Microsoft resolved a Windows Update caching failure that caused some Intune- and enterprise-managed Windows devices to lose enrollment context temporarily and be treated as unmanaged, bypassing policies that block automatic driver deployment. The incident, tracked as MO1332784, led to unauthorized but Microsoft-signed driver and BIOS updates being installed across affected organizations, with some administrators reporting large-scale operational disruption including audio and video failures. Microsoft said the issue was mitigated, normal policy enforcement has resumed, and administrators should review systems for unexpected driver or BIOS changes and roll back affected updates where necessary.
Separately, Microsoft released Edge security updates for three vulnerabilities, including critical remote code execution flaw CVE-2026-45495, which could let an attacker execute code if a user visits a malicious webpage or opens a crafted file. The company also patched CVE-2026-45494, a universal cross-site scripting issue in navigation handling, and CVE-2026-45492, an origin validation error affecting Edge’s managed sign-in flow; both were publicly disclosed through ZDI advisories and credited to Orange Tsai of DEVCORE. Microsoft urged rapid browser updates and warned that the lower-severity Edge flaws could be chained with other bugs to increase impact.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft released a security update for Edge to fix CVE-2026-45495, a remote code execution flaw in feedback log processing, along with related vulnerabilities CVE-2026-45494 and CVE-2026-45492.
Microsoft updated admin center incident report MO1332784 to state that the caching misconfiguration had been fixed and advised administrators to review unexpected BIOS or driver changes installed between June 1 and June 4.
Microsoft resolved the service degradation that had bypassed Windows driver auto-update controls on managed devices, restoring normal policy enforcement and mitigating the caching-service misclassification issue.
ZDI publicly released advisories for CVE-2026-45492 and CVE-2026-45494, two Microsoft Edge flaws affecting origin validation and navigation handling. Both advisories said Microsoft had issued updates to address the issues.
The Microsoft 365 service degradation affecting Windows driver auto-update controls on managed devices was first reported and tracked as Microsoft reference MO1332784 and NHSmail reference INC46841357.
Microsoft acknowledged an incident in which a Windows Update caching service issue caused some enterprise-managed devices to be treated as unmanaged, bypassing driver approval restrictions and allowing unintended driver installations.
Orange Tsai of the DEVCORE Research Team reported the Microsoft Edge universal cross-site scripting vulnerability CVE-2026-45494 to ZDI under coordinated disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceghacks.net
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.