Microsoft breaks Patch Tuesday record with 206 vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-41091 | Link-Following Local Privilege Escalation in Microsoft Defender (Actively Exploited) Microsoft Defender, through its Microsoft Malware Protection Engine component, contains an improper link-resolution ('link following', CWE-59) flaw in which the engine fails to properly resolve a link, such as a shortcut or symbolic link, before accessing the file it points to. An authorized attacker who already holds limited local privileges can plant or manipulate such a link so that Defender, operating in its privileged context, follows it and performs file operations on the attacker's behalf, elevating the attacker to SYSTEM privileges on the local machine with no user interaction (CVSS 7.8: AV:L/PR:L/UI:N with high C/I/A). Any Windows system running Microsoft Defender is in scope, with version ranges not specified in the available data; because Defender is the built-in default antivirus on Windows 10/11 and is widely deployed on Windows Server, exposure effectively spans the entire Windows installed base. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2026-05-20, and press reports describe a 'RoguePlanet' Defender zero-day granting SYSTEM access even on fully patched Windows, amid Microsoft's record-setting 206-CVE Patch Tuesday that coverage flagged as including one bug under active attack. A public proof-of-concept is available on GitHub, EPSS assigns an 8.2% probability of exploitation within 30 days (95th percentile), and ransomware use is not yet confirmed. Do: Apply Microsoft's current security updates — including the record June 2026 Patch Tuesday release (206 vulnerabilities) — across all Windows clients and servers, and verify the Microsoft Defender / Malware Protection Engine update actually installed rather than definitions only. Because the flaw gives a low-privileged local user SYSTEM access and is actively exploited with a public PoC available, prioritize endpoints where untrusted or low-privileged users log on locally (workstations, VDI, multi-user servers), and organizations subject to CISA BOD 22-01 must apply the required mitigations per vendor instructions or discontinue use per the KEV requirement. On hosts not yet patched, hunt for signs of local privilege escalation involving Defender, and note that ransomware use has not yet… | 7.8 | 8% | KEV PoC |
| mass≈1 billion+ Windows devices (Defender is the default, enabled-by-default antivirus on Windows 10/11) | |
| CVE-2026-49160 | HTTP/2 Resource Exhaustion Denial-of-Service in Microsoft Windows and Windows Server CVE-2026-49160 is an uncontrolled resource consumption flaw (CWE-400) in the HTTP/2 implementation on Windows, allowing an unauthenticated remote attacker to exhaust system resources by sending crafted HTTP/2 network traffic to a service that accepts HTTP/2 connections. Related reporting describes this as an 'HTTP/2 bomb' technique that can remotely deny service to HTTP/2-capable servers, including Microsoft IIS on Windows as well as other vendors' implementations (NGINX, Apache, Envoy, Cloudflare), though this CVE is scoped to Microsoft's Windows client and server products. A successful attack yields high-impact denial of service with no confidentiality or integrity loss, so any system on the affected versions running an HTTP/2-enabled service, especially an internet-exposed one, is at risk. Affected versions span Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025. There is no known public proof-of-concept and the flaw is not yet in CISA KEV, but its EPSS of 53.8% (99th percentile) signals a better-than-even chance of exploitation within 30 days, and it ships in Microsoft's record 206-vulnerability June 2026 Patch Tuesday. Do: Apply Microsoft's June 2026 Patch Tuesday updates across all listed Windows 10/11 and Windows Server versions, prioritizing internet-facing servers with HTTP/2 enabled (such as IIS). As interim mitigation, consider disabling or restricting HTTP/2 on exposed endpoints or fronting affected services with rate-limiting reverse proxies/load balancers that cap connection and resource usage. Given the 53.8% EPSS, treat this as a likely near-term exploitation target and verify patch status even though no public PoC or KEV listing exists yet. | 7.5 group max | 54% |
| masshundreds of millions of Windows devices (Windows 10/11 run on ~1.4B active devices; Windows Server in the millions) | ||
| CVE-2026-48567 | Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 9.8 | 1% |
| — |
Full article595 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Fears and warnings about a roaring flood of error-riddled software have materialized. And the disease is spreading.
Listen to this article
0:00
Learn more.
Microsoft addressed a whopping 206 vulnerabilities lurking in its vast portfolio of business products and foundational systems in this month’s Patch Tuesday update, marking the vendor’s largest monthly batch of security patches on record, according to researchers.
The massive assortment of vulnerabilities in Microsoft’s latest defect dump accentuates an alarming trend across technology — fears and warnings about a roaring flood of error-riddled software have materialized. And the disease is spreading.
“It is extraordinary that Microsoft can produce so many patches in a single month, but it does raise concerns,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, wrote in a blog post Tuesday.
Researchers consistently highlight the role artificial intelligence is playing in discovering more vulnerabilities and aiding in the development of patches and testing. Childs isn’t alone in wondering if this is the new normal and how that will impact defenders’ strategies for patch prioritization and deployment.
“Pandora’s proverbial box has been opened, and as more advanced AI models become available, we expect the norm to continue upward across the board, not just for Patch Tuesday,” Satnam Narang, senior staff research engineer at Tenable, said in an email.
This vulnerability flood isn’t a one-off or rare event. Half of Microsoft’s Patch Tuesday updates through the first half of this year contained a volume of defects well into the triple digits.
“The current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018,” Childs wrote.
Microsoft disclosed three vulnerabilities — CVE-2026-45586, CVE-2026-50507 and CVE-2026-49160 — that were publicly known at the time of release, but not yet exploited in the wild, according to the company.
Yet, in an out-of-band update May 19, the vendor did disclose and release a patch for CVE-2026-41091, an actively exploited zero-day vulnerability affecting Microsoft Defender.
Microsoft disclosed one max-severity vulnerability — CVE-2026-48567, affecting Azure HorizonDB — and nine defects with critical CVSS ratings. The company designated 15 of the vulnerabilities it addressed this month as more likely to be exploited.
The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-june-2026/