Microsoft’s agentic security system MDASH uncovers four critical Windows RCE flaws
Not a pilot. Microsoft's AI agents just found 16 Windows flaws humans missed—including 4 critical RCEs.

Why it matters
Microsoft deployed an agentic AI system (MDASH) into production security work, proving autonomous agents can scale vulnerability discovery beyond manual pentesting. This signals a shift from AI-as-analyst to AI-as-operator in enterprise security.
The key facts
6 to knowSystem name: MDASH (multi-model agentic scanning harness)
16 previously unknown flaws discovered
4 critical remote code execution (RCE) bugs patched in May 2026 Patch Tuesday
Built by Microsoft's Autonomous Code Security team
Targets Windows networking and authentication components
Production deployment (not research/pilot phase)
Go to the source
SiliconAnglesiliconangle.com
Publisher excerpt: Microsoft Corp. today detailed a new artificial intelligence-powered vulnerability discovery system that uncovered 16 previously unknown flaws in Windows networking and authentication components, including four critical remote code execution bugs patched in this month’s Patch Tuesday release. The…