# MDASH: Microsoft’s Agentic Scanner Finds 16 Windows Vulns — Same Day as Patch Tuesday

Times of AI Desk · 2026-05-12 · Security

[https://timesof.ai/2026/05/microsoft-mdash-agentic-security-scanning](https://timesof.ai/2026/05/microsoft-mdash-agentic-security-scanning)

> Microsoft Security’s MDASH — 100+ specialized agents in a multi-model scanning harness — helped find 16 Windows vulnerabilities (4 critical RCEs) shipping in the May 12 Patch Tuesday wave, while topping CyberGym-style benches in limited private preview. Dual-use agent stacks now sit next to the patch calendar.

Agentic coding tools are dual-use: the same stack that ships features can **hunt CVEs**. Putting MDASH next to **Patch Tuesday** makes “AI found the bugs we fixed today” a hyperscaler security story — not a research demo.

**Microsoft Security** (May 12) published “Defense at AI speed,” introducing **MDASH** (multi-model agentic scanning harness) from the Autonomous Code Security team. Microsoft said MDASH helped researchers identify **16 new Windows vulnerabilities** in networking and authentication — including **four critical remote code execution** flaws — that went out in the **May 12 Patch Tuesday** wave. The system orchestrates **100+ specialized AI agents** across an ensemble of models; in use by Microsoft security engineering and a **limited private preview** for select customers.

## What MDASH is

| Claim (Microsoft primary) | Detail |
|---------------------------|--------|
| **Architecture** | Harness of specialized agents (discovery, validation, exploit proof, remediation assist) — not a single model |
| **Results at launch** | 16 Windows vulns; 4 critical RCE-class; networking/authentication focus |
| **Benchmark** | Topped a leading CyberGym-style industry leaderboard score at announcement |
| **Status** | Internal production use; small customer private preview |

## Claims vs checks

Vuln counts and Patch Tuesday linkage are **Microsoft Security Blog primary**. CyberGym-style “topped” is a **vendor-cited bench** — treat as Microsoft’s snapshot, not an independent SOC audit of residual Windows risk. Later June Build follow-ups cited further score gains (secondary to this May story).

## Limits

- Limited private preview — not broadly available at announcement.
- Ensemble performance depends on model mix and harness; not transferable as a single-model Elo.
- Competitive bar vs OpenAI Daybreak / Anthropic Glasswing is desk framing.

## Sources

- Microsoft Security Blog: “Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark” (May 12, 2026).
- Microsoft Security follow-ups on MDASH preview/internal use (June 2026).
- Independent technical recaps of the May 12 CVE cohort and MDASH pipeline (May–June 2026).
