Microsoft fixed nearly 200 vulnerabilities in the June 2026 Patch Tuesday, the most voluminous monthly cycle ever recorded by the Redmond company. Of these, 33 are rated Critical according to Punto Informatico and The Cyber Express, with 28 remote code execution flaws in the Critical tier alone. Per SecurityWeek and The Cyber Express, three zero-days had already been publicly disclosed before patches were released. Punto Informatico flags a possible fourth zero-day, but the discrepancy remains unresolved in the available dossiers.
- Microsoft fixed nearly 200 vulnerabilities in the June 2026 Patch Tuesday, with counts ranging from 204 per SANS to 208 per Zero Day Initiative according to Shattered.io, a source with its own counting methodology and possible predictive content.
- Per SecurityWeek and The Cyber Express, three zero-days were already publicly disclosed: CVE-2026-49160 (HTTP/2 Bomb), CVE-2026-45586 (GreenPlasma), and CVE-2026-45585 (YellowKey).
- CVE-2026-50507 is a distinct BitLocker bypass separate from YellowKey; the brief does not classify it as a publicly disclosed zero-day.
- CVE-2026-45657 is a Windows kernel vulnerability with CVSS 9.8, rated wormable by The Cyber Express and Shattered.io.
- Nightmare Eclipse published exploit code for Microsoft Defender on June 9, 2026, 24 hours before Patch Tuesday.
Nearly 200 CVEs: Record Numbers and Discrepancies Across Counters
The exact count of vulnerabilities fixed in June varies across industry sources. Punto Informatico cites "nearly 200," SecurityWeek says "roughly 200," while The Cyber Express specifies 200 total with a severity breakdown: 33 Critical, 166 Important, 1 Moderate. Shattered.io reports higher figures: 208 CVEs per ZDI, 204 per SANS, 206 per Qualys, with 38 rated Critical versus the 33 from The Cyber Express.
The discrepancy in Critical counts — 33 per Punto Informatico and The Cyber Express, 38 per Shattered.io — is not clarified in the available dossiers. Shattered.io is a source with its own counting methodology and possible predictive content; the alternative numbers are not verifiable in other primary sources.
The stable datum is the volume: even taking the most conservative estimate, this is the largest Patch Tuesday in Microsoft history. Among the 33 Critical flaws tallied by The Cyber Express, 28 are remote code execution.
The Three Publicly Disclosed Zero-Days: HTTP/2 Bomb, GreenPlasma, and YellowKey
According to SecurityWeek, none of the addressed vulnerabilities were under active exploitation at the time of release, but three had been publicly disclosed before patching. The Cyber Express corroborates the count of three publicly disclosed zero-days.
CVE-2026-49160, dubbed HTTP/2 Bomb by Calif researchers, is a denial-of-service flaw caused by uncontrolled resource consumption in the HTTP/2 protocol. The official MSRC page assigns it a CVSS 3.1 score of 7.5 HIGH with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, marks Publicly disclosed: Yes, Exploited: No, and rates exploitability as Exploitation More Likely. An unauthenticated attacker can cause denial of service over the network without user interaction.
CVE-2026-45586, nicknamed GreenPlasma and disclosed by Nightmare Eclipse, is a privilege escalation in the CTFMON component that allows an attacker to gain SYSTEM privileges. The CVSS 3.1 score is 7.8 HIGH with vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. This flaw is also Publicly disclosed: Yes with Exploitation More Likely.
CVE-2026-45585 is linked to the earlier BitLocker issue known as YellowKey. Microsoft had published temporary mitigations in late May; the June patch completes the cycle. The CVSS score is 6.8 MEDIUM.
CVE-2026-50507 is a BitLocker bypass distinct from YellowKey, as Punto Informatico explicitly states. The brief does not classify it as a publicly disclosed zero-day.
The Wormable Kernel Flaw: CVE-2026-45657
CVE-2026-45657 is a use-after-free in the Windows kernel with a CVSS 9.8 score per The Cyber Express and Shattered.io. Both sources classify it as wormable.
"CVE-2026-45657 is the kind of vulnerability that keeps defenders up at night... The CVSS 9.8 score, combined with wormable potential, means we could see mass exploitation the moment a reliable exploit is developed."
— Zero Day Initiative researcher, quoted by The Cyber Express
The CVSS 9.8 score places this vulnerability at the top of the severity scale. Microsoft does not explicitly confirm the wormable nature in the available advisory; the assessment comes from industry sources. The confirmed official data points are the CVSS score and the use-after-free kernel classification.
Nightmare Eclipse and the June 9 Disclosure
On June 9, 2026, one day before the June 10 Patch Tuesday, Nightmare Eclipse published the RoguePlanet exploit code for Microsoft Defender. Microsoft had threatened legal action, then clarified it reports only legal violations to authorities.
The brief does not verify whether RoguePlanet was patched in this cycle. The window between exploit publication and patch release was 24 hours, not 48.
Dossier Limitations
With a single structured primary source (Punto Informatico) and multiple industry outlets, this article carries declared evidentiary limits. It is unclear what the fourth zero-day mentioned by Punto Informatico might be, if it exists. It is not verifiable whether CVE-2026-41091 is actually a fourth zero-day. The patching status of MiniPlasma is UNKNOWN. It is not confirmed whether RoguePlanet was patched. Microsoft has not confirmed the wormable nature of CVE-2026-45657 in its own advisory.
What to Do Now
Per the available sources, patching priorities rest on confirmed MSRC data. CVE-2026-49160 carries an Exploitation More Likely rating and is publicly disclosed; the source does not specify additional vectors or operational mitigations. CVE-2026-45586 has the same rating and grants SYSTEM privileges. CVE-2026-45657 carries the highest CVSS in the release at 9.8.
The source does not specify particular configurations, multi-user environments, terminal servers, or removal of prior temporary mitigations. Operational recommendations must derive from the verified data in the brief.
The June 2026 Patch Tuesday confirms a pattern of growing volume and pre-release disclosure. Organizations should calibrate priorities on official Microsoft data, recognizing that the available dossier contains unresolved areas of uncertainty.
Information has been verified against cited sources and is current as of publication.
Sources
- https://www.punto-informatico.it/patch-tuesday-giugno-2026-risolte-quasi-200-vulnerabilita/
- https://www.securityweek.com/microsoft-patches-200-vulnerabilities/
- https://thecyberexpress.com/june-2026-patch-tuesday-200-microsoft/
- https://shattered.io/it/patch-tuesday-giugno-2026/
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-49160
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-45586
- https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun