2026-05-13: Microsoft ships 137 patches with no zero-days for the first time in two years episode artwork

EPISODE · May 13, 2026 · 27 MIN

2026-05-13: Microsoft ships 137 patches with no zero-days for the first time in two years

from Cyber Threat Brief

Show Notes - 2026-05-13 Stories Covered: - May 13, 2026 - Today: - Microsoft Windows Netlogon RCE (CVE-2026-41089) (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - Microsoft Windows DNS Client RCE (CVE-2026-41096) (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - Exim Mail Server Use-After-Free (CVE-2026-45185) (https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html) - Microsoft Entra ID Credential Bypass (CVE-2026-41103) (https://krebsonsecurity.com/2026/05/patch-tuesday-may-2026-edition/) - Foxconn Confirms Ransomware Attack, Nitrogen Gang Claims Data Theft (https://www.theregister.com/cyber-crime/2026/05/12/foxconn-confirms-cyberattack-after-nitrogen-claims-apple-nvidia-data-theft/5239144) - Instructure Pays Ransom to Restore Canvas Platform (https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/) - Supply Chain Attack on npm TanStack Packages (https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/) - RubyGems Disables Sign-Ups After Staff-Targeted Attack (https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/) - Best Western International Data Breach (https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/) - UK Water Utility Fined for 2-Year Breach Detection Failure (https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/) - Microsoft Office Word Preview Pane RCE Vulnerabilities (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - Microsoft Dynamics 365 Code Injection (CVE-2026-42898) (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - Windows GDI RCE via Malicious EMF Files (CVE-2026-35421) (https://blog.talosintelligence.com/microsoft-patch-tuesday-may-2026/) - Microsoft SharePoint RCE (CVE-2026-40365) (https://blog.talosintelligence.com/microsoft-patch-tuesday-may-2026/) - Azure Critical Vulnerabilities Remediated by Microsoft (https://cyberscoop.com/microsoft-patch-tuesday-may-2026/) - Windows 11 May 2026 Updates (https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5089549-and-kb5087420-cumulative-updates-released/) - Windows 10 Extended Security Update (KB5087544) (https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5087544-extended-security-update/) - AI-Driven Vulnerability Discovery Accelerating Patch Volumes (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - CISA Releases SBOM Guidance for AI Systems (https://www.cisa.gov/resources-tools/resources/software-bill-materials-ai-minimum-elements) - Intel and AMD Chipmaker Vulnerabilities (https://www.securityweek.com/chipmaker-patch-tuesday-intel-and-amd-patch-70-vulnerabilities/) - ABB Industrial Control System Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-03) - Siemens, Schneider Electric, and ICS Vendors Publish Patch Tuesday Advisories (https://www.securityweek.com/ics-patch-tuesday-new-security-advisories-from-siemens-schneider-cisa/) CVEs Referenced: CVE-2024-41975, CVE-2025-15467, CVE-2025-2595, CVE-2025-41659, CVE-2025-41691, CVE-2025-4676, CVE-2026-0481, CVE-2026-20794, CVE-2026-26289, CVE-2026-33109, CVE-2026-33570, CVE-2026-33844, CVE-2026-35421, CVE-2026-35504, CVE-2026-35555, CVE-2026-40361, CVE-2026-40364, CVE-2026-40365, CVE-2026-41089, CVE-2026-41096, CVE-2026-41103, CVE-2026-42823, CVE-2026-42826, CVE-2026-42898, CVE-2026-45185 Indicators of Compromise: IPs: 127.0.0.1 Full brief: https://carolinacleartech.com/brief/2026-05-13/

Episode metadata supplied by the publisher feed · Published May 13, 2026

Embed this episode

Show Notes - 2026-05-13 Stories Covered: - May 13, 2026 - Today: - Microsoft Windows Netlogon RCE (CVE-2026-41089) (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - Microsoft Windows DNS Client RCE (CVE-2026-41096) (https://www.darkreading.com/application-s

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

2026-05-13: Microsoft ships 137 patches with no zero-days for the first time in two years

0:00 27:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Threat Brief?

This episode is 27 minutes long.

When was this Cyber Threat Brief episode published?

This episode was published on May 13, 2026.

Can I download this Cyber Threat Brief episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!