Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Patches 200 Vulnerabilities

Three of the vulnerabilities fixed with the latest Patch Tuesday updates were publicly disclosed before Microsoft addressed them.

Microsoft Patch Tuesday

Microsoft’s June 2026 Patch Tuesday updates fix roughly 200 vulnerabilities discovered in the company’s products. 

None of the flaws addressed this month appears to have been exploited in the wild, but three issues were publicly disclosed before Microsoft patched them.

One of them is CVE-2026-49160, described as a denial-of-service (DoS) issue affecting Windows. This vulnerability is related to HTTP2/Bomb, an attack technique that could affect hundreds of thousands of websites, and which can be used to knock web servers offline in seconds. 

Another disclosed vulnerability is CVE-2026-50507, a Windows BitLocker security bypass that can allow an attacker with physical access to the targeted system to access encrypted data.

The security hole may be related to YellowKey, one of the several exploits released by a researcher known online as Chaotic Eclipse and Nightmare Eclipse, who began leaking PoC code after a disagreement with Microsoft. Several of the exploits leaked by the researcher have been exploited in the wild.

The third publicly disclosed vulnerability patched by Microsoft this month is CVE-2026-45586, a Windows Collaborative Translation Framework bug that can be exploited to elevate privileges to System. An anonymous researcher has been credited, and the flaw may be related to the GreenPlasma exploit leaked by Chaotic Eclipse.

Advertisement. Scroll to continue reading.

All three publicly disclosed issues have been assigned an ‘exploitation more likely’ exploitability assessment by Microsoft. 

Nearly 40 of the approximately 200 security holes addressed this month have a ‘critical’ severity rating. They affect Windows, Azure, Office, Outlook, Exchange, and AI tools, and their exploitation can lead to remote code execution, privilege escalation, and information disclosure. 

This was Microsoft’s biggest Patch Tuesday to date, which is not surprising, given that the updates came shortly after the company reported significant success in finding vulnerabilities using AI.

In addition to the vulnerabilities that are specific to Microsoft products, the tech giant published advisories for 360 issues affecting third-party components used by its software.

Adobe’s latest Patch Tuesday updates fix more than 120 vulnerabilities.

Related: Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash

Related: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

Related: Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.