Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    More Lenovo Legion Y70 2026 specs revealed ahead of launch

    May 13, 2026

    Lenovo’s new ThinkPad and ThinkStation PCs look better than ever

    May 13, 2026

    Galaxy Z Fold 8 and Flip 8 could launch with Gemini Intelligence

    May 13, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Microsoft Patches 137 Vulnerabilities – SecurityWeek
    Microsoft Patches 137 Vulnerabilities – SecurityWeek
    Cybersecurity

    Microsoft Patches 137 Vulnerabilities – SecurityWeek

    The Tech GuyBy The Tech GuyMay 12, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Microsoft on Tuesday announced patching 137 vulnerabilities across its products, none of which have been flagged as exploited in the wild.

    Advertisement

    Roughly a dozen of the bugs addressed with the latest Patch Tuesday updates have an exploitability rating of ‘exploitation more likely’, indicating that threat actors could start abusing them in attacks.

    The most severe of these is CVE-2026-41103, a critical-severity flaw in the Microsoft SSO Plugin for Jira & Confluence that could lead to elevation of privilege. The issue is rooted in the incorrect implementation of the authentication algorithm.

    High-severity privilege escalation issues in Windows Remote Desktop, Windows Common Log File System Driver, Windows Kernel, Azure AI Foundry, Windows Win32k, Windows Ancillary Function Driver for WinSock, Windows TCP/IP, and Windows Cloud Files Mini Filter Driver are also prone to exploitation, Microsoft says.

    The company also draws attention to two high-severity remote code execution defects in Microsoft Word (CVE-2026-40364 and CVE-2026-40361, CVSS score of 8.4) that are more likely to be exploited. The first is a type confusion issue, while the second is a use-after-free bug.

    “These flaws could be exploited by an attacker who sends a malicious document to a target,” Tenable senior staff research engineer Satnam Narang said.

    Advertisement. Scroll to continue reading.

    “The other common thread across these vulnerabilities is that a target doesn’t need to even open the document to trigger the exploit. Exploitation is possible just by viewing a malicious document in the Preview Pane. Therefore, patching is the most reliable way to protect against flaws like these,” Narang added.

    Two other high-severity Word weaknesses were also resolved this month, but they are less likely or unlikely to be exploited, Microsoft says. More than two dozen vulnerabilities were resolved in the Office suite.

    On Tuesday, Microsoft also rolled out fixes for critical-severity bugs in Dynamics 365 (on-premises), Azure Logic Apps, Windows DNS, Windows Netlogon, Windows Hyper-V, and Azure SDK.

    The security updates also address high-severity flaws in Copilot, .NET, Azure services, Windows kernel and kernel mode drivers, Win32K, LDAP, SQL Server, Edge, Visual Studio Code, and various Windows components and services.

    Adobe on Tuesday released patches for 52 vulnerabilities across 10 products, including a couple of critical-severity code execution flaws.

    Related: SAP Patches Critical S/4HANA, Commerce Vulnerabilities

    Related: Cisco Patches High-Severity Vulnerabilities in Enterprise Products

    Related: Oracle Patches 450 Vulnerabilities With April 2026 CPU

    Related: Progress Patches Multiple Vulnerabilities in MOVEit WAF, LoadMaster

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Exaforce Raises $125 Million for Agentic SOC Platform

    May 13, 2026

    Adobe Patches 52 Vulnerabilities in 10 Products

    May 12, 2026

    TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack

    May 12, 2026

    Google Detects First AI-Generated Zero-Day Exploit

    May 12, 2026

    Frame Security Emerges From Stealth With $50M for Awareness and Training Platform

    May 11, 2026

    Build Application Firewalls Aim to Stop the Next Supply Chain Attack

    May 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20258 Views

    Facebook updates its algorithm to give users more control over which videos they see

    October 8, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    More Lenovo Legion Y70 2026 specs revealed ahead of launch

    May 13, 2026

    Lenovo’s new ThinkPad and ThinkStation PCs look better than ever

    May 13, 2026

    Galaxy Z Fold 8 and Flip 8 could launch with Gemini Intelligence

    May 13, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.