Microsoft Skips a Zero-Day for the First Time in Two Years. Nobody Wants to Talk About Why.

118 fixes shipped, none under active exploit, and a quiet Anthropic project keeps surfacing in vendor briefings. Microsoft, Apple and Oracle declined to discuss it on the record.

ThreatVectr Newsdesk· 3 min read
Microsoft Skips a Zero-Day for the First Time in Two Years. Nobody Wants to Talk About Why.
Share

Microsoft shipped patches for 118 vulnerabilities on Tuesday across Windows and its product portfolio, and for the first time in roughly 24 months, none of them addressed a zero-day under active exploitation. Sixteen carry a critical rating. None were previously disclosed. That last detail matters, and Microsoft's Security Response Center will not say why this month broke the streak.

I asked. Twice.

The most serious of the lot is CVE-2026-41089, a stack-based buffer overflow in Windows Netlogon that hands SYSTEM on a domain controller to an unauthenticated attacker with low complexity and zero user interaction. Patches go back to Windows Server 2012. Rapid7 flagged it, alongside CVE-2026-41103, an Entra ID bypass via forged credentials that Microsoft itself rates "exploitation more likely." A DNS client RCE, CVE-2026-41096, rounds out the trio worth losing sleep over. Microsoft's writeup calls exploitation "less likely," which is the same language it used for three Exchange bugs in 2023 that were under attack within a fortnight.

The quiet thread running through every vendor brief this month is Project Glasswing, the Anthropic-built code-auditing capability that a few dozen large software makers have been given access to. Microsoft acknowledged its participation in a sentence. It would not say how many of this month's 118 fixes originated from Glasswing findings versus internal research or external bounty submissions. (Two follow-up emails to MSRC press, sent Tuesday morning and Wednesday afternoon, went unanswered at time of publication.)

Apple, also an early Glasswing participant, shipped fixes for at least 52 vulnerabilities on May 11 and backported them as far as iOS 15 on the iPhone 6s. Apple typically ships around 20 per cycle, said Chris Goettl, vice president of product management at Ivanti. That is more than double the usual count. Apple's security release notes do not credit Anthropic, Glasswing, or any AI-assisted discovery. I asked Apple's product security team to confirm whether any of the 52 came from the program. The reply was the standard "we do not comment on the sourcing of vulnerability reports."

Mozilla resolved 271 vulnerabilities in Firefox 150, reportedly during the Glasswing evaluation, and has since moved to a weekly security cadence. Oracle's most recent quarterly update closed 450 flaws, over 300 of them remotely exploitable without authentication, and the company has now switched to monthly criticals. Google's Chrome update on May 8 patched 127 bugs, up from 30 the prior month. None of these vendors will say, on the record, what percentage of those findings an AI surfaced.

Anthropic's press team confirmed Glasswing exists. It declined to provide a participant list, a discovery count, or a methodology document. The company pointed to a forthcoming research post. No date.

So here is the question nobody is answering: if an LLM is now finding hundreds of exploitable bugs per vendor per quarter in shipping code, who else is running the same playbook, and against whom?

© 2026 Threat Vectr