Inleiding

Vandaag, 12 mei 2026, heeft Microsoft de maandelijkse Patch Tuesday uitgebracht. Deze maand worden er een groot aantal kwetsbaarheden gepatcht, verspreid over Windows, Azure, Microsoft Office en diverse andere producten. Hieronder vind je een volledig overzicht van alle CVE’s.

De updates zijn beschikbaar via Windows Update en het Microsoft Security Update Guide.


Kritieke kwetsbaarheden (score ≥ 9.0)

Onderstaande CVE’s verdienen directe aandacht vanwege hun hoge CVSS-score.

ProductCVEBase Score
Azure DevOpsCVE-2026-4282610.0
Azure Managed Instance for Apache CassandraCVE-2026-331099.9
Azure Logic AppsCVE-2026-428239.9
Microsoft Dynamics 365 (on-premises)CVE-2026-428989.9
Windows Hyper-VCVE-2026-404029.3
Azure Entra IDCVE-2026-403799.3
Azure SDKCVE-2026-331179.1
Microsoft SSO Plugin for Jira & ConfluenceCVE-2026-411039.1
Microsoft Dynamics 365 (on-premises)CVE-2026-428339.1
Azure Managed Instance for Apache CassandraCVE-2026-338449.0
Windows NetlogonCVE-2026-410899.8
Microsoft Windows DNSCVE-2026-410969.8

⚠️ CVE-2026-42826 (Azure DevOps) en CVE-2026-41089 (Netlogon) hebben de maximale score van 9.8 of hoger — patch deze zo snel mogelijk.


Volledig CVE-overzicht

ProductCVEBase Score
Windows Rich Text EditCVE-2026-215306.7
M365 CopilotCVE-2026-261297.5
M365 CopilotCVE-2026-261647.5
Windows Native WiFi Miniport DriverCVE-2026-321617.5
Windows Rich Text Edit ControlCVE-2026-321706.7
.NETCVE-2026-321754.3
.NETCVE-2026-321777.3
Microsoft TeamsCVE-2026-321855.5
Azure Monitor AgentCVE-2026-322047.8
Azure Machine LearningCVE-2026-322078.8
Windows Filtering Platform (WFP)CVE-2026-322094.4
Azure Managed Instance for Apache CassandraCVE-2026-331099.9
Microsoft Office SharePointCVE-2026-331108.8
Copilot Chat (Microsoft Edge)CVE-2026-331117.5
Microsoft Office SharePointCVE-2026-331128.8
Azure SDKCVE-2026-331179.1
Microsoft Dynamics 365 Customer InsightsCVE-2026-338217.7
Microsoft TeamsCVE-2026-338239.6
Azure Machine LearningCVE-2026-338338.2
Windows Event Logging ServiceCVE-2026-338347.8
Windows Cloud Files Mini Filter DriverCVE-2026-338357.8
Windows TCP/IPCVE-2026-338377.8
Windows Message QueuingCVE-2026-338387.8
Windows Win32K - GRFXCVE-2026-338397.0
Windows Win32K - ICOMPCVE-2026-338407.8
Windows KernelCVE-2026-338417.8
Azure Managed Instance for Apache CassandraCVE-2026-338449.0
Microsoft Partner CenterCVE-2026-343278.2
Windows Message QueuingCVE-2026-343298.8
Windows Win32K - GRFXCVE-2026-343307.8
Windows Win32K - GRFXCVE-2026-343317.0
Windows Kernel-Mode DriversCVE-2026-343328.0
Windows Win32K - GRFXCVE-2026-343337.8
Windows TCP/IPCVE-2026-343347.8
Windows DWM Core LibraryCVE-2026-343367.8
Windows Cloud Files Mini Filter DriverCVE-2026-343377.8
Windows Telephony ServiceCVE-2026-343387.8
Windows LDAPCVE-2026-343395.5
Windows Projected File SystemCVE-2026-343407.0
Windows Link-Layer Discovery Protocol (LLDP)CVE-2026-343417.0
Windows Print Spooler ComponentsCVE-2026-343427.0
Windows Application Identity (AppID) SubsystemCVE-2026-343437.8
Windows Ancillary Function Driver for WinSockCVE-2026-343447.8
Windows Ancillary Function Driver for WinSockCVE-2026-343457.0
Windows Win32K - GRFXCVE-2026-343477.0
Windows Storport Miniport DriverCVE-2026-343506.5
Windows TCP/IPCVE-2026-343517.8
Windows Storage Spaces ControllerCVE-2026-354157.8
Windows Ancillary Function Driver for WinSockCVE-2026-354167.0
Windows Win32K - ICOMPCVE-2026-354177.8
Windows Cloud Files Mini Filter DriverCVE-2026-354187.8
Windows DWM Core LibraryCVE-2026-354195.5
Windows KernelCVE-2026-354207.8
Windows GDICVE-2026-354217.8
Windows TCP/IPCVE-2026-354226.5
Telnet ClientCVE-2026-354235.4
Windows Internet Key Exchange (IKE) ProtocolCVE-2026-354247.5
Azure Cloud ShellCVE-2026-354289.6
Microsoft Edge for AndroidCVE-2026-354294.3
.NETCVE-2026-354337.3
Azure AI Foundry M365 published agentsCVE-2026-354358.6
Microsoft Office Click-To-RunCVE-2026-354368.8
Windows Admin CenterCVE-2026-354388.3
Microsoft Office SharePointCVE-2026-354398.8
Microsoft Office WordCVE-2026-354405.5
Microsoft Office SharePointCVE-2026-403578.8
Microsoft OfficeCVE-2026-403588.4
Microsoft Office ExcelCVE-2026-403597.8
Microsoft Office ExcelCVE-2026-403607.8
Microsoft Office WordCVE-2026-403618.4
Microsoft Office ExcelCVE-2026-403627.8
Microsoft OfficeCVE-2026-403638.4
Microsoft Office WordCVE-2026-403648.4
Microsoft Office SharePointCVE-2026-403658.8
Microsoft Office WordCVE-2026-403668.4
Microsoft Office WordCVE-2026-403678.4
Microsoft Office SharePointCVE-2026-403688.0
Windows KernelCVE-2026-403697.8
SQL ServerCVE-2026-403708.8
Power AutomateCVE-2026-403746.5
Windows Cryptographic ServicesCVE-2026-403777.8
Azure Entra IDCVE-2026-403799.3
Windows Volume Manager Extension DriverCVE-2026-403806.2
Azure Connected Machine AgentCVE-2026-403817.8
Windows Telephony ServiceCVE-2026-403827.8
Windows Common Log File System DriverCVE-2026-403977.8
Windows Remote DesktopCVE-2026-403987.8
Windows TCP/IPCVE-2026-403997.8
Windows TCP/IPCVE-2026-404017.1
Windows Hyper-VCVE-2026-404029.3
Windows Win32K - GRFXCVE-2026-404038.8
Windows TCP/IPCVE-2026-404057.5
Windows TCP/IPCVE-2026-404067.5
Windows Common Log File System DriverCVE-2026-404077.8
Windows Kernel-Mode DriversCVE-2026-404087.8
Windows SMB ClientCVE-2026-404107.0
Windows TCP/IPCVE-2026-404137.4
Windows TCP/IPCVE-2026-404147.4
Windows TCP/IPCVE-2026-404158.1
Microsoft Edge (Chromium-based)CVE-2026-404164.3
Dynamics Business CentralCVE-2026-404177.8
Microsoft Office Click-To-RunCVE-2026-404187.8
Microsoft OfficeCVE-2026-404197.8
Microsoft Office Click-To-RunCVE-2026-404208.8
Microsoft Office WordCVE-2026-404214.3
Windows Admin CenterCVE-2026-410868.8
Windows Ancillary Function Driver for WinSockCVE-2026-410887.8
Windows NetlogonCVE-2026-410899.8
Microsoft Data FormulatorCVE-2026-410948.8
Data DeduplicationCVE-2026-410957.8
Microsoft Windows DNSCVE-2026-410969.8
Windows Secure BootCVE-2026-410976.7
M365 CopilotCVE-2026-411004.4
Microsoft Office WordCVE-2026-411017.1
Microsoft Office PowerPointCVE-2026-411027.1
Microsoft SSO Plugin for Jira & ConfluenceCVE-2026-411039.1
Azure Notification ServiceCVE-2026-411058.1
Microsoft Edge (Chromium-based)CVE-2026-411077.4
GitHub Copilot and Visual StudioCVE-2026-411098.8
Visual Studio CodeCVE-2026-416106.3
Visual Studio CodeCVE-2026-416117.8
Visual Studio CodeCVE-2026-416125.5
Visual Studio CodeCVE-2026-416138.8
M365 Copilot for DesktopCVE-2026-416146.2
Azure Logic AppsCVE-2026-428239.9
Windows Telephony ServiceCVE-2026-428257.0
Azure DevOpsCVE-2026-4282610.0
Azure Monitor AgentCVE-2026-428306.5
Microsoft OfficeCVE-2026-428317.8
Microsoft OfficeCVE-2026-428327.7
Microsoft Dynamics 365 (on-premises)CVE-2026-428339.1
Microsoft Edge (Chromium-based)CVE-2026-428385.4
Microsoft Edge (Chromium-based)CVE-2026-428916.5
M365 CopilotCVE-2026-428937.4
Windows DWM Core LibraryCVE-2026-428967.8
Microsoft Dynamics 365 (on-premises)CVE-2026-428989.9
ASP.NET CoreCVE-2026-428997.5

Aanbevelingen

  • Installeer de updates zo snel mogelijk via Windows Update of WSUS/SCCM.
  • Prioriteer systemen met Azure DevOps, Netlogon, Windows DNS en Hyper-V.
  • Controleer of je SharePoint-omgeving up-to-date is — meerdere kritieke CVE’s raken SharePoint.
  • Bekijk de volledige details per CVE via het Microsoft Security Update Guide.