Microsoft's June 2026 Patch Tuesday is its biggest ever, addressing 200 documented vulnerabilities and three publicly disclosed zero-days. None are known to have been exploited in the wild yet, but the sheer volume eclipses the previous high of 167 CVEs and will dominate IT operations queues this week.
Three zero-days, all disclosed publicly before the fix
The three zero-day vulnerabilities patched in this drop are CVE-2026-50507, a Windows BitLocker bypass nicknamed "YellowKey" that lets an attacker with physical access defeat full-disk encryption; CVE-2026-49160, an HTTP.sys denial-of-service flaw in HTTP/2 publicly documented as the "HTTP/2 Bomb"; and CVE-2026-45586, a Windows Collaborative Translation Framework (CTFMON) elevation-of-privilege bug that grants SYSTEM via improper link resolution. All three were publicly disclosed before the official patch shipped, raising the urgency for organisations to deploy this month's updates without delay.
Critical bucket dominated by remote code execution
The release classifies 33 vulnerabilities as Critical, of which 28 are remote code execution flaws, four are elevation of privilege and one is an information disclosure issue. The remote-code-execution heavy mix is consistent with recent months and reflects continued pressure on Microsoft to harden internet-exposed Windows services after several years of high-profile in-the-wild zero-day chains.
What defenders should do first
Security teams should prioritise the BitLocker bypass for fleets of laptops where physical-access threats are realistic, deploy the HTTP.sys fix on any externally exposed IIS or HTTP/2 endpoint, and roll the CTFMON patch in standard rings given the local-privilege escalation risk. The release lands alongside fresh patches across the cybersecurity sector this week, including the CISA addition of an actively exploited BerriAI LiteLLM vulnerability to the KEV catalogue, underscoring how aggressively AI infrastructure components are now being targeted.
Why it matters
A 200-CVE Patch Tuesday is a budget event for every Microsoft-shop CISO. With three publicly disclosed zero-days already in the wild, the window between disclosure and weaponisation is measured in days, not weeks. Organisations that delayed last month's patches, particularly the parallel rollout of Microsoft's new MAI model stack, should expect a substantially heavier remediation calendar through the rest of June.
Reporting based on coverage from BleepingComputer, Microsoft Security Response Centre, Tenable and Help Net Security.
