Microsoft Patch Tuesday breaks records with 198+ fixes as AI accelerates bug discovery

Reviewed byNidhi Govil

4 Sources

Share

Microsoft patched a record 198 security vulnerabilities in its June Patch Tuesday update, marking the largest monthly release in recent history. The surge reflects how AI in bug discovery is transforming vulnerability research, with tools like Claude Mythos and MDASH helping researchers uncover Windows security flaws at unprecedented speed. Three zero-day vulnerabilities were publicly disclosed before patches arrived, including an HTTP.sys flaw found by OpenAI's Codex.

Microsoft Patch Tuesday Delivers Unprecedented Volume of Fixes

Microsoft's June update has shattered previous records by addressing 198 security vulnerabilities across Windows systems, marking the largest Microsoft Patch Tuesday release in recent history

1

. The update includes 32 critical flaws and three zero-day vulnerabilities that were publicly disclosed before Microsoft resolved them

1

. Some sources report the number closer to 206 CVEs across all Microsoft products, with 38 deemed critical

2

. The previous record stood at 175 fixes, set last October

4

.

Source: TechRadar

Source: TechRadar

AI in Bug Discovery Drives Record Number of Patches

The unprecedented volume stems directly from AI accelerates bug discovery efforts across the tech industry. Tom Gallagher, VP of engineering at Microsoft Security Response Center, predicted in May that "releases will continue trending larger for some time"

2

. Tech companies now deploy models like Anthropic's Claude Mythos to help find and fix Windows security flaws much faster than traditional methods allowed

1

. In April, Mozilla patched 271 security flaws in Firefox with assistance from an early version of Claude Mythos Preview

1

.

Source: SiliconANGLE

Source: SiliconANGLE

Microsoft's own MDASH system, which uses more than 100 AI agents for AI-driven vulnerability discovery, surfaced 16 previously unknown flaws patched in May

4

. Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, noted that the number of CVEs Microsoft has shipped this year already exceeds its total for all of 2018

2

4

.

Critical Zero-Day Vulnerabilities Demand Immediate Action

Three zero-day vulnerabilities were publicly known before patches arrived, amplifying the urgency for Windows users to install Microsoft's June update immediately. CVE-2026-49160, an HTTP.sys denial-of-service vulnerability dubbed "HTTP/2 Bomb," was discovered by California researcher Quang Luong with assistance from OpenAI's Codex

2

4

. The attack exploits the HTTP/2 header compression algorithm by sending thousands of tiny messages to force rapid memory allocation and system crashes

2

.

Source: ZDNet

Source: ZDNet

CVE-2026-50507, tracked as YellowKey, represents a Windows BitLocker security feature bypass that allows attackers with physical access to capture encrypted data from unpatched systems

1

3

. The third publicly disclosed flaw, CVE-2026-45586 (GreenPlasma), affects the Windows Collaborative Translation Framework and enables local attackers to gain SYSTEM access, potentially deploying malware and moving laterally through victim environments

2

3

.

Both GreenPlasma and YellowKey were disclosed by Chaotic Eclipse, a researcher who conflicted with Microsoft over vulnerability reporting practices and researcher compensation

3

. Microsoft did not credit any researchers for these two flaws in its advisory

3

.

Windows Kernel Flaw Poses Wormable Threat

Among the critical-rated security vulnerabilities, CVE-2026-45657 stands out as particularly dangerous. This use-after-free vulnerability in the Windows kernel's TCP/IP stack scored 9.8 on the Common Vulnerability Scoring System scale

4

. Remote, unauthenticated attackers can exploit this flaw without any user interaction by sending malicious network packets to vulnerable Windows systems

2

. Microsoft indicates the bug is wormable on some networks, meaning it could spread automatically between connected systems

4

.

Implications for Cybersecurity Researchers and Administrators

The surge in AI-driven vulnerability discovery creates both opportunities and challenges for the security community. Childs warned that "AI is supercharging flaw discovery at an uncontrollable scale" and questioned what quality issues may exist in patches produced at this volume

4

. Administrators face mounting pressure to adjust their prioritization and patch deployment processes for this new reality

2

.

Microsoft also shipped patches for 360 browser vulnerabilities this month, an order of magnitude above recent norms, and has stopped enumerating Chromium bugs in its Security Update Guide as a result

4

. Adam Barnett, lead software engineer at Rapid7, noted that other vulnerability categories, especially Linux kernel vulnerabilities, are experiencing similar increases in AI-assisted vulnerability reports

4

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved