Skip to content
Microsoft, Palo Alto Networks Find Many Vulnerabilities by Using AI on Their Own Code

Microsoft, Palo Alto Networks Find Many Vulnerabilities by Using AI on Their Own Code

Ground.News May 13, 2026

Microsoft’s MDASH discovered 16 of the Patch Tuesday vulnerabilities, and Palo Alto used Mythos to find dozens of flaws.

Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it's being tested by some customers as part of a limited private preview. MDASH, short for multi-model agentic scanning harness, is designed as a model-agnostic system that uses bespoke AI agents for different vulnerability

Microsoft has unveiled a new AI-driven vulnerability discovery system that identified 16 previously unknown Windows vulnerabilities, including four critical remote code execution flaws, in what security analysts say could mark a major shift in how software vulnerabilities are discovered and remediated. The system, codenamed MDASH, was developed by Microsoft’s Autonomous Code Security team alongside the Windows Attack Research and Protection grou…

Microsoft responded to growing competition in AI security by announcing that its new agentic security system helped researchers discover 16 new vulnerabilities in the Windows networking and authentication stack, including four critical remote code execution (RCE) vulnerabilities. MDASH architecture diagram (Source: Microsoft) Two of the four flaws — CVE-2026-40361 and CVE-2026-40364 — were deemed by Microsoft to be more likely to be exploited. T…

Microsoft has released important security updates for, among others, Azure, Edge, Office and Windows. Many vulnerabilities have been discovered with AI agents.

Microsoft has joined the ranks of companies using artificial intelligence models to look for vulnerabilities in large codebases, and said its MDASH scanner found four critical remote code execution (RCE) bugs in Windows. These were in the TCP/IP networking stack in the Windows kernel, the Internet Key Exchange (IKE) version 2 and Netlogon services, as well as the domain name service (DNS) application programming interface (API) library, Microso…

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (3)