Serial number:AV26-456
Date:May 12, 2026
Updated: May 27, 2026
On May 12, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:
- .NET 10.0 installed on Linux
- .NET 10.0 installed on Mac OS
- .NET 10.0 installed on Windows
- .NET 8.0 installed on Linux
- .NET 8.0 installed on Mac OS
- .NET 8.0 installed on Windows
- .NET 9.0 installed on Linux
- .NET 9.0 installed on Mac OS
- .NET 9.0 installed on Windows
- Azure AI Foundry
- Azure Cloud Shell
- Azure Connected Machine Agent
- Azure DevOps
- Azure Logic Apps
- Azure Machine Learning
- Azure Managed Instance for Apache Cassandra
- Azure Monitor Action Group notification system
- Azure Monitor Agent
- Azure Monitor Agent Metrics Extension
- Azure SDK for Java
- Copilot Chat (Microsoft Edge)
- Dynamics 365 Customer Insights
- M365 Copilot for Desktop
- Microsoft .NET Framework 3.5
- Microsoft .NET Framework 3.5 AND 4.7.2
- Microsoft .NET Framework 3.5 AND 4.8
- Microsoft .NET Framework 3.5 AND 4.8.1
- Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2
- Microsoft .NET Framework 4.8
- Microsoft 365
- Microsoft 365 Copilot for Android
- Microsoft 365 Copilot's Business Chat
- Microsoft Confluence SAML SSO plugin
- Microsoft Data Formulator
- Microsoft Dynamics 365
- Microsoft Dynamics 365 Business Central
- Microsoft Edge (Chromium-based)
- Microsoft Enterprise Security Token Service (ESTS)
- Microsoft Excel 2016
- Microsoft Excel for Android
- Microsoft JIRA SAML SSO plugin
- Microsoft Office 2016
- Microsoft Office 2019
- Microsoft Office LTSC 2021
- Microsoft Office LTSC 2024
- Microsoft Office LTSC for Mac 2021
- Microsoft Office LTSC for Mac 2024
- Microsoft Office for Android
- Microsoft Outlook for iOS
- Microsoft Partner Center
- Microsoft PowerPoint for Android
- Microsoft SQL Server 2016
- Microsoft SQL Server 2017
- Microsoft SQL Server 2019
- Microsoft SQL Server 2022
- Microsoft SQL Server 2025
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
- Microsoft Teams
- Microsoft Teams for Android
- Microsoft Visual Studio 2017
- Microsoft Visual Studio 2019
- Microsoft Visual Studio 2022
- Microsoft Visual Studio 2026
- Microsoft Word 2016
- Microsoft Word for Android
- Office Online Server
- Power Automate for Desktop
- Visual Studio Code
- Visual Studio Code - Live Preview extension
- Windows 10
- Windows 11
- Windows Admin Center
- Windows Admin Center in Azure Portal
- Windows Server 2012
- Windows Server 2016
- Windows Server 2019
- Windows Server 2025
Update 1
On May 21, 2026, Microsoft published an out-of-band (OOB) security update to address CVE-2026-45659, an additional vulnerability impacting Microsoft SharePoint Enterprise Server 2019, Microsoft SharePoint Server 2016 and Microsoft SharePoint Server Subscription Edition. The CVE was inadvertently omitted from the May 2026 Security Updates.
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.


