Microsoft has unveiled MDASH, a new artificial intelligence (AI)-powered vulnerability discovery system that has managed to identify 16 previously unknown vulnerabilities in Windows. Among them are four critical remote code execution (RCEs).

The MDASH system was developed by Microsoft's Autonomous Code Security team in collaboration with the Windows Attack Research and Protection team . The platform will enter private preview for enterprise customers next month.
The vulnerabilities, which were identified, were fixed as part of the Patch Tuesday on May 12.
“Cyberdefenses are facing an increasingly asymmetric battle,” Microsoft said in a blog post. “Attackers are using AI to increase the speed, scale, and sophistication of attacks.”
Critical Windows components affected by vulnerabilities
The four critical vulnerabilities affected key Windows components that are widely deployed in corporate environments.
See also: Japanese banks gain access to Anthropic's Mythos
Among them was CVE-2026-33827, a use-after-free vulnerability in the Windows IPv4 stack. Another vulnerability, CVE-2026-33824, involved a pre-authentication double-free issue in the IKEEXT that affects RRAS VPN, DirectAccess, and Always-On VPN deployments.
Two additional critical vulnerabilities affected Netlogon and Windows DNS Client, both with CVSS scores of 9.8. The remaining 12 vulnerabilities, rated “Important,” included denial-of-service, privilege escalation, information disclosure, and security feature bypass vulnerabilities affecting components such as tcpip.sys, http.sys, ikeext.dll, and telnet.exe.

How MDASH organizes AI agents
According to Microsoft, MDASH organizes more than 100 specialized AI agents into multiple frontier and distilled models, with each agent participating in a different stage of the vulnerability discovery process. Some agents scan source code for potential vulnerabilities, others validate whether the findings are genuine, and another stage tries to construct triggering inputs capable of reproducing the issue before the finding reaches an engineer for review.
“The model is an input. The system is the product,” wrote Taesoo Kim, Microsoft’s vice president of security agents.
Microsoft said the architecture was intentionally designed to remain largely model- agnostic , allowing the company to change the underlying AI models without rebuilding the broader organizational pipeline. This detail is significant because MDASH comes just weeks after Microsoft announced Project Glasswing , a collaboration involving Anthropic and others to evaluate vulnerability discovery using Anthropic’s Claude Mythos Preview model .
“Microsoft now operates as a platform owner, security vendor, AI infrastructure player, OpenAI partner, Mythos integrator, and agentic security vendor,” said Sanchit Vir Gogia, principal analyst at Greyhound Research. “This is a powerful position. It is also a concentration of influence that security leaders need to consider with clear eyes.”
See also: Android Intrusion Logging: New Spyware Detection Feature

AI and vulnerabilities
The announcement also highlights growing concern that AI-powered vulnerability discovery could accelerate offensive operations as well as defensive research. Anthropic has previously said that its Mythos Preview model has identified thousands of high-severity vulnerabilities, including a decade-old vulnerability in OpenBSD and an issue in FFmpeg that had remained unknown for a long time (despite millions of attempts by traditional fuzzing tools).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Experts suggest that businesses should seek early access to systems like MDASH, where possible, rather than waiting for wider commercial availability.
For CISOs, the broader implication may be that vulnerability management shifts from periodic scanning to continuous, AI-assisted discovery and remediation.
“The future belongs to security teams that can find, validate, mitigate, and remediate in a controlled manner,” said Sanchit Vir Gogia.
Benchmarks show progress, but caution is needed
To support its claims, Microsoft published benchmark results showing that MDASH detected all 21 intentionally placed vulnerabilities in an internal Windows test driver, with no false positives.
The company also stated that the system successfully recovered almost all Microsoft Security Response Center cases tested on older Windows component snapshots.
In the public CyberGym benchmark for vulnerability replication tasks, Microsoft said that MDASH achieved a score of 88.45%, topping the public rankings at the time of publication.
See also: Claude Mythos finds only one vulnerability in Curl – what is it?
Gogia said the results show the category is maturing, but cautioned against treating benchmark scores as direct evidence of business value. “CyberGym is a brand, not a buying decision,” he said.
He added that many enterprises still lack the governance maturity required to effectively operate AI vulnerability discovery.

The MDASH revelations signal that the battle between cybercriminals and security firms is entering a new era, one in which artificial intelligence will play a leading role in both offense and defense. Microsoft is trying to position itself at the forefront of this transition, investing in autonomous systems that can identify vulnerabilities with a speed and accuracy that traditional security teams can hardly achieve. However, the same technology also raises new concerns, as the automation of exploit discovery could also be used by malicious actors to develop more sophisticated cyberattacks.
For businesses, the message is clear: cybersecurity is gradually transforming from a periodic process of checks to a continuous, AI-driven ecosystem of prevention and immediate response. Organizations that do not invest in automated vulnerability detection and remediation technologies in a timely manner may find themselves faced with a threat environment that evolves faster than traditional defense capabilities.
