Microsoft Patches Record 200 Flaws in June Patch Tuesday

Microsoft releases its largest ever Patch Tuesday, fixing 200 security flaws with three zero-days already exploited.

By Central
Record-breaking Patch Tuesday: 200 vulnerabilities patched, including zero-days from researcher Nightmare Eclipse.
Highlights
  • AI-driven vulnerability discovery is fueling a surge in patch volume, with Microsoft fixing a record 200 flaws this month.
  • Three zero-day bugs are already publicly exploited, including one discovered by OpenAI's Codex in Microsoft IIS.
  • A researcher known as Nightmare Eclipse plans to release more zero-day exploits on July 14, the next Patch Tuesday.

Microsoft today released software updates addressing nearly 200 security vulnerabilities across its Windows operating systems and supported software, setting a new record for the company’s monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available. The sheer volume marks a turning point: both Microsoft engineers and the broader security community are increasingly leveraging artificial intelligence tools to discover flaws, and this month’s heavy cadence may soon become the norm.

AI-Driven Discovery Fuels Record Patch Volume

Satnam Narang, senior staff research engineer at Tenable, noted that some surveys put AI usage among security professionals at roughly 90 percent, making the explosion in patch volume an expected development. “Pandora’s proverbial box has been opened,” Narang said, “and as more advanced AI models become available, we expect the norm to continue upward across the board, not just for Patch Tuesday.” The record 200 vulnerabilities fixed this month may be only the beginning as automated tooling accelerates both discovery and disclosure.

June Zero-Day Vulnerabilities and the Nightmare Eclipse Researcher

Among the zero-day bugs addressed this month is CVE-2026-49160, a denial of service vulnerability affecting a range of web servers including Microsoft Internet Information Services (IIS). Notably, Microsoft reports that the flaw was discovered by OpenAI’s Codex. Two additional zero-days appear to trace back to recent disclosures by “Nightmare Eclipse,” a security researcher who has been releasing exploit code for various Windows flaws. One of those exploits, dubbed GreenPlasma, leverages an elevation of privilege weakness in the Windows Collaborative Translation Framework, patched as CVE-2026-45586. Another, YellowKey, targets a Windows BitLocker vulnerability that allows an attacker with physical access to view encrypted data, addressed by CVE-2026-50507.

Nightmare Eclipse claims to be a former Microsoft employee—a claim the company has not verified—and has pledged to release what they describe as a “bone shattering” drop of additional zero-day exploits on July 14, coinciding with next month’s Patch Tuesday. Hours after Microsoft issued its patches today, the researcher published an exploit for what they assert is a zero-day bug in Windows Defender.

Controversy Over Researcher Relations and Credit

Microsoft faced significant backlash on social media last month after suggesting in a blog post that it was considering legal action against the security researcher. The company later clarified that while it has no intention of pursuing lawsuits against researchers, it would report them to authorities if they break the law. Notably, the advisories for CVE-2026-49160 and CVE-2026-50507 do not credit any individual researcher, stating only that “Microsoft recognizes the efforts of those in the security community who help us protect customers through coordinated vulnerability disclosure.”

Beyond Patch Tuesday: 360 Browser Flaws and Internal Emergencies

The actual number of security flaws Microsoft addressed this month is far higher than the Patch Tuesday count suggests. Rapid7’s Adam Barnett noted that Microsoft has already patched 360 browser vulnerabilities this month—an order of magnitude more than typical monthly volumes. “As usual, browser flaws are not included in the Patch Tuesday count,” Barnett wrote, adding that the sustained uptick has led Microsoft to stop enumerating Chromium CVEs in its Security Update Guide.

Microsoft also patched a zero-day in Visual Studio Code that allowed attackers to steal GitHub tokens with a single click. The company was forced to push a stopgap fix on June 3 after a researcher published exploitation instructions, having opted not to work with Microsoft following a prior experience in which the company silently patched a reported flaw without offering credit. Separately, Microsoft battled internal zero-day emergencies last week when at least 72 of its public code repositories were infected with a variant of the Shai-Hulud worm, all linked to the Microsoft Azure Durable Task SDK.

Industry-Wide Patch Surge: Adobe and Google Ship Massive Updates

Microsoft is not alone in shipping outsized update bundles. Adobe has released fixes for a massive number of critical vulnerabilities across products including Adobe Experience Manager, Acrobat Reader, and ColdFusion. Google resolved 429 vulnerabilities in its latest Chrome browser update—an eye-popping figure that underscores the growing scale of the patching challenge across the entire software ecosystem.

What Affected Users Should Do Now

Given the record number of patches, the publicly available exploit code for multiple vulnerabilities, and the credible threat of additional exploit drops in the coming weeks, users and administrators should prioritize applying this month’s updates immediately. Back up your data before installing operating system patches, and ensure that browser updates—including a full restart of the browser—have taken effect. For organizations, this cycle reinforces the need for a robust vulnerability management process: maintain an accurate asset inventory, apply critical patches within 48 hours, and deploy a multi-layer endpoint protection solution that can detect and block exploit attempts before patches reach every system. Enable two-factor authentication on all accounts where available and monitor for unusual activity in the days following patch deployment.

Share This Article