# Microsoft Plugs 200 Vulnerabilities in June 2026 Patch Tuesday, Including Three Public Zero-Days


Microsoft's June 2026 Patch Tuesday delivers a substantial security update addressing 200 vulnerabilities across its product portfolio, including three publicly disclosed zero-day flaws that, fortunately, have not yet been exploited in the wild. The update emphasizes critical remote code execution and privilege escalation vulnerabilities affecting Windows, HTTP.sys, and encryption systems.


## The Threat


This month's patch cycle is particularly significant for its volume and severity. Microsoft classified 33 vulnerabilities as Critical, the highest severity rating in its vulnerability classification system. Of these Critical flaws, 28 are remote code execution (RCE) vulnerabilities—the most dangerous category, as they allow attackers to execute arbitrary code on affected systems without user interaction in some cases.


The three publicly disclosed zero-days present immediate concern:


1. CVE-2026-45586 — Windows Collaborative Translation Framework (CTFMON) elevation of privilege vulnerability

2. CVE-2026-49160 — HTTP.sys HTTP/2 denial of service vulnerability (the "HTTP/2 Bomb")

3. CVE-2026-50507 — Windows BitLocker security feature bypass vulnerability


While none of these flaws are currently known to be actively exploited, their public disclosure means threat actors have detailed information about how to weaponize them, making rapid patching essential.


## Background and Context


Microsoft's Patch Tuesday releases occur monthly, but the volume and nature of vulnerabilities fluctuate based on discovery and responsible disclosure timelines. June 2026's 200-vulnerability patch set reflects ongoing security research across the broader Microsoft ecosystem, though this figure excludes earlier-month updates to products including Azure HorizonDB, Microsoft Copilot variants, Microsoft Exchange Online, and Microsoft Graph.


Additionally, Microsoft's security team coordinated with Google to address 360 vulnerabilities in Microsoft Edge and Chromium-based components, which are counted separately. This coordinated approach demonstrates the interconnected nature of modern software security—a vulnerability in a shared browser engine affects multiple vendors simultaneously.


The breakdown of vulnerabilities by category reveals the diversity of threats:


| Vulnerability Type | Count |

|---|---|

| Remote Code Execution | 55 |

| Elevation of Privilege | 65 |

| Information Disclosure | 30 |

| Spoofing | 27 |

| Security Feature Bypass | 19 |

| Denial of Service | 7 |


Elevation of Privilege (EoP) vulnerabilities, numbering 65, are particularly concerning in enterprise environments where attackers often gain an initial foothold with limited permissions before escalating to administrative access.


## Technical Details


### HTTP/2 Bomb: A Novel Denial-of-Service Attack


The most technically significant public disclosure is CVE-2026-49160, the HTTP/2 Bomb vulnerability discovered by researchers at Calif (an offensive security firm). This flaw exploits fundamental properties of the HTTP/2 protocol itself.


How the Attack Works:

HTTP/2 introduced header compression to reduce bandwidth. The HTTP/2 Bomb abuses this feature by crafting specially formatted headers that decompress into massive payloads within the server's memory. An attacker can send a relatively small network packet that, when decompressed, consumes disproportionately large amounts of RAM on the target server.


The attack mechanism is further amplified through flow-control manipulation—HTTP/2's mechanism for controlling data transmission rates. By adjusting flow-control settings, attackers can prevent servers from freeing allocated memory, essentially trapping resources until the connection closes or the server crashes.


Microsoft's Mitigation:

Rather than patching the HTTP/2 protocol itself (which is outside Microsoft's control), the company introduced a new registry setting: MaxHeadersCount. This configuration allows administrators to cap the maximum number of headers accepted in HTTP/2 and HTTP/3 requests, directly limiting the potential for header-based memory exhaustion attacks. Details are available in KB5102602.


### Windows BitLocker Bypass


CVE-2026-50507 represents a physical security vulnerability—a category often overlooked in purely network-focused threat modeling. BitLocker, Windows' full-disk encryption feature, is bypassed through "improper protection mechanism" when an attacker has physical access to the device.


While the advisory is limited in detail, such flaws typically involve:

  • Exploitation of DMA (Direct Memory Access) ports on hibernation files
  • Recovery key exposure during boot sequences
  • Side-channel attacks on the encryption key storage

  • The "unauthorized attacker" designation suggests the flaw requires physical device access, limiting its exploitability to theft scenarios or insider threats—but in regulated industries like healthcare and finance, this remains a material risk.


    ### CTFMON Elevation of Privilege


    CVE-2026-45586 affects the Windows Collaborative Translation Framework Monitor (CTFMON), a component that runs with high privileges. The vulnerability uses improper link resolution (link following)—a classic file system race condition—to grant SYSTEM-level privileges to an authorized user. While the attacker must already have user-level access, SYSTEM privileges enable lateral movement, credential harvesting, and persistence mechanisms.


    ## Implications for Organizations


    Immediate Risk:

    Organizations running unpatched Windows systems, Windows servers, or HTTP/2-enabled web services are exposed to these three public zero-days. While exploitation is not yet documented, proof-of-concept code could emerge within days of patch deployment or disclosure discussions in security forums.


    Enterprise Prioritization:

    The 28 critical RCE vulnerabilities should be prioritized in patch deployment order, particularly for:

  • Internet-facing Windows systems
  • Exchange servers and email systems
  • Remote Desktop Services (RDP) infrastructure
  • Web servers and proxies running HTTP/2

  • Breach Risk:

    With 55 RCE and 65 EoP vulnerabilities in a single patch cycle, unpatched environments represent critical breach vectors. Threat actors typically mass-scan for known vulnerabilities within hours of patch release, exploiting organizations that lag in deployment.


    Defense-in-Depth Necessity:

    The HTTP/2 Bomb vulnerability illustrates why network-level defenses (rate limiting, connection pooling, reverse proxies with request validation) remain essential even after patching, as similar attacks may exist in other protocols.


    ## Recommendations


    For Organizations:


  • Immediate: Deploy patches to internet-facing systems within 48 hours; prioritize servers with critical RCE vulnerabilities.
  • Short-term: Enable the MaxHeadersCount registry setting (KB5102602) on all HTTP/2-enabled servers as additional mitigation against HTTP/2 Bomb variants.
  • Medium-term: Conduct vulnerability scanning across the entire Windows estate to identify unpatched systems; audit patch deployment pipelines for delays.
  • Long-term: Evaluate physical security controls around encrypted drives to prevent BitLocker bypasses in theft scenarios; implement hardware-backed credential storage where available.

  • For Security Teams:


  • Monitor threat intelligence feeds for CVE-2026-45586, CVE-2026-49160, and CVE-2026-50507 proof-of-concept code.
  • Update intrusion detection signatures and endpoint protection rules to detect exploitation attempts.
  • Conduct tabletop exercises simulating ransomware attacks that leverage EoP flaws for privilege escalation.

  • ---


    ## HackWire Analysis


    The June 2026 Patch Tuesday underscores a critical inflection point in software security: the volume of vulnerabilities now outpaces human operational capacity to patch systematically. Two hundred flaws in a single month—and that's excluding products like Exchange Online and Edge—reflects the reality that modern software is intricate and bug-prone. What's notable is the pattern: 65 privilege escalation flaws and 55 RCE vulnerabilities suggest that foundational security assumptions (process isolation, privilege boundaries, memory safety) remain broken across Microsoft's stack.


    The HTTP/2 Bomb is particularly instructive. Here's a protocol-level design flaw, discovered by dedicated researchers, that affects every HTTP/2 implementation globally. The fact that Microsoft can't *fix* it—only mitigate it with rate-limiting—reveals the gap between security patches (which fix specific code bugs) and security *design* (which prevents entire categories of attack). Organizations patching June vulnerabilities may feel momentarily safer, but they're treating symptoms while the underlying design flaws remain.


    The three public zero-days being unexloited (so far) is fortunate, but temporary. The average time from public disclosure to first active exploitation is now measured in hours. Organizations sitting on unpatched systems as of June 10, 2026, are betting that their systems won't be targeted in the narrow window before they patch—a bet that rarely pays off at scale.


    For defenders, the real story is this: patch deployment speed is now a primary security control, not a secondary one. If your organization takes more than a week to deploy critical patches, you're accepting material breach risk. — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Exploits](https://www.hackwire.news/category/exploits) and [Windows Security](https://www.hackwire.news/category/windows-security)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)