Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Patches 200 Vulnerabilities

Three of the vulnerabilities fixed with the latest Patch Tuesday updates were publicly disclosed before Microsoft addressed them.

Microsoft Patch Tuesday

Microsoft’s June 2026 Patch Tuesday updates fix roughly 200 vulnerabilities discovered in the company’s products. 

None of the flaws addressed this month appears to have been exploited in the wild, but three issues were publicly disclosed before Microsoft patched them.

One of them is CVE-2026-49160, described as a denial-of-service (DoS) issue affecting Windows. This vulnerability is related to HTTP2/Bomb, an attack technique that could affect hundreds of thousands of websites, and which can be used to knock web servers offline in seconds. 

Another disclosed vulnerability is CVE-2026-50507, a Windows BitLocker security bypass that can allow an attacker with physical access to the targeted system to access encrypted data.

The security hole may be related to YellowKey, one of the several exploits released by a researcher known online as Chaotic Eclipse and Nightmare Eclipse, who began leaking PoC code after a disagreement with Microsoft. Several of the exploits leaked by the researcher have been exploited in the wild.

The third publicly disclosed vulnerability patched by Microsoft this month is CVE-2026-45586, a Windows Collaborative Translation Framework bug that can be exploited to elevate privileges to System. An anonymous researcher has been credited, and the flaw may be related to the GreenPlasma exploit leaked by Chaotic Eclipse.

Advertisement. Scroll to continue reading.

All three publicly disclosed issues have been assigned an ‘exploitation more likely’ exploitability assessment by Microsoft. 

Nearly 40 of the approximately 200 security holes addressed this month have a ‘critical’ severity rating. They affect Windows, Azure, Office, Outlook, Exchange, and AI tools, and their exploitation can lead to remote code execution, privilege escalation, and information disclosure. 

This was Microsoft’s biggest Patch Tuesday to date, which is not surprising, given that the updates came shortly after the company reported significant success in finding vulnerabilities using AI.

In addition to the vulnerabilities that are specific to Microsoft products, the tech giant published advisories for 360 issues affecting third-party components used by its software.

Adobe’s latest Patch Tuesday updates fix more than 120 vulnerabilities.

Related: Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash

Related: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

Related: Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.