news.mlab.sh
Back to the feed
vulnerability

Microsoft ships largest Patch Tuesday on record, with one bug under active attack

Critical
Summary

Microsoft released its largest Patch Tuesday update to date, containing 206 CVEs, driven by the increasing use of AI in vulnerability discovery. A particularly concerning vulnerability, CVE-2026-45657, is described as ‘wormable’ and could allow remote attackers to gain full control of systems, mirroring the capabilities of the 2017 WannaCry ransomware. Additionally, a separate vulnerability affecting Microsoft Defender (CVE-2026-41091) has been actively exploited, highlighting the ongoing urgency for organizations to apply security patches.

Microsoft’s June Patch Tuesday update represents a significant escalation in the frequency and scale of security updates, largely due to the growing role of artificial intelligence in vulnerability identification. Trend Micro’s ZDI reported a record-breaking 208 CVEs, surpassing previous records and emphasizing the accelerated pace of vulnerability discovery. This trend is fueled by AI tools that are identifying flaws faster than traditional methods, leading to larger releases like this one. The ‘wormable’ nature of CVE-2026-45657, a critical vulnerability within the Windows kernel, is particularly alarming, as it possesses the potential to autonomously spread across networks, similar to the devastating impact of WannaCry.

Alongside the core vulnerabilities, a previously exploited flaw affecting Microsoft Defender (CVE-2026-41091) was also addressed. This elevation-of-privilege vulnerability allows attackers with a foothold on a system to gain complete control. Furthermore, a BitLocker bypass vulnerability (CVE-2026-50507) was disclosed, posing a significant risk to devices utilizing Microsoft’s full-disk encryption feature. The situation is further complicated by the actions of a pseudonymous researcher, ‘Nightmare Eclipse,’ who has been releasing exploit code for unpatched Windows flaws, stemming from alleged grievances with Microsoft regarding bug reporting and bounty payments. Microsoft’s initial strong condemnation of Eclipse’s actions has been tempered following a backlash from the security community, and Eclipse has threatened further releases on July 14th.

Read the full article at The Record