news.mlab.sh
Back to the feed
vulnerability

Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs

Critical
Summary

Microsoft released a significant security update addressing 206 vulnerabilities across its software portfolio, including multiple critical Remote Code Execution (RCE) flaws and several zero-days. The update focuses on patching vulnerabilities in Windows Kernel, DHCP Client, BitLocker, and other components, highlighting the ongoing need for proactive security measures. This release includes fixes for vulnerabilities exploited through network traffic and physical access, emphasizing the potential for severe impact including data theft and system compromise.

Microsoft has released a substantial security update, patching 206 vulnerabilities across its software ecosystem. The update includes three critical Remote Code Execution (RCE) flaws, notably CVE-2026-45657, which allows an attacker to execute code with system-level privileges via crafted network traffic. Additionally, the update addresses vulnerabilities in Windows HTTP.sys, DHCP Client, and BitLocker, with several of these being actively exploited through zero-day vulnerabilities. The inclusion of vulnerabilities like CVE-2026-44815, which requires no credentials to compromise a system, underscores the ease with which attackers can leverage these flaws. Microsoft has also implemented mitigations, such as the "MaxHeadersCount" registry setting, to combat attacks like HTTP2/Bomb, which can overwhelm servers with excessive HTTP headers.

Read the full article at The Hacker News