather than exposed technology or core infrastructure — so the tree files it Track. The 9.9 reflects a scope change on a successful attack, not an unauthenticated path. Where an on-prem Dynamics instance is internet-facing, treat the authentication requirement as the only real barrier and move it forward in the queue.

ProductPackageCarries
Microsoft Dynamics 365 (on-premises)not establishedresolve via vendor advisory before deployment

Then. Apply the Dynamics 365 on-premises update on your normal application-patching cadence; prioritise internet-reachable deployments and confirm least-privilege on application accounts in the interim.

Method, sources, caveats

Sources

SourceAdmiraltyUsed for
https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-MayA1PRIMARY: MSRC CVRF, 'May 2026 Security Updates', InitialReleaseDate 2026-05-12. Every May-12 CVE has Exploited:No / PubliclyDisclosed:No; Netlogon and DNS Client vector strings (PR:N/UI:N, 9.8)
https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilitiesA1KEV read 2026-07-17: no May-12-release CVE present; only out-of-band Exchange/Defender items (added 15/20 May) are listed
https://www.tenable.com/blog/microsofts-may-2026-patch-tuesday-addresses-118-cB2Count (118), Critical (16); zero-day-free 'first since June 2024'; Netlogon/DNS 9.8 unauthenticated
https://www.zerodayinitiative.com/blog/2026/5/12/the-may-2026-security-update-B2Count (138), Critical (30); Netlogon wormable framing; no CVE public or under active attack at release
https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2026-patch-tuesdB2Count (120), Critical (17: 14 RCE, 2 EoP, 1 info disclosure); no zero-days; per-version KBs
https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-may-2026/B2Count (130), Critical (30); Netlogon and DNS Client unauthenticated RCE characterisation
https://support.microsoft.com/en-us/topic/may-12-2026-kb5089549-os-builds-2620A2Windows 11 25H2/24H2 package KB5089549 and builds of record (26200.8457 / 26100.8457)