A digital lock breaks apart under streams of data, with 'CVE-2026' tags floating nearby and a red alert banner reading 'Patch Now'.
A digital lock breaks apart under streams of data, with 'CVE-2026' tags floating nearby and a red alert banner reading 'Patch Now'.

This surge in patched flaws shows how AI is accelerating vulnerability discovery, useful context for a colleague in IT security following the trend.

Microsoft Patches Record 206 Flaws Story flow and key facts

Microsoft's June 2026 security update addressed a record 206 vulnerabilities across its software ecosystem, marking one of the largest single-month patch releases in its history. The fixes include 39 critical-severity flaws, among them three zero-days actively exploited before the patch. Top vulnerabilities include CVE-2026-45657, a remote code execution flaw in the Windows Kernel with a CVSS score of 9.8, which could allow attackers to execute system-level code via malicious network traffic without authentication.

Other significant flaws include CVE-2026-44815, a buffer overflow in the Windows DHCP Client that enables remote code execution, and CVE-2026-45585, a BitLocker security bypass with a public proof-of-concept exploit called YellowKey. The update also resolves CVE-2026-49160, linked to the HTTP2/Bomb attack that can crash servers in seconds by exhausting memory, and CVE-2026-45586, suspected to patch a privilege escalation exploit known as GreenPlasma.

The surge in disclosed vulnerabilities is attributed to AI-assisted discovery tools, which are accelerating the rate at which security flaws are found. Experts note that the volume of CVEs in 2026 already exceeds Microsoft’s total for 2018. The update also resolves MiniPlasma, an incomplete fix from 2020, underscoring the long-term risks of partial patches. Organizations are urged to prioritize systems handling network services like DHCP and HTTP.

Facts

  • Microsoft patched a record 206 vulnerabilities in its June 2026 update.
  • Three of the flaws were zero-days already disclosed in public, including CVE-2026-50507 (bitskrieg) affecting BitLocker.
  • CVE-2026-45657 is a critical remote code execution flaw in Windows Kernel with a CVSS score of 9.8.
  • Security experts attribute the rising number of CVEs to AI-assisted vulnerability discovery.
  • The update resolves MiniPlasma, a lingering issue from an incomplete 2020 fix for CVE-2020-17103.

Canto visual news explainer. AI tools may assist production. Editorial policy