Skip to content
CC-4782

CC-4782

Digital.Nhs.Uk [email protected] (NHS Digital) May 13, 2026

Multiple other Microsoft platforms. Please see Microsoft's May 2026 Security Updates guide for full details.

Microsoft has released security updates to address 137 vulnerabilities in Microsoft products, which includes the following critical vulnerabilities.

CVE-2026-41103 - a privilege escalation vulnerability with a CVSSv3 score of 9.1 arising from a critical 'Incorrect Implementation of Authentication Algorithm' weakness in Microsoft SSO Plugin for Jira & Confluence.

Windows Autopatch is enabling hotpatch security updates by default

Starting with the May 2026 Windows security update, Microsoft is enabling hotpatch security updates by default for devices. This change impacts all eligible devices managed by Microsoft Intune, and applies whether you use Windows Autopatch through Microsoft Intune or the Windows updates API in Microsoft Graph.

For more details, please see Microsoft's blog post.

Affected organisations are encouraged to review Microsoft's May 2026 Security Updates and apply the relevant updates as soon as possible.

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.

Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.

Last edited: 13 May 2026 1:39 pm