socradar.io 6/10/2026, 2:52:15 PM · external

MS Patch Tuesday 2026 Fixes 206 Flaws Including Three Zero Days

MS Patch Tuesday 2026 Fixes 206 Flaws Including Three Zero Days
Developing story vulnerability 11 articles tracked
Microsoft June 2026 Patch Tuesday fixes 206 flaws, including CVE-2026-49160 zero‑day
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CISA KEV Not in KEV
Patch Patch Available

THE June 2026 Patch Tuesday from Microsoft addresses a significant total of 206 vulnerabilities, including three zero-day vulnerabilities, notably the HTTP/2 Bomb Flaw (CVE-2026-49160). Key highlights include: 1. **Critical Vulnerabilities**: High-risk vulnerabilities identified include CVE-2026-48567 (CVSS 10.0) for Azure HorizonDB and several others rated above 9.0.

2. **Zero-Day Vulnerabilities**: The critical three zero-days pose serious risks, especially CVE-2026-49160 which allows Denial of Service attacks via crafted HTTP requests. 3. **Patching Priorities**: Organizations should prioritize patching systems dealing with HTTP/HTTPS traffic and DHCP infrastructure, while ensuring BitLocker protection on devices is maintained due to bypass risks. 4. **Bulk Updates**: The release emphasizes the urgency of patching to mitigate potential exploitation.

View Primary Source Via socradar.io

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline