Vulnerabilities

Microsoft Patches 200 Vulnerabilities

Three of the vulnerabilities fixed with the latest Patch Tuesday updates were publicly disclosed before Microsoft addressed them.

Microsoft Patch Tuesday

Microsoft’s June 2026 Patch Tuesday updates fix roughly 200 vulnerabilities discovered in the company’s products. 

None of the flaws addressed this month appears to have been exploited in the wild, but three issues were publicly disclosed before Microsoft patched them.

One of them is CVE-2026-49160, described as a denial-of-service (DoS) issue affecting Windows. This vulnerability is related to HTTP2/Bomb, an attack technique that could affect hundreds of thousands of websites, and which can be used to knock web servers offline in seconds. 

Another disclosed vulnerability is CVE-2026-50507, a Windows BitLocker security bypass that can allow an attacker with physical access to the targeted system to access encrypted data.

The security hole may be related to YellowKey, one of the several exploits released by a researcher known online as Chaotic Eclipse and Nightmare Eclipse, who began leaking PoC code after a disagreement with Microsoft. Several of the exploits leaked by the researcher have been exploited in the wild.

The third publicly disclosed vulnerability patched by Microsoft this month is CVE-2026-45586, a Windows Collaborative Translation Framework bug that can be exploited to elevate privileges to System. An anonymous researcher has been credited, and the flaw may be related to the GreenPlasma exploit leaked by Chaotic Eclipse.

Advertisement. Scroll to continue reading.

All three publicly disclosed issues have been assigned an ‘exploitation more likely’ exploitability assessment by Microsoft. 

Nearly 40 of the approximately 200 security holes addressed this month have a ‘critical’ severity rating. They affect Windows, Azure, Office, Outlook, Exchange, and AI tools, and their exploitation can lead to remote code execution, privilege escalation, and information disclosure. 

This was Microsoft’s biggest Patch Tuesday to date, which is not surprising, given that the updates came shortly after the company reported significant success in finding vulnerabilities using AI.

In addition to the vulnerabilities that are specific to Microsoft products, the tech giant published advisories for 360 issues affecting third-party components used by its software.

Adobe’s latest Patch Tuesday updates fix more than 120 vulnerabilities.

Related: Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash

Related: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

Related: Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

Related Content

Vulnerabilities

Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.

Artificial Intelligence

Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. 

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Vulnerabilities

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.

Endpoint Security

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.

Government

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.

Vulnerabilities

Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.

Vulnerabilities

The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.  

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version