Microsoft's June Patch Tuesday fixes a record 206 vulnerabilities
The update is the largest on record and includes three publicly disclosed zero-days in BitLocker, HTTP.sys and Windows CTF.
Microsoft on June 10, 2026 released its June Patch Tuesday update, fixing 206 security vulnerabilities — the largest monthly security release on record since the program began in October 2003, according to the Microsoft Security Response Center.
Three of the bugs were publicly disclosed before the fix shipped, putting them in the zero-day category. None were known to be under active exploitation at the time of release, Microsoft said — a window that typically narrows once patch details are public and attackers reverse-engineer them.
The disclosed flaws span widely used components. CVE-2026-50507 lets an attacker with physical access bypass BitLocker Device Encryption. CVE-2026-49160, rated CVSS 7.5, allows a remote denial-of-service against the HTTP.sys web stack through an "HTTP/2 Bomb" technique. CVE-2026-45586, rated 7.8, affects the Windows Collaborative Translation Framework and can be used to elevate privileges to SYSTEM, the company's update guide shows.
The record count reflects volume, not necessarily a spike in severity; the BitLocker flaw, for instance, requires physical access, which limits its practical reach. Severity and exploitability vary across the 206 fixes, and the headline number is best read as the size of this month's patch workload rather than a single emergency.
For administrators, the takeaway is operational: a release this large complicates testing and staged rollout, and the three zero-days warrant priority given that public disclosure raises the odds of exploitation. Microsoft's guidance is to apply the updates promptly, with the elevation-of-privilege and denial-of-service issues among the first to address.
An entrepreneur with over a decade of experience in AI, Cloud, and HPC. He is currently a DevOps Architect and the founder of Data Phoenix, an influential media voice for the AI industry, with a strong focus on community building and open source.
More news

Microsoft disrupts EvilTokens, citing 12,000 compromised inboxes

Local process can redirect Meta Muse dictation traffic on macOS

Critical Splunk Enterprise flaw rated CVSS 9.8 is under active attack as CISA sets a June 21 patch deadline
Dmytro Spodarets·Jun 21, 2026