Patch Tuesday cycleMay 2026 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

May 2026 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 116 operational patch records link 183 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

116Patch recordsStable operational entries, not CVE duplicates
183Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
0Accelerated actionsNo accelerated action in this view
0Revised entriesCanonical history remains visible

May 2026 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
116 matching recordsPage 1 of 6
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB26-49 · Updated 2026-05-12
Product and releaseAdobe Commerce2.4.9 2.4.8-p5 2.4.7-p10 2.4.6-p15 2.4.5-p17 2.4.4-p18, 1.5.3 1.5.2-p5 1.4.2-p10 1.3.4-p17 1.3.3-p18, 2.4.9 2.4.8-p5 2.4.7-p10 2.4.6-p15
Review linked CVEs (15) No confirmed exploitation stated

Operational summary

Adobe published APSB26-49 on Patch Tuesday for Adobe Commerce. The bulletin links 15 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-49
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.7; Adobe priority 2

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Designer to the fixed Adobe releaseAPSB26-52 · Updated 2026-05-12
Product and releaseAdobe Substance 3D Designer16.0.1
Review linked CVEs (5) No confirmed exploitation stated

Operational summary

Adobe published APSB26-52 on Patch Tuesday for Adobe Substance 3D Designer. The bulletin links 5 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-52
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 6.3; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (5)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Sampler to the fixed Adobe releaseAPSB26-54 · Updated 2026-05-12
Product and releaseAdobe Substance 3D Sampler6.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-54 on Patch Tuesday for Adobe Substance 3D Sampler. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-54
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Painter to the fixed Adobe releaseAPSB26-55 · Updated 2026-05-12
Product and releaseAdobe Substance 3D Painter12.0.3
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-55 on Patch Tuesday for Adobe Substance 3D Painter. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-55
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Premiere Pro to the fixed Adobe releaseAPSB26-46 · Updated 2026-05-12
Product and releaseAdobe Premiere Pro26.2, 25.6.5
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB26-46 on Patch Tuesday for Adobe Premiere Pro. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-46
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Media Encoder to the fixed Adobe releaseAPSB26-47 · Updated 2026-05-12
Product and releaseAdobe Media Encoder25.6.5, 26.2
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-47 on Patch Tuesday for Adobe Media Encoder. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-47
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe After Effects to the fixed Adobe releaseAPSB26-48 · Updated 2026-05-12
Product and releaseAdobe After Effects25.6.5, 26.2
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB26-48 on Patch Tuesday for Adobe After Effects. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-48
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Connect to the fixed Adobe releaseAPSB26-50 · Updated 2026-05-12
Product and releaseAdobe Connect2026.3.125 (Windows) 2026.01.39 (macOS)
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-50 on Patch Tuesday for Adobe Connect. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-50
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 9.6; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.6
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB26-51 · Updated 2026-05-12
Product and releaseAdobe Illustrator29.8.7, 30.4
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

Adobe published APSB26-51 on Patch Tuesday for Adobe Illustrator. The bulletin links 4 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-51
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Content Credentials SDK to the fixed Adobe releaseAPSB26-53 · Updated 2026-05-12
Product and releaseContent Credentials SDK@contentauth/c2pa-web@0.7.1, c2pa-v0.80.1
Review linked CVEs (14) No confirmed exploitation stated

Operational summary

Adobe published APSB26-53 on Patch Tuesday for Content Credentials SDK. The bulletin links 14 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-53
Platform
Windows, macOS, Linux, iOS, Android
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.5; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Apps update for Microsoft Word for AndroidMSRC-2026-05-apps-release-notes · Updated 2026-05-12
Product and releaseMicrosoft Word for Android16.0.19822.20190
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Word for Android.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-05-apps-release-notes
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.7
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for M365 Copilot for DesktopMSRC-2026-05-apps-release-notes · Updated 2026-05-12
Product and releaseM365 Copilot for Desktop19.2604.43111.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for M365 Copilot for Desktop.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-05-apps-release-notes
Platform
Apps
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 6.2
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Microsoft 365 Copilot for AndroidMSRC-2026-05-apps-release-notes · Updated 2026-05-12
Product and releaseMicrosoft 365 Copilot for Android16.0.19822.20190
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft 365 Copilot for Android.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-05-apps-release-notes
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 4.4
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Monitor AgentMSRC-2026-05-azure-release-notes · Updated 2026-05-12
Product and releaseAzure Monitor Agent1.14.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Monitor Agent.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-05-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure SDK for JavaMSRC-2026-05-azure-release-notes · Updated 2026-05-12
Product and releaseAzure SDK for Java4.10.6
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure SDK for Java.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-05-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Machine LearningMSRC-2026-05-azure-release-notes · Updated 2026-05-12
Product and releaseAzure Machine Learning1.7.6
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Machine Learning.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-05-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.2
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Connected Machine AgentMSRC-2026-05-azure-release-notes · Updated 2026-05-12
Product and releaseAzure Connected Machine Agent1.63
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Connected Machine Agent.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-05-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft JIRA SAML SSO pluginMSRC-2026-05-azure-release-notes · Updated 2026-05-12
Product and releaseMicrosoft JIRA SAML SSO plugin1.3.3
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft JIRA SAML SSO plugin.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-05-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft Confluence SAML SSO pluginMSRC-2026-05-azure-release-notes · Updated 2026-05-12
Product and releaseMicrosoft Confluence SAML SSO plugin7.4.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Confluence SAML SSO plugin.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-05-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Monitor Agent Metrics ExtensionMSRC-2026-05-azure-release-notes · Updated 2026-05-12
Product and releaseAzure Monitor Agent Metrics Extension1.42.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Monitor Agent Metrics Extension.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-05-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 6.5
Confirmed exploitedCVSS above 9.0