CRITICAL: Microsoft Patch Tuesday Drops Unauthenticated Netlogon and DNS RCE Bugs Rated 9.8
Microsoft shipped 138 patches for May 2026 including two unauthenticated remote code execution flaws rated CVSS 9.8. CVE-2026-41089 is a Netlogon overflow that hands SYSTEM on domain controllers to anyone on the network. CVE-2026-41096 is a DNS Client heap overflow triggered by a malicious DNS response. Patch domain controllers first.