16 New Windows Vulnerabilities Discovered by Microsoft’s AI-Powered Agentic Security System

Key Takeaways

  • Microsoft introduced a new AI-powered vulnerability discovery system called MDASH.
  • The platform identified 16 new Windows vulnerabilities, including four Critical remote code execution flaws.
  • MDASH uses more than 100 specialised AI agents instead of a single AI model.
  • The system achieved 100% detection on a private Windows driver test with zero false positives.

In this post we are discussing 16 New Windows Vulnerabilities Discovered by Microsoft’s AI-Powered Agentic Security System. Recently, Microsoft announced a new AI-powered security system called MDASH (Microsoft Security multi-model agentic scanning harness) that can automatically find serious software vulnerabilities in Windows. Microsoft explains that the platform helped researchers discover 16 new security flaws, including several critical remote code execution bugs.

What is MDASH?

MDASH, short for Microsoft’s multi-model agentic scanning harness, is an AI-powered vulnerability discovery and remediation platform. Instead of depending on one AI model, the system combines multiple frontier and distilled models that work together through different stages of security analysis.

Table of Contents

16 New Windows Vulnerabilities Discovered by Microsoft’s AI-Powered Agentic Security System

The new system was developed by Microsoft’s Autonomous Code Security team and uses more than 100 specialized AI agents working together. Instead of relying on a single AI model, the platform analyzes code, validates findings, and tests whether vulnerabilities can actually be exploited.

What’s New in This Announcement?

Microsoft built a new AI system called MDASH. It uses many small AI agents working together to find security bugs faster. One of the biggest highlights is the discover of 16 vulnerabilities in Windows networking and authentication components during Microsoft’s Patch Tuesday cycle. Several of these bugs were found in highly sensitive services including:

Patch My PC
  • tcpip.sys
  • ikeext.dll
  • netlogon.dll
  • dnsapi.dll
  • http.sys
ComponentCVESeverityType
tcpip.sysCVE-2026-33827CriticalRemote Code Execution
tcpip.sysCVE-2026-40413ImportantDenial of Service (DoS)
tcpip.sysCVE-2026-40405ImportantDenial of Service
ikeext.dllCVE-2026-33824CriticalRemote Code Execution
tcpip.sysCVE-2026-40406ImportantInformation Disclosure
tcpip.sysCVE-2026-35422ImportantSecurity Feature Bypass
tcpip.sysCVE-2026-32209ImportantSecurity Feature Bypass
ikeext.dllCVE-2026-35424ImportantDenial of Service
telnet.exeCVE-2026-35423ImportantInformation Disclosure
tcpip.sysCVE-2026-40414ImportantDenial of Service
tcpip.sysCVE-2026-40401ImportantDenial of Service
tcpip.sysCVE-2026-40415ImportantRemote Code Execution
http.sysCVE-2026-33096ImportantDenial of Service
tcpip.sysCVE-2026-40399ImportantElevation of Privilege
netlogon.dllCVE-2026-41089CriticalRemote Code Execution
dnsapi.dllCVE-2026-41096CriticalRemote Code Execution
16 New Windows Vulnerabilities Discovered by Microsoft’s AI-Powered Agentic Security System -Table.1

AI Model Benchmark Performance Chart

The chart below shows the improvement of AI models in vulnerability discovery between 2024 and 2026. Earlier models achieved lower detection rates, while newer models such as GPT-5.5 and Claude Sonnet 4.6 showed significantly stronger performance. Microsoft’s MDASH multi-model system achieved one of the highest success rates by combining multiple AI models and specialised agents instead on asingle model.

16 New Windows Vulnerabilities Discovered by Microsoft’s AI-Powered Agentic Security System -Fig.1 Creds to MS
16 New Windows Vulnerabilities Discovered by Microsoft’s AI-Powered Agentic Security System -Fig.1Creds to MS

MDASH Workflow Architecture

Microsoft’s MDASH system automates vulnerability discovery using multiple AI agents. The workflow includes repository analysis, code scanning, bug validation, proof-of-concept generation, and automated patch validation. More than 100 specialised AI agents work together to identify vulnerabilities, reduce false positives, reproduce bugs, and recommend fixes across large enterprise codebases.

16 New Windows Vulnerabilities Discovered by Microsoft’s AI-Powered Agentic Security System -Fig.2 Creds to MS
16 New Windows Vulnerabilities Discovered by Microsoft’s AI-Powered Agentic Security System -Fig.2 Creds to MS

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the WhatsApp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair is a Workplace Technology solution architect with 25+ years of experience. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He is a blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, and Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Entra, and Microsoft Security.

Leave a Comment