Microsoft released its largest-ever Patch Tuesday on 10 June 2026, addressing over 200 security vulnerabilities across Windows, Microsoft 365, and related products. Businesses should prioritise applying these updates promptly.
- Scale: More than 200 CVEs addressed in a single release, with 33 rated Critical. This is the biggest single Patch Tuesday in the programme's history.
- Wormable Windows flaw (CVSS 9.8): A critical vulnerability in the Windows TCP/IP stack allows remote code execution with no user interaction. All Windows 10, 11, and Server versions are affected. Microsoft has flagged this as potentially wormable, meaning it could spread between machines on the same network.
- BitLocker bypass (CVE-2026-50507 "YellowKey"): A publicly disclosed flaw allows a person with physical access to a device to bypass BitLocker full-disk encryption. Relevant for businesses with encrypted laptops in shared or public environments.
- HTTP/2 denial-of-service (CVE-2026-49160 "HTTP/2 Bomb"): A publicly disclosed vulnerability that can be used to knock web-facing servers offline. Affects businesses running on-premises web services.
- EDR update delivery change: Microsoft Defender for Endpoint endpoint detection and response updates will no longer be bundled with monthly Windows updates. They will now be delivered separately via Microsoft Update.
Ensure Windows Update has run on all business devices and verify patches have applied successfully. Contact your IT provider if you need assistance prioritising or deploying these updates. Source: Zero Day Initiative - June 2026 Security Update Review.