Microsoft released security updates for 203 vulnerabilities across its product portfolio, including 33 rated critical, and patched six zero-day flaws. One of the zero-days, CVE-2026-42897, was reported as actively exploited in the wild; it affects Microsoft Exchange Server and allows spoofing through an input-sanitization weakness that can trigger JavaScript execution in the Outlook on the web context when a crafted email is opened.
The update set also addressed multiple Windows zero-days, including the Windows BitLocker Security Feature Bypass Vulnerability tracked as CVE-2026-45585. According to public reporting, the Windows flaws span components such as CTFMON, HTTP.sys, BitLocker, and the Cloud Files Mini Filter Driver, with impacts including privilege escalation, denial of service, security feature bypass, and potential access to encrypted data. Microsoft urged organizations to deploy the patches promptly to reduce exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft released its June 2026 security updates addressing 203 vulnerabilities, including 33 critical flaws and six zero-days. CSIRT.SK highlighted that one of the zero-days, CVE-2026-42897 affecting Microsoft Exchange Server, was actively exploited in the wild.
Microsoft's Security Update Guide published an advisory for CVE-2026-45585, a Windows BitLocker Security Feature Bypass Vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.