Microsoft’s May 2026 Patch Tuesday releases security updates addressing at least 120 vulnerabilities across multiple products. Both outlets report that no zero-day vulnerabilities are disclosed or identified as actively exploited in connection with this month’s update cycle. The coverage notes that the fixes include multiple Common Vulnerabilities and Exposures (CVE) entries, with no public indication of zero-day exploitation at the time of release.
Help Net Security adds additional emphasis on the set of most severe issues in the update set, pointing to four critical remote code execution vulnerabilities in Microsoft Word. It further highlights two specific Word issues, identified as CVE-2026-40361 and CVE-2026-40364, as warranting faster attention relative to other fixes in the broader release.
Overall, the reporting converges on the same core facts: this month’s Patch Tuesday includes a large number of vulnerability fixes (around 120 or more CVEs), and unlike some prior months, there are no zero-days publicly disclosed alongside the patches.