ΑρχικήUpdatesMicrosoft Patch Tuesday Μαΐου 2026: Διόρθωση 120 ευπαθειών

Microsoft Patch Tuesday Μαΐου 2026: Διόρθωση 120 ευπαθειών

Η Microsoft διέθεσε το καθιερωμένο Patch Tuesday για τον Μάιο του 2026, προχωρώντας σε μια εκτεταμένη δέσμη ενημερώσεων ασφαλείας που αντιμετωπίζει συνολικά 120 ευπάθειες σε προϊόντα και υπηρεσίες του οικοσυστήματος Windows. Αν και η συγκεκριμένη έκδοση δεν περιλαμβάνει γνωστές zero-day επιθέσεις, ο αριθμός και η σοβαρότητα των προβλημάτων που διορθώνονται προκαλούν έντονο ενδιαφέρον στην κοινότητα κυβερνοασφάλειας.

Microsoft Patch Tuesday Μαΐου 2026: Διόρθωση 120 ευπαθειών

17 κρίσιμες ευπάθειες απαιτούν άμεση προσοχή

Από το σύνολο των σφαλμάτων που επιδιορθώθηκαν, οι 17 χαρακτηρίζονται ως «Κρίσιμες». Οι 14 σχετίζονται με απομακρυσμένη εκτέλεση κώδικα (Remote Code Execution – RCE), δύο αφορούν ανύψωση δικαιωμάτων πρόσβασης και μία σχετίζεται με αποκάλυψη ευαίσθητων πληροφοριών.

Η απομακρυσμένη εκτέλεση κώδικα παραμένει μία από τις πιο επικίνδυνες κατηγορίες επιθέσεων, καθώς επιτρέπει σε έναν επιτιθέμενο να εκτελέσει κακόβουλο λογισμικό σε έναν υπολογιστή χωρίς φυσική πρόσβαση. Σε εταιρικά περιβάλλοντα, τέτοιου είδους αδυναμίες μπορούν να οδηγήσουν σε παραβίαση δικτύων, κλοπή δεδομένων και εγκατάσταση ransomware.

Δείτε επίσης: Η APT28 συνδέεται με το MSHTML zero-day πριν από το Patch Tuesday Φεβρουαρίου

Αναλυτικά οι κατηγορίες ευπαθειών

Η Microsoft κατέγραψε τις διορθώσεις στις εξής κατηγορίες:

  • 61 ευπάθειες ανύψωσης δικαιωμάτων
  • 31 ευπάθειες απομακρυσμένης εκτέλεσης κώδικα
  • 14 ευπάθειες αποκάλυψης πληροφοριών
  • 13 ευπάθειες πλαστογράφησης
  • 8 ευπάθειες Denial of Service
  • 6 ευπάθειες παράκαμψης μηχανισμών ασφαλείας

Οι ευπάθειες ανύψωσης δικαιωμάτων συνεχίζουν να κυριαρχούν αριθμητικά, γεγονός που αποδεικνύει ότι οι κυβερνοεγκληματίες εξακολουθούν να στοχεύουν τεχνικές που επιτρέπουν την απόκτηση αυξημένων δικαιωμάτων μέσα σε ένα σύστημα μετά την αρχική παραβίαση.

Εκτός λίστας αρκετές διορθώσεις της Microsoft

Αξίζει να σημειωθεί ότι η καταμέτρηση των 120 ευπαθειών αφορά αποκλειστικά τις ενημερώσεις που διατέθηκαν από τη Microsoft στο πλαίσιο του Patch Tuesday. Δεν περιλαμβάνονται διορθώσεις που είχαν ήδη κυκλοφορήσει νωρίτερα μέσα στον μήνα για πλατφόρμες όπως Mariner, Azure, Copilot, Microsoft Teams και Microsoft Partner Center.

Δείτε επίσης: Η Microsoft διορθώνει 167 ευπάθειες στο τελευταίο Patch Tuesday

Microsoft Patch Tuesday Μαΐου 2026: Διόρθωση 120 ευπαθειών

Παράλληλα, εκτός της επίσημης λίστας παραμένουν και 131 ευπάθειες του Microsoft Edge που σχετίζονται με τον Chromium engine και επιδιορθώθηκαν από την Google. Το στοιχείο αυτό αποκαλύπτει πόσο σύνθετο έχει γίνει το σύγχρονο οικοσύστημα λογισμικού, όπου διαφορετικοί προμηθευτές συνεργάζονται έμμεσα για τη συνολική ασφάλεια των χρηστών.

Το Microsoft Office στο στόχαστρο των επιθέσεων

Ιδιαίτερο ενδιαφέρον παρουσιάζουν οι διορθώσεις που αφορούν το Microsoft Office, το Word και το Excel. Η Microsoft επιβεβαίωσε την ύπαρξη πολλαπλών ευπαθειών που θα μπορούσαν να οδηγήσουν σε απομακρυσμένη εκτέλεση κώδικα μέσω κακόβουλων αρχείων.

Οι επιθέσεις βασίζονται συνήθως σε παραποιημένα έγγραφα που αποστέλλονται μέσω email ή εφαρμογών ανταλλαγής αρχείων. Με το άνοιγμα του αρχείου, ο επιτιθέμενος μπορεί να αποκτήσει πρόσβαση στο σύστημα του θύματος ή να εγκαταστήσει κακόβουλο λογισμικό χωρίς να γίνει άμεσα αντιληπτός.

Ανησυχία προκαλεί και το γεγονός ότι αρκετές από αυτές τις ευπάθειες μπορούν να ενεργοποιηθούν ακόμη και μέσω του παραθύρου προεπισκόπησης αρχείων. Αυτό σημαίνει ότι σε ορισμένες περιπτώσεις δεν απαιτείται καν το πλήρες άνοιγμα του εγγράφου για να ξεκινήσει η επίθεση.

Για τον λόγο αυτό, οι ειδικοί ασφαλείας συνιστούν την άμεση εγκατάσταση των ενημερώσεων, ιδιαίτερα σε οργανισμούς που διαχειρίζονται μεγάλο όγκο email και συνημμένων αρχείων καθημερινά.

Οι πιο επικίνδυνες ευπάθειες του μήνα

Μεταξύ των σημαντικότερων διορθώσεων ξεχωρίζει η CVE-2026-35421, μια κρίσιμη ευπάθεια στο Windows GDI που μπορεί να αξιοποιηθεί μέσω κακόβουλων αρχείων Enhanced Metafile (EMF). Το άνοιγμα ενός τέτοιου αρχείου στο Microsoft Paint θα μπορούσε να επιτρέψει την εκτέλεση αυθαίρετου κώδικα στο σύστημα του χρήστη.

Δείτε επίσης: Microsoft Patch Tuesday Φεβρουαρίου 2026: Διορθώσεις για 58 ευπάθειες

Ιδιαίτερη προσοχή συγκεντρώνει και η CVE-2026-40365, η οποία επηρεάζει τον Microsoft SharePoint Server. Σύμφωνα με τη Microsoft, ένας πιστοποιημένος χρήστης μπορεί να εκμεταλλευτεί το κενό ασφαλείας μέσω δικτύου και να εκτελέσει κακόβουλο κώδικα απομακρυσμένα στον διακομιστή. Για επιχειρήσεις που βασίζονται στον SharePoint για συνεργασία και διαχείριση εγγράφων, η συγκεκριμένη ευπάθεια θεωρείται υψηλού ρίσκου.

Εξίσου σοβαρή χαρακτηρίζεται η CVE-2026-41096 που επηρεάζει τον DNS Client των Windows. Ένας κακόβουλος DNS server μπορεί να αποστείλει ειδικά διαμορφωμένες απαντήσεις σε ευάλωτα συστήματα, προκαλώντας αλλοίωση μνήμης και τελικά απομακρυσμένη εκτέλεση κώδικα.

Microsoft Patch Tuesday Μαΐου 2026: Διόρθωση 120 ευπαθειών

Η κυβερνοασφάλεια γίνεται πλέον καθημερινή ανάγκη

Το Patch Tuesday του Μαΐου 2026 επιβεβαιώνει ότι οι απειλές στον κυβερνοχώρο εξελίσσονται διαρκώς και επηρεάζουν τόσο απλούς χρήστες όσο και μεγάλους οργανισμούς. Η τακτική εγκατάσταση ενημερώσεων ασφαλείας δεν αποτελεί πλέον προαιρετική διαδικασία, αλλά βασικό κομμάτι της ψηφιακής άμυνας κάθε συστήματος.

Καθώς οι επιθέσεις γίνονται ολοένα πιο στοχευμένες και εξελιγμένες, η έγκαιρη ενημέρωση λογισμικού και η σωστή εκπαίδευση των χρηστών παραμένουν οι σημαντικότεροι παράγοντες προστασίας απέναντι στις σύγχρονες κυβερνοαπειλές.

Microsoft Patch Tuesday Μαΐου 2026: Όλες οι ευπάθειες

Στον παρακάτω πίνακα, μπορείτε να δείτε όλες τις ευπάθειες που διορθώνονται αυτό το μήνα:

TagCVE IDCVE TitleSeverity
.NETCVE-2026-35433.NET Elevation of Privilege VulnerabilityImportant
.NETCVE-2026-32177.NET Elevation of Privilege VulnerabilityImportant
.NETCVE-2026-32175.NET Core Tampering VulnerabilityImportant
AMD CPU BranchCVE-2025-54518AMD: CVE-2025-54518 CPU OP Cache CorruptionImportant
ASP.NET CoreCVE-2026-42899ASP.NET Core Denial of Service VulnerabilityImportant
Azure Connected Machine AgentCVE-2026-40381Azure Connected Machine Agent Elevation of Privilege VulnerabilityImportant
Azure Logic AppsCVE-2026-42823Azure Logic Apps Elevation of Privilege VulnerabilityImportant
Azure Machine LearningCVE-2026-33833Azure Machine Learning Notebook Spoofing VulnerabilityImportant
Azure Monitor AgentCVE-2026-32204Azure Monitor Agent Elevation of Privilege VulnerabilityImportant
Azure Monitor AgentCVE-2026-42830Azure Monitor Agent Metrics Extension Elevation of Privilege VulnerabilityImportant
Azure SDKCVE-2026-33117Azure SDK for Java Security Feature Bypass VulnerabilityImportant
Data DeduplicationCVE-2026-41095Data Deduplication Elevation of Privilege VulnerabilityImportant
Dynamics Business CentralCVE-2026-40417Microsoft Dynamics 365 Business Central Elevation of Privilege VulnerabilityImportant
GitHub Copilot and Visual StudioCVE-2026-41109GitHub Copilot and Visual Studio Code Security Feature Bypass VulnerabilityImportant
M365 CopilotCVE-2026-41100Microsoft 365 Copilot for Android Spoofing VulnerabilityImportant
M365 CopilotCVE-2026-42893Microsoft Outlook for iOS Tampering VulnerabilityImportant
M365 CopilotCVE-2026-26164M365 Copilot Information Disclosure VulnerabilityCritical
M365 Copilot for DesktopCVE-2026-41614M365 Copilot for Desktop Spoofing VulnerabilityImportant
Microsoft Data FormulatorCVE-2026-41094Microsoft Data Formulator Remote Code Execution VulnerabilityImportant
Microsoft Dynamics 365 (on-premises)CVE-2026-42898Microsoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityCritical
Microsoft Dynamics 365 (on-premises)CVE-2026-42833Microsoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-42832Microsoft Office Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-42831Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2026-40363Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2026-40419Microsoft Office Click-To-Run Elevation of Privilege VulnerabilityImportant
Microsoft OfficeCVE-2026-40358Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft Office Click-To-RunCVE-2026-35436Microsoft Office Click-To-Run Elevation of Privilege VulnerabilityImportant
Microsoft Office Click-To-RunCVE-2026-40420Microsoft Office Click-To-Run Elevation of Privilege VulnerabilityImportant
Microsoft Office Click-To-RunCVE-2026-40418Microsoft Office Click-To-Run Elevation of Privilege VulnerabilityImportant
Microsoft Office ExcelCVE-2026-40360Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office ExcelCVE-2026-40362Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2026-40359Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office PowerPointCVE-2026-41102Microsoft PowerPoint for Android Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2026-40368Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2026-35439Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2026-33112Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2026-40365Microsoft SharePoint Server Remote Code Execution VulnerabilityCritical
Microsoft Office SharePointCVE-2026-40357Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2026-33110Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
Microsoft Office WordCVE-2026-40361Microsoft Word Remote Code Execution VulnerabilityCritical
Microsoft Office WordCVE-2026-40367Microsoft Word Remote Code Execution VulnerabilityCritical
Microsoft Office WordCVE-2026-35440Microsoft Word Information Disclosure VulnerabilityImportant
Microsoft Office WordCVE-2026-40421Microsoft Word Information Disclosure VulnerabilityImportant
Microsoft Office WordCVE-2026-41101Microsoft Word for Android Spoofing VulnerabilityImportant
Microsoft Office WordCVE-2026-40366Microsoft Word Remote Code Execution VulnerabilityCritical
Microsoft Office WordCVE-2026-40364Microsoft Word Remote Code Execution VulnerabilityCritical
Microsoft SSO Plugin for Jira & ConfluenceCVE-2026-41103Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege VulnerabilityCritical
Microsoft TeamsCVE-2026-32185Microsoft Teams Spoofing VulnerabilityImportant
Microsoft Windows DNSCVE-2026-41096Windows DNS Client Remote Code Execution VulnerabilityCritical
Power AutomateCVE-2026-40374Microsoft Power Automate Desktop Information Disclosure VulnerabilityImportant
SQL ServerCVE-2026-40370SQL Server Remote Code Execution VulnerabilityImportant
Telnet ClientCVE-2026-35423Windows 11 Telnet Client Information Disclosure VulnerabilityImportant
Visual Studio CodeCVE-2026-41613Visual Studio Code Elevation of Privilege VulnerabilityImportant
Visual Studio CodeCVE-2026-41612Visual Studio Code Information Disclosure VulnerabilityImportant
Visual Studio CodeCVE-2026-41610Visual Studio Code Security Feature Bypass VulnerabilityImportant
Visual Studio CodeCVE-2026-41611Visual Studio Code Remote Code Execution VulnerabilityImportant
Windows Admin CenterCVE-2026-41086Windows Admin Center in Azure Portal Elevation of Privilege VulnerabilityImportant
Windows Admin CenterCVE-2026-35438Windows Admin Center Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-35416Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-41088Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-34345Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-34344Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Application Identity (AppID) SubsystemCVE-2026-34343Windows Application Identity (AppID) Subsystem Elevation of Privilege VulnerabilityImportant
Windows Cloud Files Mini Filter DriverCVE-2026-34337Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityImportant
Windows Cloud Files Mini Filter DriverCVE-2026-35418Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityImportant
Windows Cloud Files Mini Filter DriverCVE-2026-33835Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityImportant
Windows Common Log File System DriverCVE-2026-40397Windows Common Log File System Driver Elevation of Privilege VulnerabilityImportant
Windows Common Log File System DriverCVE-2026-40407Windows Common Log File System Driver Elevation of Privilege VulnerabilityImportant
Windows Cryptographic ServicesCVE-2026-40377Microsoft Cryptographic Services Elevation of Privilege VulnerabilityImportant
Windows DWM Core LibraryCVE-2026-34336Windows DWM Core Library Information Disclosure VulnerabilityImportant
Windows DWM Core LibraryCVE-2026-42896Windows DWM Core Library Elevation of Privilege VulnerabilityImportant
Windows DWM Core LibraryCVE-2026-35419Windows DWM Core Library Information Disclosure VulnerabilityImportant
Windows Event Logging ServiceCVE-2026-33834Windows Event Logging Service Elevation of Privilege VulnerabilityImportant
Windows Filtering Platform (WFP)CVE-2026-32209Windows Filtering Platform (WFP) Security Feature Bypass VulnerabilityImportant
Windows GDICVE-2026-35421Windows GDI Remote Code Execution VulnerabilityCritical
Windows Hyper-VCVE-2026-40402Windows Hyper-V Elevation of Privilege VulnerabilityCritical
Windows Internet Key Exchange (IKE) ProtocolCVE-2026-35424Internet Key Exchange (IKE) Protocol Denial of Service VulnerabilityImportant
Windows KernelCVE-2026-40369Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-33841Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-35420Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows Kernel-Mode DriversCVE-2026-34332Windows Kernel-Mode Driver Remote Code Execution VulnerabilityImportant
Windows Kernel-Mode DriversCVE-2026-40408Windows WAN ARP Driver Elevation of Privilege VulnerabilityImportant
Windows LDAP – Lightweight Directory Access ProtocolCVE-2026-34339Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityImportant
Windows Link-Layer Discovery Protocol (LLDP)CVE-2026-34341Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege VulnerabilityImportant
Windows Message QueuingCVE-2026-34329Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityImportant
Windows Message QueuingCVE-2026-33838Windows Message Queuing (MSMQ) Elevation of Privilege VulnerabilityImportant
Windows Native WiFi Miniport DriverCVE-2026-32161Windows Native WiFi Miniport Driver Remote Code Execution VulnerabilityCritical
Windows NetlogonCVE-2026-41089Windows Netlogon Remote Code Execution VulnerabilityCritical
Windows Print Spooler ComponentsCVE-2026-34342Windows Print Spooler Elevation of Privilege VulnerabilityImportant
Windows Projected File SystemCVE-2026-34340Windows Projected File System Elevation of Privilege VulnerabilityImportant
Windows Remote DesktopCVE-2026-40398Windows Remote Desktop Services Elevation of Privilege VulnerabilityImportant
Windows Rich Text EditCVE-2026-21530Windows Rich Text Edit Elevation of Privilege VulnerabilityImportant
Windows Rich Text Edit ControlCVE-2026-32170Windows Rich Text Edit Elevation of Privilege VulnerabilityImportant
Windows Secure BootCVE-2026-41097Secure Boot Security Feature Bypass VulnerabilityImportant
Windows SMB ClientCVE-2026-40410Windows SMB Client Elevation of Privilege VulnerabilityImportant
Windows Storage Spaces ControllerCVE-2026-35415Windows Storage Spaces Controller Elevation of Privilege VulnerabilityImportant
Windows Storport Miniport DriverCVE-2026-34350Windows Storport Miniport Driver Denial of Service VulnerabilityImportant
Windows TCP/IPCVE-2026-34351Windows TCP/IP Elevation of Privilege VulnerabilityImportant
Windows TCP/IPCVE-2026-33837Windows TCP/IP Local Elevation of Privilege VulnerabilityImportant
Windows TCP/IPCVE-2026-40406Windows TCP/IP Information Disclosure VulnerabilityImportant
Windows TCP/IPCVE-2026-40414Windows TCP/IP Denial of Service VulnerabilityImportant
Windows TCP/IPCVE-2026-34334Windows TCP/IP Elevation of Privilege VulnerabilityImportant
Windows TCP/IPCVE-2026-40399Windows TCP/IP Elevation of Privilege VulnerabilityImportant
Windows TCP/IPCVE-2026-35422Windows TCP/IP Driver Security Feature Bypass VulnerabilityImportant
Windows TCP/IPCVE-2026-40413Windows TCP/IP Denial of Service VulnerabilityImportant
Windows TCP/IPCVE-2026-40415Windows TCP/IP Remote Code Execution VulnerabilityImportant
Windows TCP/IPCVE-2026-40401Windows TCP/IP Denial of Service VulnerabilityImportant
Windows TCP/IPCVE-2026-40405Windows TCP/IP Denial of Service VulnerabilityImportant
Windows Telephony ServiceCVE-2026-40382Windows Telephony Service Elevation of Privilege VulnerabilityImportant
Windows Telephony ServiceCVE-2026-34338Windows Telephony Service Elevation of Privilege VulnerabilityImportant
Windows Telephony ServiceCVE-2026-42825Windows Telephony Service Elevation of Privilege VulnerabilityImportant
Windows Volume Manager Extension DriverCVE-2026-40380Windows Volume Manager Extension Driver Remote Code Execution VulnerabilityImportant
Windows Win32K – GRFXCVE-2026-33839Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32K – GRFXCVE-2026-40403Windows Graphics Component Remote Code Execution VulnerabilityCritical
Windows Win32K – GRFXCVE-2026-34347Windows Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32K – GRFXCVE-2026-34333Windows Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32K – GRFXCVE-2026-34330Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32K – GRFXCVE-2026-34331Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32K – ICOMPCVE-2026-35417Windows Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32K – ICOMPCVE-2026-33840Win32k Elevation of Privilege VulnerabilityImportant

Πηγή: www.bleepingcomputer.com

📧
Εγγραφείτε στο Newsletter του SecNews

Τα σημαντικότερα νέα Ασφάλειας & Τεχνολογίας στο Inbox σας.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

ΑΝΑΖΗΤΗΣΗ

FOLLOW US

📧
Newsletter SecNews
Τα σημαντικότερα νέα Ασφάλειας & Τεχνολογίας στο inbox σας.

LIVE NEWS