Summary
May 2026 Patch Tuesday looked quiet on Microsoft's release notes – low triple-digit net-new CVEs, zero actively exploited, zero publicly disclosed at release – but Jason Kikta and Landon Miles argue the month was anything but. The real story sits in the acknowledgment sections: AI-assisted vulnerability research was credited by name across Windows, macOS, and Linux in the same patch cycle, including Anthropic researchers on a critical Windows graphics RCE. Kikta and Miles also flag the fixes that can't wait for normal cadence, from two pre-authenticated 9.8 RCEs in core Windows services to Apple's Wi-Fi kernel RCE in Tahoe 26.5 and the Linux Dirty Frag chain that Copy Fail mitigations don't fully cover.
)
)
)
)
)
)
)