Microsoft Patch Tuesday May 2026: Netlogon and DNS Client
May's Windows fixes include critical Netlogon and DNS Client vulnerabilities. Later Netlogon exploitation makes verification of domain-controller updates essential.
The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.
Microsoft’s May 2026 release included critical remote-code-execution fixes for Windows Netlogon and the DNS Client. For an organisation checking its backlog, those components deserve explicit version verification.
The risk picture changed after release. In June, CERT-EU reported active exploitation of CVE-2026-41089, citing Belgium’s cybersecurity authority. An assessment made on patch day should not remain frozen when new exploitation evidence appears.
Netlogon: verify domain controllers
CVE-2026-41089 is a stack-based buffer overflow in Windows Netlogon. Microsoft’s CVE record, reproduced by NVD, gives it a CVSS score of 9.8 and describes unauthorised network-based code execution.
CERT-EU identifies affected Windows Server versions acting as domain controllers. Check every relevant domain controller against the current Microsoft advisory, including older versions supported through applicable programmes.
Confirm installation and restart status. If there are signs of compromise, investigate identity activity as well as updating the operating system.
DNS Client: look beyond DNS servers
CVE-2026-41096 concerns a heap-based buffer overflow in the Windows DNS component, with a Microsoft CVSS score of 9.8. The Microsoft-supplied CVE record describes unauthorised code execution over a network.
This is a DNS Client issue. Prioritising only machines with the DNS Server role would miss relevant systems. Match affected Windows versions to the vendor’s update list, including endpoints.
Secure Boot needs its own verification
The 2011 Secure Boot certificates began expiring in June 2026, with different certificates following different dates. There is no single universal 26 June deadline.
Microsoft explains the effect of expiry and provides certificate-update guidance. Check actual certificate status and platform prerequisites rather than assuming a monthly update completed the transition.
Finish with a verified inventory
Use current supported updates that resolve the applicable issues. Record failed deployments and offline devices, assign exceptions and check required reboots.
The May archive is a starting point for these specific issues. The Security Update Guide remains the reference for current affected products, revisions and update instructions.