BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
May 2026 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 116 operational patch records link 183 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
May 2026 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB26-49 · Updated 2026-05-12Product and releaseAdobe Commerce2.4.9 2.4.8-p5 2.4.7-p10 2.4.6-p15 2.4.5-p17 2.4.4-p18, 1.5.3 1.5.2-p5 1.4.2-p10 1.3.4-p17 1.3.3-p18, 2.4.9 2.4.8-p5 2.4.7-p10 2.4.6-p15Review linked CVEs (15) No confirmed exploitation stated
Operational summary
Adobe published APSB26-49 on Patch Tuesday for Adobe Commerce. The bulletin links 15 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-49
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 8.7; Adobe priority 2
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Designer to the fixed Adobe releaseAPSB26-52 · Updated 2026-05-12Product and releaseAdobe Substance 3D Designer16.0.1Review linked CVEs (5) No confirmed exploitation stated
Operational summary
Adobe published APSB26-52 on Patch Tuesday for Adobe Substance 3D Designer. The bulletin links 5 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-52
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 6.3; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Sampler to the fixed Adobe releaseAPSB26-54 · Updated 2026-05-12Product and releaseAdobe Substance 3D Sampler6.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB26-54 on Patch Tuesday for Adobe Substance 3D Sampler. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-54
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Painter to the fixed Adobe releaseAPSB26-55 · Updated 2026-05-12Product and releaseAdobe Substance 3D Painter12.0.3Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB26-55 on Patch Tuesday for Adobe Substance 3D Painter. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-55
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Premiere Pro to the fixed Adobe releaseAPSB26-46 · Updated 2026-05-12Product and releaseAdobe Premiere Pro26.2, 25.6.5Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB26-46 on Patch Tuesday for Adobe Premiere Pro. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-46
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Media Encoder to the fixed Adobe releaseAPSB26-47 · Updated 2026-05-12Product and releaseAdobe Media Encoder25.6.5, 26.2Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB26-47 on Patch Tuesday for Adobe Media Encoder. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-47
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe After Effects to the fixed Adobe releaseAPSB26-48 · Updated 2026-05-12Product and releaseAdobe After Effects25.6.5, 26.2Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB26-48 on Patch Tuesday for Adobe After Effects. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-48
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Connect to the fixed Adobe releaseAPSB26-50 · Updated 2026-05-12Product and releaseAdobe Connect2026.3.125 (Windows) 2026.01.39 (macOS)Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB26-50 on Patch Tuesday for Adobe Connect. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-50
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.6; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB26-51 · Updated 2026-05-12Product and releaseAdobe Illustrator29.8.7, 30.4Review linked CVEs (4) No confirmed exploitation stated
Operational summary
Adobe published APSB26-51 on Patch Tuesday for Adobe Illustrator. The bulletin links 4 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-51
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Content Credentials SDK to the fixed Adobe releaseAPSB26-53 · Updated 2026-05-12Product and releaseContent Credentials SDK@contentauth/c2pa-web@0.7.1, c2pa-v0.80.1Review linked CVEs (14) No confirmed exploitation stated
Operational summary
Adobe published APSB26-53 on Patch Tuesday for Content Credentials SDK. The bulletin links 14 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-53
- Platform
- Windows, macOS, Linux, iOS, Android
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.5; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Apps update for Microsoft Word for AndroidMSRC-2026-05-apps-release-notes · Updated 2026-05-12Product and releaseMicrosoft Word for Android16.0.19822.20190Review linked CVEs (3) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Word for Android.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-05-apps-release-notes
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Apps update for M365 Copilot for DesktopMSRC-2026-05-apps-release-notes · Updated 2026-05-12Product and releaseM365 Copilot for Desktop19.2604.43111.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for M365 Copilot for Desktop.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-05-apps-release-notes
- Platform
- Apps
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Apps update for Microsoft 365 Copilot for AndroidMSRC-2026-05-apps-release-notes · Updated 2026-05-12Product and releaseMicrosoft 365 Copilot for Android16.0.19822.20190Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft 365 Copilot for Android.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-05-apps-release-notes
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Monitor AgentMSRC-2026-05-azure-release-notes · Updated 2026-05-12Product and releaseAzure Monitor Agent1.14.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Monitor Agent.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-05-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure SDK for JavaMSRC-2026-05-azure-release-notes · Updated 2026-05-12Product and releaseAzure SDK for Java4.10.6Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure SDK for Java.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-05-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Machine LearningMSRC-2026-05-azure-release-notes · Updated 2026-05-12Product and releaseAzure Machine Learning1.7.6Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Machine Learning.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-05-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Connected Machine AgentMSRC-2026-05-azure-release-notes · Updated 2026-05-12Product and releaseAzure Connected Machine Agent1.63Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Connected Machine Agent.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-05-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Microsoft JIRA SAML SSO pluginMSRC-2026-05-azure-release-notes · Updated 2026-05-12Product and releaseMicrosoft JIRA SAML SSO plugin1.3.3Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft JIRA SAML SSO plugin.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-05-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Microsoft Confluence SAML SSO pluginMSRC-2026-05-azure-release-notes · Updated 2026-05-12Product and releaseMicrosoft Confluence SAML SSO plugin7.4.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Confluence SAML SSO plugin.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-05-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Monitor Agent Metrics ExtensionMSRC-2026-05-azure-release-notes · Updated 2026-05-12Product and releaseAzure Monitor Agent Metrics Extension1.42.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Monitor Agent Metrics Extension.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-05-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.