Particle.news

Microsoft Ships Record Patch Tuesday After Surge in Disclosed Flaws

Security teams face urgent patching because AI-assisted research and bundled third‑party updates sharply raised the number of disclosed and patched vulnerabilities.

Overview

  • Microsoft released its June Patch Tuesday updates on Tuesday, fixing roughly 198–208 Windows and Microsoft-product vulnerabilities and issuing patches for three publicly disclosed zero-days.
  • Researchers flagged at least one patched flaw, CVE-2026-41091, as under active exploitation and Microsoft rated the HTTP.sys DoS bug CVE-2026-49160, the BitLocker bypass CVE-2026-50507, and the CTFMON privilege escalation CVE-2026-45586 as publicly disclosed before patching.
  • When included with Chromium and other third‑party component fixes distributed this month, the effective monthly tally rises toward roughly 571–600 CVEs, greatly increasing the volume administrators must test and deploy.
  • Vendors and researchers link the spike to widespread use of AI tools that speed discovery and produce proof‑of‑concepts from patch diffs, and Microsoft published mitigations such as a MaxHeadersCount registry setting for HTTP.sys while urging priority patching of network‑facing, identity, and kernel flaws.
  • The scale and pace of disclosures is straining operations: defenders must speed testing, prioritize exposed servers and domain controllers, watch for researcher exploit drops, and adapt patch workflows as high-volume, AI‑driven reporting becomes more common.