# Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Three Critical Network RCEs


Microsoft released fixes Tuesday for 206 security vulnerabilities—the largest single patch batch in company history—with 39 rated Critical and three zero-day flaws disclosed at the time of release. The update includes multiple remote code execution vulnerabilities in Windows kernel, networking components, and critical system services that require no user authentication and no user interaction. The advisory also covers three BitLocker encryption bypass vulnerabilities, including a public proof-of-concept exploit, making this one of Microsoft's most critical patch Tuesday cycles in years.


## The Threat


Microsoft's June 2026 Patch Tuesday addresses a concerning trend in Windows vulnerability patterns: an increasing concentration of critical flaws in low-level networking and kernel components that underpin enterprise infrastructure. The most dangerous vulnerabilities—CVE-2026-45657, CVE-2026-47291, and CVE-2026-44815—are all remote code execution flaws affecting core Windows networking and kernel functionality. These vulnerabilities can be exploited over the network with no credentials required and no user interaction, meaning a malicious actor can simply send specially crafted network packets to achieve system-level code execution.


CVE-2026-44815 deserves particular attention: it's a stack-based buffer overflow in the Windows DHCP Client service that runs with high privilege on virtually every networked Windows system. DHCP is a fundamental network service deployed in 99% of enterprise environments. According to security experts quoted in the original advisory, successful exploitation could lead directly to server compromise, malware installation, and lateral movement through the network. An attacker doesn't need to target a specific workstation—they can compromise DHCP infrastructure and reach hundreds of systems simultaneously.


The three publicly disclosed zero-days (CVE-2026-45586, CVE-2026-49160, and CVE-2026-50507) represent a different threat vector: encryption bypass and denial-of-service attacks. The BitLocker bypasses, particularly CVE-2026-50507 (linked to the "bitskrieg" attack), allow attackers with physical access to extract encrypted data from locked systems. While this requires physical access, it undermines a critical security boundary that many organizations rely on for data protection on stolen or decommissioned devices. Combined with network-based breaches, this creates a multi-stage attack scenario: remote compromise followed by offline data extraction if drives are physically recovered.


## Severity and Impact


| Vulnerability ID | CVSS Score | Severity | Component | Attack Vector | Authentication | User Interaction |

|---|---|---|---|---|---|---|

| CVE-2026-45657 | 9.8 | Critical | Windows Kernel (use-after-free) | Network | None | None |

| CVE-2026-47291 | 9.8 | Critical | Windows HTTP.sys | Network | None | None |

| CVE-2026-44815 | 9.8 | Critical | Windows DHCP Client | Network | None | None |

| CVE-2026-45586 | 7.8 | Important | Windows CTFMON | Local | Low | None |

| CVE-2026-45658 | 7.8 | Important | Windows BitLocker | Local | None | Required |

| CVE-2026-49160 | 7.5 | Important | HTTP.sys (HTTP/2 DoS) | Network | None | None |

| CVE-2026-45585 | 6.8 | Important | Windows BitLocker | Local | None | Required |

| CVE-2026-50507 | 6.8 | Important | Windows BitLocker | Local | None | Required |

| CVE-2026-45655 | 5.3 | Important | Windows BitLocker | Local | None | Required |


Vulnerability Breakdown (206 Total):

  • 39 Critical | 167 Important
  • Privilege Escalations: 63
  • Remote Code Execution: 56
  • Information Disclosure: 30
  • Spoofing: 27
  • Security Feature Bypass: 20
  • Denial of Service: 7
  • Tampering: 3

  • ## Affected Products


    Windows Operating Systems & Components:

  • Windows Kernel (multiple versions)
  • Windows DHCP Client service
  • Windows HTTP.sys (IIS and native HTTP APIs)
  • Windows Collaborative Translation Framework (CTFMON)
  • Windows BitLocker Device Encryption
  • Windows Remote Procedure Call (RPC)

  • Enterprise & Server Products:

  • Microsoft Exchange Server
  • Microsoft SQL Server
  • Microsoft SharePoint Server
  • Microsoft Office applications
  • Microsoft Teams
  • Microsoft Hyper-V

  • Additional Components:

  • Microsoft Edge browser (includes 350+ Chromium patches from Google)
  • Windows Subsystem for Linux (WSL)
  • Microsoft .NET Framework

  • Third-Party Components:

  • Windows Kernel vulnerability (CVE-2025-10263)
  • UEFI Secure Boot bypass (CVE-2026-8863)

  • ## Mitigations


    Immediate Actions (Within 24-48 Hours):

    1. Deploy Windows patches immediately to all systems, prioritizing servers, domain controllers, and systems handling DHCP services. Treat CVE-2026-44815 as a critical priority—any system exposed to untrusted networks is at risk.

    2. Apply HTTP.sys patches to all IIS servers and systems exposing HTTP services. CVE-2026-47291 and CVE-2026-49160 can be exploited remotely without authentication.

    3. Patch Windows Kernel fixes (CVE-2026-45657) across the environment. This affects all Windows versions from Windows 10 through Windows Server 2022.


    Near-Term Actions (This Week):

    1. Segment DHCP servers from untrusted network segments. If possible, restrict DHCP traffic to authorized subnets only. Monitor DHCP servers for unexpected traffic patterns that may indicate exploitation attempts.

    2. Update Microsoft Edge and validate Chromium patch coverage across all instances.

    3. Enable BitLocker integrity monitoring where available. While patches address the known bypasses, integrity checking can detect tampering attempts.


    Ongoing Measures:

    1. Implement network-based intrusion detection focused on Windows kernel exploitation signatures and unusual HTTP.sys traffic patterns.

    2. Conduct privilege audit on service accounts running DHCP and HTTP services. Restrict these accounts to minimum necessary permissions.

    3. Enable Windows Defender Exploit Guard on workstations and servers to provide defense-in-depth against kernel-level exploitations.

    4. Establish a patching baseline: With 206 fixes, organizations should define deployment windows (critical within 48 hours, important within 2 weeks, standard within 30 days).


    For Physical Security:

    Organizations concerned about BitLocker bypasses should implement additional controls: full disk encryption at the firmware level where possible, TPM 2.0 enforcement, and secure boot configuration audits.


    ## References


  • [Microsoft Security Update Guide](https://msrc.microsoft.com/update-guide)
  • [CVE-2026-45657 Details](https://www.cve.org/CVERecord?id=CVE-2026-45657)
  • [CVE-2026-44815 DHCP Client Vulnerability](https://www.cve.org/CVERecord?id=CVE-2026-44815)
  • [CVE-2026-45585 BitLocker YellowKey PoC](https://www.cve.org/CVERecord?id=CVE-2026-45585)
  • [CVSS Vector Details](https://www.first.org/cvss/)
  • [Google Chromium Release Notes](https://chromereleases.googleblog.com/)

  • ---


    ## HackWire Analysis


    This patch cycle marks a significant escalation in the severity and concentration of Windows vulnerabilities. The three 9.8-CVSS flaws are not isolated edge cases—they represent a systemic vulnerability pattern in Microsoft's core networking stack. DHCP, HTTP.sys, and the Windows kernel are architectural layers that touch nearly every Windows deployment globally, making these bugs potentially the most impactful network-exploitable flaws Microsoft has released in the past 18 months.


    The BitLocker bypass cluster is equally notable. Four separate BitLocker bypasses in a single month suggests either a fundamental weakness in Microsoft's full-disk encryption implementation or a concentrated research effort against encryption boundaries. The existence of public proof-of-concept code (YellowKey) for CVE-2026-45585 means attackers already have exploitation knowledge. Organizations relying on BitLocker as their primary data protection mechanism should recognize this patch cycle as a wake-up call: encryption keys are only as strong as the boot and kernel integrity processes protecting them.


    What's missing from headlines: the cascade risk. In a sophisticated attack, an adversary could weaponize CVE-2026-44815 to compromise a DHCP server, then use that foothold to deliver malware across an entire subnet. If that malware includes physical access to stolen equipment, CVE-2026-50507 becomes the extraction vector for encrypted data. Microsoft patched the individual links in that chain, but defenders need to recognize that defending against this batch of flaws requires layered mitigations—not just patching and moving on.


    The record volume (206 flaws) should also trigger organizational introspection: if patching infrastructure is already overwhelmed, this batch will stress it further. Enterprises need to stop treating all "Important" severity flaws equally and instead focus on the network-exploitable critical flaws first, deferring lower-risk patches to scheduled maintenance windows.


    — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)