Microsoft has released its June 2026 security updates today, addressing 200 vulnerabilities across Windows, Office, Exchange, and related products. Three of these are publicly disclosed zero-day flaws that require urgent attention.
- CVE-2026-45586 — Windows CTFMON Elevation of Privilege: Allows a local attacker to gain full SYSTEM-level access through a link-following exploit. This flaw was publicly disclosed before Microsoft patched it.
- CVE-2026-50507 — BitLocker Security Feature Bypass ("YellowKey"): Could allow a local attacker to access an encrypted drive using a specially crafted USB or EFI partition — bypassing BitLocker's disk encryption protection. Also publicly disclosed before patching.
- CVE-2026-49160 — HTTP.sys Denial of Service ("HTTP/2 Bomb"): Allows attackers to crash Windows web servers by sending small, crafted requests that force the server to allocate disproportionate amounts of memory. Publicly disclosed before patching.
- Who is affected: All businesses running Windows 10, Windows 11, or Windows Server. Organisations using on-premises Exchange Server should also apply the separately released Exchange security updates.
- Deployment note: Always ensure the latest Servicing Stack Update is installed before applying the main cumulative update. Skipping this step can cause security packages to be silently bypassed, leaving systems exposed despite an apparent successful update.
- Defender for Endpoint change: From this month, Microsoft Defender for Endpoint EDR updates will no longer be bundled with Patch Tuesday. They will be delivered separately via Microsoft Update.
If you have a managed IT arrangement, your provider should be rolling out these patches now. Businesses managing their own systems should prioritise applying KB5094126 (Windows 11) or KB5094127 (Windows 10) as soon as possible.
Sources: BleepingComputer | Tenable | Microsoft Support