---
schema: 1
kind: research
title: Microsoft MDASH — multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack kernel components
headline: Microsoft MDASH — multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack kernel components
summary: "Microsoft's Autonomous Code Security team published a detailed technical disclosure on 2026-05-12 of MDASH, an AI-orchestrated vulnerability-discovery pipeline running over 100 specialised agents across an ensemble of frontier and distilled models (Microsoft Security Blog, 2026-05-12)."
discovered_at: "2026-05-13T05:00:08Z"
event_date: 2026-05-13
run_id: 2026-05-13-c148b9a5
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - ai-abuse
regions:
  - global
sectors: []
entities:
  - "tool:microsoft-mdash-2026"
cves: []
sources:
  - url: "https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-finds-16-new-vulnerabilities/"
    publisher: "Microsoft Security Blog, 2026-05-12"
    role: primary
  - url: "https://www.theregister.com/patches/2026/05/13/doozy-of-a-patch-tuesday-includes-30-critical-microsoft-cves/5239224"
    publisher: "The Register, 2026-05-13"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-13.md
---

Microsoft's Autonomous Code Security team published a detailed technical disclosure on 2026-05-12 of MDASH, an AI-orchestrated vulnerability-discovery pipeline running over 100 specialised agents across an ensemble of frontier and distilled models ([Microsoft Security Blog, 2026-05-12](https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-finds-16-new-vulnerabilities/)). The pipeline executes a five-stage prepare → scan → validate → dedup → prove loop that ends with an **automated end-to-end exploitability proof** before a finding is sent to engineering — meaning every MDASH-disclosed CVE was validated as practically exploitable, not just theoretically reachable. In MDASH's first production run against Windows the harness produced 16 previously unknown CVEs concentrated in the network-exposed kernel attack surface — `tcpip.sys` (Windows TCP/IP stack), `ikeext.dll` (the Windows IKEv2 keying service for DirectAccess and Always-On VPN), `netlogon.dll`, and `dnsapi.dll` — split as 10 kernel-mode and 6 user-mode bugs, including four Critical RCEs. The harness scored 88.45% on the public CyberGym benchmark (1,507 real-world CVEs across 188 open-source projects) and achieved 100% recall on the `tcpip.sys` historical-CVE corpus ([The Register, 2026-05-13](https://www.theregister.com/patches/2026/05/13/doozy-of-a-patch-tuesday-includes-30-critical-microsoft-cves/5239224)). Microsoft has scheduled a customer-facing preview of the harness for June 2026.

**Defender takeaway:** Two operational implications. First, the MDASH-discovered Windows CVEs (a substantial subset of the May 2026 Patch Tuesday in § 2) should be treated as "practically exploitable" even without observed ITW activity, because the proof-of-exploitability stage runs before disclosure — that lifts these above the typical "Less Likely / More Likely" scoring noise. Second, the `ikeext.dll` surface is directly relevant to EU public-sector remote-access deployments: DirectAccess and Always-On VPN are widely deployed as the AD-integrated remote-access primitive across Swiss federal and EU government estates; any unauthenticated bug in `ikeext.dll` is a remote-perimeter risk. Mapped to `T1190 Exploit Public-Facing Application` and `T1133 External Remote Services`. Hardening: expedite May 2026 cumulative update on internet-exposed Windows hosts with DirectAccess / Always-On VPN; verify the network-perimeter ACL still scopes IKEv2 reach to known client networks.
