Microsoft's Record June Patch Tuesday Fixes Over 200 Flaws, Including Three Critical Zero-Days

Microsoft said it “shipped several [critical fixes] only after the bugs were already public,” indicating some fixes entered Patch Tuesday after disclosure rather than solely via coordinated timelines.
For the HTTP.sys “HTTP/2 Bomb” zero-day (CVE-2026-49160), Microsoft specifically credited OpenAI Group PBC’s Codex—“one of the first publicly attributed cases of an AI system reporting a vulnerability in a major Patch Tuesday cycle.”
Two additional zero-days were attributed to uncoordinated disclosure by a pseudonymous researcher (“Nightmare Eclipse”), who published proof-of-concept code for a Windows Defender bug “within hours of Tuesday’s release.”
ZDNET lists the exact KB packages for this cycle: KB5094126 (Windows 11 24H2/25H2), KB5093998 (Windows 11 23H2), and KB5094127 (Windows 10).
Industry warning: Dustin Childs (TrendAI’s Zero Day Initiative) said, “We are heading into a high-stakes summer for cybersecurity,” adding that the volume is “a stark warning that AI is supercharging flaw discovery at an uncontrollable scale,” and he questioned potential “quality issues” given the scale Microsoft is producing.
Microsoft released its largest security update ever on June 9, breaking its own record with fixes for 198 to 206 vulnerabilities in a single Patch Tuesday. The package includes a wormable Windows kernel flaw rated 9.8 out of 10 in severity — the highest possible danger score — along with three publicly known zero-days, two of which had proof-of-concept attack code published within hours of the patch release, according to SiliconAngle.
Cybersecurity agencies in the US and UK issued urgent orders for critical infrastructure operators to apply the updates within 24 hours. The previous Patch Tuesday record was 175 fixes, set in October 2025, according to SiliconAngle.
The most alarming fix covers CVE-2026-45657, a use-after-free flaw deep in the Windows TCP/IP stack. A use-after-free bug lets attackers access memory that a program already freed, causing unpredictable behavior. This one requires no password, no login, and no click from a victim. It can spread on its own across misconfigured networks — the definition of a wormable flaw — drawing comparisons to EternalBlue, the exploit behind the 2017 WannaCry ransomware outbreak, according to HotHardware.
A second high-priority fix targets CVE-2026-41091 in Microsoft Defender, the built-in Windows antivirus tool. Microsoft detected active exploitation of this flaw on June 2, a full week before the patch shipped. Microsoft addressed it by updating the Defender Malware Protection Engine automatically — a separate process from the main Windows update — which adds a second step for IT teams to confirm, according to TweakTown.
One zero-day stands apart from the rest. CVE-2026-49160, dubbed the "HTTP/2 Bomb," is a denial-of-service flaw in Windows HTTP.sys — the component that handles web traffic. Microsoft credited OpenAI's Codex system with finding and reporting the bug directly to Microsoft's security team on May 28. SiliconAngle called it "one of the first publicly attributed cases of an AI system reporting a vulnerability in a major Patch Tuesday cycle."
The third zero-day, CVE-2026-50507, is a BitLocker security bypass. BitLocker is Windows' built-in drive encryption tool. All three zero-days were already public before the patches shipped, meaning attackers had a head start. Microsoft said it "shipped several critical fixes only after the bugs were already public," according to WebProNews.
A researcher going by "Nightmare Eclipse" made Microsoft's week harder. The researcher hinted at "The Defender's Downfall" on decentralized forums the evening before the patch release. By 12:15 PM Pacific time on June 9 — just over two hours after the patches dropped — Nightmare Eclipse published full working exploit code for the Defender flaw. Their message: "Security through obscurity is dead." TweakTown reported that Microsoft ultimately patched every vulnerability Nightmare Eclipse disclosed.
The rapid PoC release — PoC means proof-of-concept, a working attack demonstration — shrank the window enterprises had to patch before real attackers could copy the technique. Early reports on June 11 showed some Windows 11 25H2 systems hitting minor stability problems after applying KB5094126, the main update package for that version, according to TweakTown.
Security analysts warn that this record volume is not a one-time event. Dustin Childs of TrendAI's Zero Day Initiative said: "We are heading into a high-stakes summer for cybersecurity. This volume is a stark warning that AI is supercharging flaw discovery at an uncontrollable scale." He also raised concerns about whether Microsoft's quality checks can keep pace, according to WebProNews.
The 32 to 38 critical fixes in this cycle also include Exchange Server vulnerabilities and multiple BitLocker bypasses, adding complexity for enterprise teams. ZDNET tracked the specific update packages: KB5094126 covers Windows 11 versions 24H2 and 25H2, KB5093998 covers Windows 11 23H2, and KB5094127 covers Windows 10. All require a reboot to take effect. Microsoft's next Patch Tuesday is July 14.
Publishers
28
Articles
7
Reach
35