4 Sources
[1]
Microsoft patches record 198 Windows bugs in June update - and 3 are zero days
Follow ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways * Microsoft's June update patches a record 198 security flaws. * Some 32 are rated critical, while three are zero-day flaws. * The update also adds several helpful new features to Windows 11. Microsoft's monthly Patch
[2]
AI is making Patch Tuesday (kinda) fun again
Unless you're an admin or vulnerability manager - then you're totally screwed Microsoft set a record with its June Patch Tuesday release, addressing 206 CVEs across its products and shipping fixes for them, with 38 deemed critical and the rest important. Three are listed as publicly known, but
[3]
Microsoft breaks Patch Tuesday record with fixes for over 200 security flaws
* June 2026 Patch Tuesday release fixes nearly 200 Windows vulnerabilities, Microsoft's largest release to date * It includes Chaotic Eclipse's GreenPlasma (CVE‑2026‑45586) and YellowKey (CVE‑2026‑45585), disclosed without coordination * AI‑driven bug discovery fueling record‑high patch volumes,
[4]
Microsoft patches record 200-plus vulnerabilities as AI accelerates bug discovery
Microsoft patches record 200-plus vulnerabilities as AI accelerates bug discovery Microsoft Corp. on Tuesday patched more than 200 security vulnerabilities, the most the company has ever fixed in a single Patch Tuesday, with researchers saying artificial intelligence bug-hunting is the reason the
Share
Copy Link
Microsoft patched a record 198 security vulnerabilities in its June Patch Tuesday update, marking the largest monthly release in recent history. The surge reflects how AI in bug discovery is transforming vulnerability research, with tools like Claude Mythos and MDASH helping researchers uncover Windows security flaws at unprecedented speed. Three zero-day vulnerabilities were publicly disclosed before patches arrived, including an HTTP.sys flaw found by OpenAI's Codex.
Microsoft's June update has shattered previous records by addressing 198 security vulnerabilities across Windows systems, marking the largest Microsoft Patch Tuesday release in recent history
1
. The update includes 32 critical flaws and three zero-day vulnerabilities that were publicly disclosed before Microsoft resolved them1
. Some sources report the number closer to 206 CVEs across all Microsoft products, with 38 deemed critical2
. The previous record stood at 175 fixes, set last October4
.
Source: TechRadar
The unprecedented volume stems directly from AI accelerates bug discovery efforts across the tech industry. Tom Gallagher, VP of engineering at Microsoft Security Response Center, predicted in May that "releases will continue trending larger for some time"
2
. Tech companies now deploy models like Anthropic's Claude Mythos to help find and fix Windows security flaws much faster than traditional methods allowed1
. In April, Mozilla patched 271 security flaws in Firefox with assistance from an early version of Claude Mythos Preview1
.
Source: SiliconANGLE
Microsoft's own MDASH system, which uses more than 100 AI agents for AI-driven vulnerability discovery, surfaced 16 previously unknown flaws patched in May
4
. Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, noted that the number of CVEs Microsoft has shipped this year already exceeds its total for all of 20182
4
.Three zero-day vulnerabilities were publicly known before patches arrived, amplifying the urgency for Windows users to install Microsoft's June update immediately. CVE-2026-49160, an HTTP.sys denial-of-service vulnerability dubbed "HTTP/2 Bomb," was discovered by California researcher Quang Luong with assistance from OpenAI's Codex
2
4
. The attack exploits the HTTP/2 header compression algorithm by sending thousands of tiny messages to force rapid memory allocation and system crashes2
.
Source: ZDNet
CVE-2026-50507, tracked as YellowKey, represents a Windows BitLocker security feature bypass that allows attackers with physical access to capture encrypted data from unpatched systems
1
3
. The third publicly disclosed flaw, CVE-2026-45586 (GreenPlasma), affects the Windows Collaborative Translation Framework and enables local attackers to gain SYSTEM access, potentially deploying malware and moving laterally through victim environments2
3
.Both GreenPlasma and YellowKey were disclosed by Chaotic Eclipse, a researcher who conflicted with Microsoft over vulnerability reporting practices and researcher compensation
3
. Microsoft did not credit any researchers for these two flaws in its advisory3
.Related Stories
Among the critical-rated security vulnerabilities, CVE-2026-45657 stands out as particularly dangerous. This use-after-free vulnerability in the Windows kernel's TCP/IP stack scored 9.8 on the Common Vulnerability Scoring System scale
4
. Remote, unauthenticated attackers can exploit this flaw without any user interaction by sending malicious network packets to vulnerable Windows systems2
. Microsoft indicates the bug is wormable on some networks, meaning it could spread automatically between connected systems4
.The surge in AI-driven vulnerability discovery creates both opportunities and challenges for the security community. Childs warned that "AI is supercharging flaw discovery at an uncontrollable scale" and questioned what quality issues may exist in patches produced at this volume
4
. Administrators face mounting pressure to adjust their prioritization and patch deployment processes for this new reality2
.Microsoft also shipped patches for 360 browser vulnerabilities this month, an order of magnitude above recent norms, and has stopped enumerating Chromium bugs in its Security Update Guide as a result
4
. Adam Barnett, lead software engineer at Rapid7, noted that other vulnerability categories, especially Linux kernel vulnerabilities, are experiencing similar increases in AI-assisted vulnerability reports4
.Summarized by
Navi
[2]
09 Jul 2026•Technology

09 Sept 2026•Technology

29 Jul 2026•Technology
