INTEL_REPORT
Cisco Talos Blog · published 5/12/2026, 7:57:04 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities Microsoft has released its monthly security update for May 2026, which includes 112 vulnerabilities affecting a range of products, including 16 that Microsoft marked as “critical”. By   Jaeson Schultz   Microsoft has released its monthly security update for May 2026, which includes 137 vulnerabilities affecting a range of products, including 31 that Microsoft …
https://blog.talosintelligence.com/microsoft-patch-tuesday-may-2026
sha256:8dc41695a60ed334cda4264bdcacf1decd3abfe6a9e81066561969c841876daa
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| CVE-2026-35421 |
| Open → |
| cve | CVE-2026-40358 | Open → |
| cve | CVE-2026-40361 | Open → |
| cve | CVE-2026-40363 | Open → |
| cve | CVE-2026-40364 | Open → |
| cve | CVE-2026-40365 | Open → |
| cve | CVE-2026-40366 | Open → |
| cve | CVE-2026-40367 | Open → |
| cve | CVE-2026-40403 | Open → |
| cve | CVE-2026-42831 | Open → |
| cve | CVE-2026-42898 | Open → |
| cve | CVE-2026-33835 | Open → |
| cve | CVE-2026-33837 | Open → |
| cve | CVE-2026-33840 | Open → |
| cve | CVE-2026-33841 | Open → |
| cve | CVE-2026-35416 | Open → |
| cve | CVE-2026-35417 | Open → |
| cve | CVE-2026-40369 | Open → |
| cve | CVE-2026-40397 | Open → |
| cve | CVE-2026-40398 | Open → |