Patch Tuesday Microsoft: Critical DNS client vulnerability threatens Windows

Microsoft has released important security updates for Azure, Edge, Office, and Windows, among others. Many vulnerabilities were discovered with AI agents.

listen Print view

(Image: heise online)

2 min. read

Security vulnerabilities classified as “critical” by Microsoft affect Azure, M365, Office, SharePoint, Windows, and Word, among others. In many cases, attackers can push malicious code onto computers, thus completely compromising systems.

Admins should ensure that the Windows Update function is active and systems are up-to-date. Otherwise, PCs are vulnerable. So far, there are no reports of attackers exploiting vulnerabilities.

The most alarming is a “critical” vulnerability (CVE-2026-42826) with the highest possible CVSS Score of 10 out of 10 in Azure DevOps. At this point, attackers can access protected information in an unspecified way. Microsoft states that the vulnerability has been patched server-side. Therefore, admins do not need to take any action here.

Further “critical” vulnerabilities impact Azure Managed Instance for Apache Cassandra (CVE-2026-33109), Microsoft Dynamics 365 On-Premises (CVE-2026-41096), and the DNS client in Windows (CVE-2026-41096), among others. In the latter case, remote attackers can trigger memory errors via a crafted DNS request without authentication, allowing malicious code to reach computers. Various Windows 11 and Server editions are impacted.

On this Patch Tuesday, Microsoft has resolved a total of nearly 140 security issues. In a post, the company states that a large portion of the vulnerabilities were discovered with the help of several AI agents.

Videos by heise

Further information on the vulnerabilities and affected software can be found in Microsoft's Security Update Guide.

(des)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.