Microsoft’s May 2026 Patch Tuesday addressed nearly 200 vulnerabilities, including two zero-day exploits, but the update is overshadowed by an escalating and public feud with a security researcher. The company confirmed it fixed a vulnerability it had previously patched six years ago, marking a regression that highlights the persistent challenges in maintaining secure software. This incident, part of a broader disclosure campaign by the researcher known as Nightmare Eclipse, raises critical questions about the dynamics of vulnerability disclosure and the pressure it places on software vendors.
Microsoft Fixes 0-Day Regression: The MiniPlasma Vulnerability
Among the vulnerabilities addressed was a flaw disclosed by the researcher Nightmare Eclipse, tracked as CVE-2020-17103. This vulnerability, which the researcher refers to as MiniPlasma, was originally fixed by Microsoft six years ago. The latest patch indicates that the vulnerability was reintroduced through a regression or an incomplete patch in its initial form. Microsoft is in the process of updating its Tuesday bulletin to officially acknowledge this re-publication of a previously resolved security issue. The incident serves as a stark reminder that even long-standing fixes can be undone by subsequent code changes, leaving systems vulnerable to attacks that were once mitigated.
Researcher Rivalry and Unresolved Vulnerabilities
The tension between Microsoft and Nightmare Eclipse has been building for months. The researcher has taken multiple public potshots at Microsoft, with criticisms appearing to focus on the company’s vulnerability disclosure program. Microsoft has publicly railed against the researcher, accusing them of not “responsibly” disclosing vulnerabilities and making a veiled reference to the possibility of pursuing legal action. Following a public backlash, Microsoft relented and vowed no such legal action would occur. This ongoing conflict has resulted in a stream of vulnerability disclosures, many of which remain unpatched.
Microsoft has not yet released patches for other vulnerabilities disclosed by Nightmare Eclipse. The company did provide manual instructions for mitigating YellowKey, a vulnerability that allows attackers to defeat Bitlocker full-disk encryption. This is a particularly critical issue as it undermines the primary protection against physical device access. The underlying cause of the YellowKey vulnerability remains unaddressed. The status of other disclosed flaws, including a Windows Defender vulnerability named RedSun and a local privilege escalation flaw named BlueHammer that provides SYSTEM rights, is also currently unclear.
New Exploit Code and Two Confirmed Zero-Days
On Tuesday, Nightmare Eclipse published exploit code for a new Windows vulnerability, a race condition that targets Microsoft Defender. This rapid-fire disclosure strategy increases the urgency for Microsoft to respond. Tuesday’s patch batch included fixes for roughly 200 vulnerabilities. Beyond the MiniPlasma regression, two of the patched vulnerabilities were also confirmed as zero-days, indicating they were actively exploited in the wild before Microsoft issued a fix.
What the YellowKey Bitlocker Vulnerability Means for Users
What is the YellowKey vulnerability?
The YellowKey vulnerability is a flaw that completely defeats the default Windows 11 Bitlocker full-disk encryption protections. It allows an attacker with physical access to a device to bypass the encryption and access the data on the drive. This is the precise scenario Bitlocker is designed to protect against, making it a severe breach of a fundamental security layer.
How Can Users Protect Themselves Amid Unpatched Vulnerabilities?
The core of this situation is that users are dependent on Microsoft to provide patches for disclosed vulnerabilities. For the YellowKey Bitlocker flaw, affected users should follow the manual mitigation instructions provided by Microsoft as a temporary workaround. For general protection against zero-day attacks and unpatched vulnerabilities, users should employ a multi-layered endpoint protection solution. This includes using a reputable security suite with real-time threat detection and behavioral analysis. For any sensitive actions, especially over public Wi-Fi, users should ensure they are connected through a reputable no-log VPN service with AES-256 encryption and a kill switch to protect their data in transit. Maintaining a strong offline backup strategy is also critical, as physical access attacks can lead to data loss.
What Affected Users Should Do Now
The primary action for all Windows users is to install the latest Patch Tuesday updates immediately. For those specifically concerned about the Bitlocker vulnerability, apply the manual mitigations provided by Microsoft as soon as possible. Users should also enable multi-factor authentication (2FA) on all critical accounts, monitor their systems for any signs of unauthorized access, and ensure they are running a modern, multi-layer antivirus solution. For enterprise IT administrators, it is imperative to prioritize testing and deployment of the MiniPlasma patch, as a regression indicates a fundamental weakness in the affected codebase. A thorough review of any systems handling sensitive data in light of the Bitlocker bypass is strongly recommended. The situation underscores the importance of a robust vulnerability management program and the need to trust, but verify, the integrity of even previously patched security updates.