Microsoft released its largest-ever monthly security update on 9 June 2026, patching 206 vulnerabilities across Windows, Exchange Server, and related products. Three zero-day vulnerabilities are included, one of which allows attackers to bypass BitLocker disk encryption with physical access to a device.
- What it is: The June 2026 Patch Tuesday update bundle, addressing 206 flaws with 33 rated Critical. This is the largest single Patch Tuesday release in Microsoft's history.
- Who is affected: All Windows 10, Windows 11, and Windows Server users. Exchange Server customers also have separate security updates this month.
- Key vulnerabilities patched:
- YellowKey (CVE-2026-45585): A backdoor in the Windows Recovery Environment allowing an attacker with physical access to bypass BitLocker encryption on Windows 11 and Server 2022/2025.
- CVE-2026-45586: An elevation of privilege flaw giving attackers SYSTEM-level access on compromised Windows machines.
- HTTP/2 Bomb (CVE-2026-49160): A denial-of-service vulnerability affecting servers and hosted services.
- What to do: Apply this month's Windows updates as a priority. Businesses running Windows Server or Exchange Server should ensure their IT provider has applied June's patches. Confirm automatic updates are enabled on all business workstations.
We recommend applying this update cycle within the next 7 days given the volume of Critical-rated fixes. Sources: BleepingComputer, Microsoft Security Update Guide, Exchange Server Update.