Microsoft released its June Patch Tuesday updates to address more than 200 vulnerabilities across Windows, .NET, Office, Teams, Exchange Server, Azure, Visual Studio Code, and other products, including three publicly disclosed zero-days: CVE-2026-45586 in the Windows Collaborative Translation Framework (CTFMON), CVE-2026-49160 in HTTP.sys, and CVE-2026-50507 in Windows BitLocker. The update covered a broad range of impact types, including elevation of privilege, spoofing, denial of service, security feature bypass, information disclosure, and remote code execution, with notable high-severity issues such as CVE-2026-44815, a DHCP Client Service RCE flaw rated CVSS 9.8, and CVE-2026-47281, a Visual Studio Code elevation-of-privilege bug rated CVSS 9.6.
Researchers described the release as part of a wider 2026 "patch tsunami," estimating roughly 198 to 208 Microsoft CVEs in the June cycle and about 571 CVEs overall when Chromium and other third-party issues were included, with 38 rated critical. One of the zero-days, CVE-2026-49160, was detailed as an HTTP/2 and HTTP/3 header compression flaw that can trigger resource exhaustion through a "compression bomb," and Microsoft added a MaxHeadersCount registry mitigation; the bug was reportedly credited to OpenAI Codex, underscoring claims that AI-assisted discovery is accelerating vulnerability reporting and increasing patch-management pressure on enterprises.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
HiSolutions reported that Microsoft credited OpenAI Codex with reporting CVE-2026-49160, highlighting AI-assisted vulnerability discovery as part of the June 2026 disclosure wave.
In connection with the June 2026 Patch Tuesday coverage, HiSolutions said Microsoft introduced a MaxHeadersCount registry mitigation for the publicly disclosed zero-day CVE-2026-49160 affecting HTTP/2 and HTTP/3 header compression handling.
On 2026-06-10, Microsoft released its June 2026 Patch Tuesday security updates, addressing 206 vulnerabilities across products including Windows, .NET, Office, Teams, Exchange Server, Azure, and Visual Studio Code. The release included three publicly disclosed zero-days: CVE-2026-45586, CVE-2026-49160, and CVE-2026-50507.
HiSolutions reported that Cisco PSIRT knew of limited exploitation of the critical Cisco Catalyst SD-WAN Controller authentication flaw CVE-2026-20182 in May 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.