vulnerability Microsoft smashes Patch Tuesday record for second successive month Microsoft released a massive Patch Tuesday update, exceeding 600 security vulnerabilities – the largest in the program's history. This surge in vulnerabilities, driven in part by AI-assisted discovery, has led to a significant increase in exploited flaws, with two vulnerabilities already being actively exploited in the… The Record · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-55040UNpatch tuesdayvulnerabilityexploit
threat-intel Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes Microsoft's July 2026 Patch Tuesday update is the largest in the program's history, containing 622 unique CVEs, including three zero-day vulnerabilities. The sheer volume of updates presents a significant prioritization… Dark Reading · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch-tuesdayzero-dayvulnerability
threat-intel Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Microsoft released its largest Patch Tuesday update to date, encompassing 622 security updates, with two of these fixes already being actively exploited by attackers. These vulnerabilities, affecting SharePoint Server an… The Hacker News · Jul 14, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-50661zero-dayprivilege escalationremote code execution
vulnerability New Windows Zero-Day Exploit ‘RoguePlanet’ Released A new Windows zero-day exploit, dubbed RoguePlanet, has been released by the threat actor Nightmare Eclipse, targeting Microsoft Defender and potentially leading to local privilege escalation and BitLocker bypass. This f… SecurityWeek · Jun 10, 2026 High CVE-2026-45586CVE-2026-50507CVE-2026-41091USzero-daylocal privilege escalationbitlocker
vulnerability Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft released a significant security update addressing 206 vulnerabilities across its software portfolio, including multiple critical Remote Code Execution (RCE) flaws and several zero-days. The update focuses on pa… The Hacker News · Jun 10, 2026 Critical CVE-2025-10263CVE-2026-8863CVE-2026-45657USzero-dayrcebitlocker
vulnerability Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges A new Microsoft Defender zero-day vulnerability, dubbed "RoguePlanet," has emerged, allowing attackers to gain SYSTEM privileges on fully patched Windows 10 and 11 systems via a race condition. The vulnerability was disc… BleepingComputer · Jun 9, 2026 High zero-dayrace conditionremote code execution
threat-intel A Record-Breaking Patch Tuesday for June 2026 Microsoft released a record-breaking 200 security patches on June 2026, addressing numerous vulnerabilities across its operating systems and software. Several critical flaws, including those identified by the security re… Krebs on Security · Jun 9, 2026 High CVE-2026-49160CVE-2026-45586CVE-2026-50507USzero-daypatch tuesdayai
threat-intel Blame AI: Patch Tuesday Hits Record 206 CVEs Microsoft’s June 2026 Patch Tuesday update released a record-breaking 206 CVEs, signaling a potential shift towards larger and more frequent security updates driven by the accelerating pace of vulnerability discovery fac… Dark Reading · Jun 9, 2026 High CVE-2026-45586CVE-2026-49160CVE-2026-50507USvulnerabilityzero-dayai
threat-intel Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash This article reports on a controversy between Microsoft and a security researcher, known as Nightmare Eclipse, regarding the disclosure of several zero-day vulnerabilities affecting Microsoft products. Microsoft initiall… SecurityWeek · Jun 3, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825USzero-dayvulnerability disclosurelegal action
threat-intel Microsoft says it will not pursue security researchers after zero-day backlash Microsoft retracted a controversial blog post condemning security researchers who disclose zero-day vulnerabilities, stating it has no intention to pursue legal action against them. The initial statement, perceived as a… The Record · Jun 1, 2026 Medium UKzero-dayvulnerabilityresponsible disclosure
vulnerability Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has strongly criticized the public disclosure of zero-day vulnerabilities affecting Windows components, particularly following a researcher's independent disclosures. The company asserts that uncoordinated disc… The Hacker News · May 28, 2026 High CVE-2026-33825CVE-2026-41091CVE-2026-45498zero-dayvulnerabilitydisclosure
vulnerability Microsoft shares mitigation for YellowKey Windows zero-day Microsoft has released mitigation steps for a newly disclosed Windows zero-day vulnerability, dubbed YellowKey, which allows unauthorized access to BitLocker-protected drives. The vulnerability was initially revealed by… BleepingComputer · May 20, 2026 High CVE-2026-33825CVE-2026-45585zero-daybitlockerwinre
threat-intel Windows Zero-Day Barrage Continues After Patch Tuesday A security researcher known as "Nightmare Eclipse" has disclosed six Windows zero-day vulnerabilities over the past six weeks, some of which are actively being exploited. These vulnerabilities, including YellowKey, Green… Dark Reading · May 19, 2026 High CVE-2020-17103CVE-2026-33825USzero-daybitlockerprivilege escalation
vulnerability Zero-Day Exploit Against Windows BitLocker A new zero-day exploit, dubbed YellowKey, has been discovered targeting Windows BitLocker encryption. The vulnerability allows attackers to bypass BitLocker's security measures with physical access to the affected device… Schneier on Security · May 18, 2026 High zero-dayencryptionbitlocker