AI News #Microsoft#cybersecurity#AI agents#vulnerability discovery#Patch Tuesday

Microsoft MDASH: Multi-Model AI Security System Finds 16 Zero-Day Vulnerabilities

Microsoft's new agentic security system MDASH orchestrates over 100 specialized AI agents to discover vulnerabilities, topping industry benchmarks.

Tuesday May 12, 2026
Microsoft MDASH: Multi-Model AI Security System Finds 16 Zero-Day Vulnerabilities

Microsoft unveiled MDASH (Multi-model Agentic Scanning Harness), a security system that orchestrates over 100 specialized AI agents to discover and validate software vulnerabilities. In its first major deployment, it found 16 new vulnerabilities in Windows networking and authentication — including four critical remote code execution flaws. The system achieved an industry-leading 88.45% score on the public CyberGym benchmark.

What Is Microsoft MDASH?

MDASH is a multi-model agentic scanning harness built by Microsoft’s Autonomous Code Security team. Unlike single-model approaches, it uses an ensemble of frontier and distilled AI models working together. These agents discover, debate, and prove exploitable bugs end-to-end, mimicking how a team of human security researchers would operate — but at machine speed.

How Well Did MDASH Perform?

The results were striking:

What Vulnerabilities Did It Find?

This month’s Patch Tuesday includes 16 CVEs found by MDASH, including:

Key Takeaways

Frequently Asked Questions

Is MDASH replacing human security researchers? No. MDASH augments human teams by automating vulnerability discovery at scale. Human researchers still validate and prioritize findings.

What models power MDASH? The system uses an ensemble of frontier and distilled models. Microsoft notes the surrounding agentic system contributes substantially to performance beyond any single model’s capability.

How can I access MDASH? It is currently being used by Microsoft security engineering teams and tested by a small set of customers as part of a limited private preview.

Back to all news