started · updated
Microsoft patches record 206 vulnerabilities in June 2026 Patch Tuesday
Microsoft released its June 2026 Patch Tuesday update, fixing a record 206 security flaws—the highest number ever in a single cycle. The batch includes 38 critical bugs and three publicly disclosed zero‑day vulnerabilities. The most severe is CVE‑2026‑45657, a use‑after‑free flaw in the Windows kernel’s TCP/IP stack rated 9.8 CVSS and described as wormable without any credential or user interaction. Other high‑profile fixes address Outlook Web Access (CVE‑2026‑42897), a privilege‑escalation issue in Microsoft Defender (CVE‑2026‑41091), and a denial‑of‑service flaw in HTTP.sys (CVE‑2026‑49160) linked to an "HTTP/2 Bomb" technique. Artificial‑intelligence tools, including OpenAI’s Codex and other proprietary scanners, helped discover many of the bugs, marking a structural shift in vulnerability research. Additionally, Microsoft revoked several Microsoft‑signed UEFI shim bootloaders (CVE‑2026‑8863) via the DBX database to block Secure Boot bypass attacks affecting Linux distributions and other third‑party software. The update also patches numerous other issues across Windows 10, Windows 11, and Windows Server versions, prompting organizations to prioritize rapid deployment, especially for internet‑facing servers.