Overview
- Microsoft released its June Patch Tuesday updates on Tuesday, fixing roughly 198–208 Windows and Microsoft-product vulnerabilities and issuing patches for three publicly disclosed zero-days.
- Researchers flagged at least one patched flaw, CVE-2026-41091, as under active exploitation and Microsoft rated the HTTP.sys DoS bug CVE-2026-49160, the BitLocker bypass CVE-2026-50507, and the CTFMON privilege escalation CVE-2026-45586 as publicly disclosed before patching.
- When included with Chromium and other third‑party component fixes distributed this month, the effective monthly tally rises toward roughly 571–600 CVEs, greatly increasing the volume administrators must test and deploy.
- Vendors and researchers link the spike to widespread use of AI tools that speed discovery and produce proof‑of‑concepts from patch diffs, and Microsoft published mitigations such as a MaxHeadersCount registry setting for HTTP.sys while urging priority patching of network‑facing, identity, and kernel flaws.
- The scale and pace of disclosures is straining operations: defenders must speed testing, prioritize exposed servers and domain controllers, watch for researcher exploit drops, and adapt patch workflows as high-volume, AI‑driven reporting becomes more common.