Visualização de leitura

Microsoft Patches Record 200 Vulnerabilities in June 2026 Patch Tuesday

June 2026 Patch Tuesday

Microsoft's June 2026 Patch Tuesday, released on June 10, 2026, addressed 200 security vulnerabilities across Windows, Office, Azure, and related products—the largest single Patch Tuesday release in the programme's history, surpassing the previous record of 167 CVEs. The update includes fixes for three publicly disclosed zero-day vulnerabilities and 33 critical-severity flaws. The June 2026 release patches vulnerabilities across all major Microsoft product families: Windows 11 and Windows Server, Microsoft Office, Exchange Server, .NET Framework, Azure services, Hyper-V, Remote Desktop Services, and HTTP.sys. Of the 200 CVEs addressed, 33 are rated Critical, 166 are rated Important, and one is rated Moderate. Twenty-eight of the critical flaws are remote code execution vulnerabilities, four are elevation of privilege issues, and one is an information disclosure flaw.

June 2026 Patch Tuesday: Three Zero-Day Vulnerabilities

This month's release includes patches for three publicly disclosed zero-days. None are currently known to be under active exploitation, but security researchers note that patch reversal is underway. CVE-2026-50507 – Windows BitLocker Bypass (publicly disclosed): This vulnerability, nicknamed "YellowKey" by the researcher who discovered it, allows a local attacker with physical access to a device to bypass BitLocker's full-disk encryption and access data on an encrypted drive. The flaw requires local access and an elevated privilege context, reducing immediate remote risk—but it is significant for organisations that rely on BitLocker to protect data on lost or stolen hardware. The severity rating is Important. CVE-2026-49160 – HTTP/2 Denial of Service (publicly disclosed): Dubbed "HTTP/2 Bomb," this vulnerability was publicly disclosed by researchers at offensive security firm Calif before the patch was available. An unauthenticated remote attacker can exhaust server memory by sending crafted HTTP/2 frames, causing denial of service on Windows IIS and other HTTP.sys-dependent services. CVE-2026-45586 – Windows CTFMON Privilege Escalation (publicly disclosed): This elevation-of-privilege flaw in the Windows Collaborative Translation Framework Monitor (ctfmon.exe) grants a logged-in attacker SYSTEM-level privileges. While exploitation requires local access, it is a valuable component in multi-stage attack chains following initial compromise. Headline Critical Vulnerability: CVE-2026-45657
Beyond the three zero-days, security professionals should prioritise CVE-2026-45657, a Windows Kernel use-after-free vulnerability with a CVSS score of 9.8. The flaw stems from improper handling of TCP/IP operations within the Windows Kernel and allows a remote, unauthenticated attacker to execute arbitrary code at the SYSTEM level with no user interaction. Microsoft has classified it as "wormable" under certain network configurations. "CVE-2026-45657 is the kind of vulnerability that keeps defenders up at night," said a Zero Day Initiative researcher. The CVSS 9.8 score, combined with wormable potential, means we could see mass exploitation the moment a reliable exploit is developed.
The record-breaking scale of this month's release creates prioritisation challenges for already-stretched security teams. Microsoft and independent researchers recommend prioritising patches for BitLocker-protected devices, HTTP.sys and IIS infrastructure, Remote Desktop Services, Hyper-V hosts, and Windows Kernel components.

Mitigation Steps

  • Deploy June 2026 cumulative updates (KB5094126 for Windows 11, KB5094127 for Windows 10) without delay.
  • Prioritise CVE-2026-45657 patching on all internet-accessible Windows systems.
  • Apply the IIS/HTTP.sys patch for CVE-2026-49160 on all public-facing web servers.
  • Audit BitLocker-protected device inventory and apply CVE-2026-50507 patches before deploying new field hardware.
  • Review CTFMON and SYSTEM privilege escalation detections in endpoint security tooling.
  • Use the Microsoft Security Update Guide (msrc.microsoft.com) to filter by CVSS >= 9.0 for prioritisation.
  • Validate patch deployment through automated compliance reporting within 72 hours.

Microsoft’s biggest-ever Patch Tuesday fixes 206 bugs, including 3 zero-days

This month’s Patch Tuesday fixes 206 security flaws in Microsoft software, making it the biggest Patch Tuesday release ever.

The update includes 32 critical vulnerabilities, as well as three publicly disclosed zero-days. Microsoft classifies these as zero-days because information about the vulnerabilities became public before patches were available. None are known to have been actively exploited by attackers.

The huge number of fixed vulnerabilities makes this the largest Patch Tuesday since Microsoft launched the program in October 2003. The company introduced the monthly update schedule after the Blaster worm caused disruption in the early days of Windows.

How to apply patches and check if you’re protected

These updates fix security problems and keep your Windows PC protected. Here’s how to make sure you’re up to date:

1. Open Settings

  • Click the Start button (the Windows logo at the bottom left of your screen).
  • Click on Settings (it looks like a little gear).

2. Go to Windows Update

  • In the Settings window, select Windows Update (usually at the bottom of the menu on the left).

3. Check for updates

  • Click the button that says Check for updates.
  • Windows will search for the latest Patch Tuesday updates.
  • If you have selected to get the latest updates as soon as they’re available, you may see this under More options.
    In which case you may see a Restart required message. Restart your system and the update will complete.
    restart required
  • If not, continue with the steps below.

4. Download and install

  • If updates are found, they’ll start downloading automatically. Once complete, you’ll see a button that says Install or Restart now.
  • Click Install if needed and follow any prompts. Your computer will usually need a restart to finish the update. If it does, click Restart now.

5. Double-check you’re up to date

  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set!
Windows up to date

Technical details

One publicly disclosed vulnerability is important to mention. This flaw in Windows BitLocker is tracked as CVE-2026-50507 (CVSS score: 6.8 out of 10) and its description states:

“a protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.”

BitLocker is a built-in Windows security feature that encrypts your entire hard drive, securing your data from unauthorized access if your device is lost or stolen. However, this vulnerability could allow an attacker with physical access to bypass BitLocker Device Encryption and gain access to encrypted data.

Another is CVE-2026-49160 (CVSS score: 7.5 out of 10) in HTTP.sys. This vulnerability can be exploited to launch a remote denial-of-service attack against major web servers using a technique called HTTP/2 Bomb.

The third to discuss is CVE-2026-45586 (CVSS score: 7.8 out of 10) in the Windows Collaborative Translation Framework (CTFMON). An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. These elevation of privilege (EoP) vulnerabilities are especially valuable to attackers because they can be combined with other flaws to gain full control of a compromised system.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.

The software giant said in a blog post last month that both its engineers and the security community are increasing using artificial intelligence tools to find bugs, meaning this month’s heavy Patch Tuesday may start to become the norm, said Satnam Narang, senior staff research engineer at Tenable.

“Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said. “Pandora’s proverbial box has been opened, and as more advanced AI models become available, we expect the norm to continue upward across the board, not just for Patch Tuesday.”

June’s zero-day bugs include CVE-2026-49160, a denial of service vulnerability affecting a range of web servers, including Microsoft Internet Information Services (IIS). Microsoft says the flaw was reported by OpenAI’s Codex.

Two of the zero-days addressed this month appear to stem from recent vulnerability disclosures by Nightmare Eclipse, the nickname chosen by a security researcher who has been dropping exploits for various Windows flaws. One of those, dubbed “GreenPlasma,” leverages an elevation of privilege weakness in the Windows Collaborative Translation Framework, the same framework patched today in CVE-2026-45586.

Nightmare Eclipse also last month released “YellowKey,” an exploit for a Windows BitLocker vulnerability that allows an attacker with physical access to view encrypted data, and CVE-2026-50507 is a patch for an elevation of privilege bug in BitLocker.

Microsoft received heavy blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher. The company later clarified on Twitter/X that while it has no intention of pursuing legal actions against researchers, it would report them to authorities if they break the law. The advisories for CVE-2026-49160 and CVE-2026-50507 do not credit any researchers in the acknowledgement section, saying only that “Microsoft recognizes the efforts of those in the security community who help us protect customers through coordinated vulnerability disclosure.”

Nightmare Eclipse claims to be a former employee of Microsoft, although Microsoft has not responded to questions about this claim. Rapid7 notes that a recent blog post by Nightmare Eclipse included an image of Albert Wesker, a character from the Resident Evil video game series who formerly worked as a researcher for a technology company before going rogue.

Nightmare Eclipse has pledged to release even more zero-day exploits for Windows in what they called a “bone shattering” drop planned for July 14 (the same day as next month’s Patch Tuesday). Immediately following the release of Microsoft patches today, the researcher published an exploit for what they claimed was a zero-day bug in Windows Defender.

While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barnett.

“So far this month, Microsoft has provided patches to address 360 browser vulnerabilities, which is an order of magnitude more than has been typical in any given month over the past few years,” Barnett wrote. “As usual, browser [flaws] are not included in the Patch Tuesday count above. Indeed, the vast, and presumably sustained, uptick in the number of browser vulnerabilities has led to Microsoft no longer enumerating Chromium CVEs in the Security Update Guide.”

Microsoft also patched a zero-day vulnerability in Visual Studio Code that allows attackers to steal GitHub tokens with a single click. The company was forced to push a stopgap fix for the flaw on June 3, after a researcher published instructions showing how to exploit it. The researcher said they opted not to work with Microsoft because of a recent experience wherein Redmond silently patched a flaw they reported without offering credit or recognition.

Microsoft battled its own internal zero-day emergencies last week, after at least 72 of the company’s public code repositories were infected with a variant of the Shai-Hulud worm. Researchers found that all of the affected packages were connected to Microsoft official Azure Durable Task SDK, which got hit by the same Shai-Hulud worm in May.

Other major software makers are also shipping outsized update bundles this month. Adobe has released updates to fix a massive number of critical vulnerabilities across a range of products, including Adobe Experience Manager, Acrobat Reader and Cold Fusion. On June 3, Google resolved a whopping 429 vulnerabilities in its latest Chrome browser update (Chrome automatically downloads updates but installing them usually requires a complete restart of the browser).

As ever, please consider backing up your data before applying operating system updates, and drop a note in the comments if you run into any problems with this month’s patches.

Further reading:

Microsoft’s Security Update Guide

Action1’s Patch Tuesday breakdown

SANS Internet Storm Center notes on Patch Tuesday

❌