Microsoft security patch release for CVE-2026-45586
Security Patch Release
Summary
Hide ▲
Show ▼
Microsoft's June 2026 Patch Tuesday delivers 200 flaw fixes across Windows and related products, including six zero-days and one actively exploited vulnerability. The release covers high-impact bugs such as CVE-2026-45586, CVE-2026-49160, CVE-2026-45585, CVE-2026-50507, CVE-2020-17103, and CVE-2026-42897. The patch bundle requires urgent attention because it spans privilege escalation, denial of service, BitLocker bypass, and Exchange spoofing issues.
Related Happenings
Microsoft security patch release for CVE-2026-42824
Security Patch Release
H score30
First: 15.06.2026 16:00
Last: 15.06.2026 16:00
Sources 1
About this happening:
Microsoft's fix for SearchLeak in Microsoft 365 Copilot Enterprise closed a critical flaw tied to CVE-2026-42824 that could expose mailbox, OneDrive, and SharePo...
Microsoft security patch release for CVE-2026-42824
Security Patch ReleaseAbout this happening: Microsoft's fix for SearchLeak in Microsoft 365 Copilot Enterprise closed a critical flaw tied to CVE-2026-42824 that could expose mailbox, OneDrive, and SharePo...
Microsoft June 2026 Patch Tuesday record 206-vulnerability update
Security Patch Release
H score55
First: 10.06.2026 12:38
Last: 10.06.2026 12:38
Sources 1
About this happening:
Microsoft shipped a record 206-vulnerability update for its software portfolio, including three publicly disclosed flaws. The release spans Critical and Important...
Microsoft June 2026 Patch Tuesday record 206-vulnerability update
Security Patch ReleaseAbout this happening: Microsoft shipped a record 206-vulnerability update for its software portfolio, including three publicly disclosed flaws. The release spans Critical and Important...
Microsoft June 2026 Patch Tuesday GreenPlasma and YellowKey fixes
Security Patch Release
H score15
First: 10.06.2026 02:11
Last: 10.06.2026 02:11
Sources 1
About this happening:
Microsoft released June 2026 Patch Tuesday updates that fixed the GreenPlasma and YellowKey flaws, closing two previously disclosed issues in the Windows ecosystem...
Microsoft June 2026 Patch Tuesday GreenPlasma and YellowKey fixes
Security Patch ReleaseAbout this happening: Microsoft released June 2026 Patch Tuesday updates that fixed the GreenPlasma and YellowKey flaws, closing two previously disclosed issues in the Windows ecosystem...
Microsoft June 2026 Patch Tuesday record security update bundle
Security Patch Release
H score36
First: 10.06.2026 01:07
Last: 10.06.2026 01:07
Sources 1
About this happening:
Microsoft released a record Patch Tuesday bundle for June 2026 that patches nearly 200 security holes across Windows operating systems and supported software,...
Microsoft June 2026 Patch Tuesday record security update bundle
Security Patch ReleaseAbout this happening: Microsoft released a record Patch Tuesday bundle for June 2026 that patches nearly 200 security holes across Windows operating systems and supported software,...
Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498
Security Patch Release
H score44
First: 21.05.2026 10:49
Last: 21.05.2026 10:49
Sources 1
About this happening:
Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...
Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498
Security Patch ReleaseAbout this happening: Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...
Latest development: 21.05.2026 12:52
Microsoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.
Timeline
-
09.06.2026 20:57 2 articles · 1mo ago
Microsoft releases June 2026 Patch Tuesday for 200 flaws and six zero-days
Initial DisclosureMicrosoft's June 2026 Patch Tuesday delivers security updates for 200 flaws, including five publicly disclosed zero-days and one actively exploited vulnerability, across Windows and related products.
Show sources
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws — www.bleepingcomputer.com — 09.06.2026 20:57
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws — www.bleepingcomputer.com — 09.06.2026 20:57
-
09.06.2026 20:57 1 articles · 1mo ago
Microsoft patches Windows CTFMON, HTTP.sys, BitLocker, and Mini-Plasma flaws
Technical Analysis UpdateThe June 2026 updates fix CVE-2026-45586 in Windows Collaborative Translation Framework (CTFMON), CVE-2026-49160 in HTTP.sys, CVE-2026-45585 and CVE-2026-50507 in Windows BitLocker Device Encryption, and CVE-2020-17103 in Windows Cloud Files Mini Filter Driver.
Show sources
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws — www.bleepingcomputer.com — 09.06.2026 20:57
-
09.06.2026 20:57 1 articles · 1mo ago
Microsoft adds MaxHeadersCount and Exchange Emergency Mitigation Service
Mitigation Patch UpdateMicrosoft introduces a new MaxHeadersCount registry setting to limit headers accepted in HTTP/2 and HTTP/3 requests, and it says mitigations for the actively exploited Microsoft Exchange Server spoofing flaw are being pushed through the Exchange Emergency Mitigation Service while a full fix is still in progress.
Show sources
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws — www.bleepingcomputer.com — 09.06.2026 20:57
-
09.06.2026 20:57 1 articles · 1mo ago
Microsoft and researchers attribute June 2026 zero-days to anonymous, Calif.io, and Nightmare Eclipse disclosures
Attribution UpdateMicrosoft credits CVE-2026-45586 to an anonymous researcher, the HTTP/2 denial-of-service flaw is credited to Quang Luong and Codex of Calif.io, and Nightmare Eclipse is tied to the GreenPlasma, YellowKey, and Mini-Plasma disclosures; CVE-2020-17103 was originally reported to Microsoft by Google Project Zero researcher James Forshaw in September 2020.
Show sources
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws — www.bleepingcomputer.com — 09.06.2026 20:57