Microsoft’s June 2026 Patch Tuesday addressed nearly 200 vulnerabilities—the most ever in a single month—including three publicly disclosed zero days, though none were actively exploited in the wild. The patches fixed two exploits from a protest campaign by researcher Nightmare Eclipse (GreenPlasma and YellowKey) an...

Create a landscape editorial hero image for this Studio Global article: What were the key details of Microsoft's record-breaking June 2026 Patch Tuesday, including the total number of flaws patched, the three pub. Article summary: Here are the key details from Microsoft's record-breaking June 2026 Patch Tuesday.. Topic tags: general, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "Microsoft has pushed fixes for 112 common vulnerabilities and exposures (CVEs) on the first Patch Tuesday of 2026, among them a number of" source context "Microsoft patches 112 CVEs on first Patch Tuesday of 2026 | Computer Weekly" Reference image 2: visual subject "Microsoft has pushed fixes for 112 common vulnerabilities and exposures (CVEs) on the first Patch Tuesday of 2026, among them a number of" source context "Microsoft patches 112 CVEs on
Microsoft’s June 2026 Patch Tuesday was not just another monthly security release—it was the largest in the program's history. The company shipped patches for roughly 200 flaws, smashing the previous record of 167 CVEs set in October 2025 . While the sheer volume is staggering, the update is especially notable for fixing three publicly disclosed zero-day vulnerabilities, two of which emerged from a very public protest against Microsoft's vulnerability disclosure practices.
Different security vendors counted slightly different CVE totals due to out-of-band fixes, but the consensus lands close to 200. BleepingComputer and Rapid7 both report 200 flaws; Qualys counted 206, including previously fixed Mariner, Azure, and Copilot bugs; and Tenable logged 198 CVEs . Of these, 33 were rated Critical and the remainder were Important. The category breakdown includes 65 Elevation of Privilege (EoP) flaws, 55 Remote Code Execution (RCE) vulnerabilities, 30 Information Disclosure, 27 Spoofing, 19 Security Feature Bypass, and 7 Denial of Service (DoS) bugs
.
Crucially, none of the three zero-day vulnerabilities were known to have been exploited in the wild before the patches were released .
This is a "link following" flaw in the Windows Collaborative Translation Framework (CTFMON) that allows an authenticated attacker to escalate privileges locally to SYSTEM. Microsoft listed the reporter as anonymous, but security researchers quickly connected it to the “GreenPlasma” exploit publicly released by the researcher Nightmare Eclipse (also known in community discussions as “Chaotic Eclipse”). The disclosure was part of a campaign to protest Microsoft’s bug bounty and vulnerability disclosure programs .
This is an uncontrolled resource consumption vulnerability (CWE-400) in the HTTP/2 protocol stack, assigned a CVSS score of 7.5. An unauthenticated remote attacker can send a small amount of data that forces the server to allocate a disproportionately large amount of memory. By manipulating HTTP/2 flow-control settings, an attacker can keep that memory tied up indefinitely . Discovered by Quang Luong and Codex of Calif.io, the attack can knock affected web servers offline in seconds
. Microsoft introduced a new MaxHeadersCount registry setting (documented in KB5102602) to limit HTTP/2 and HTTP/3 request headers as a mitigation
.
This is a protection-mechanism failure that allows an unauthenticated attacker with physical access to bypass BitLocker encryption by exploiting the Windows Recovery Environment on TPM-only drives. This is the second exploit from the Nightmare Eclipse campaign fixed this month, publicly known as “YellowKey” .
The researcher Nightmare Eclipse publicly launched a wave of Windows zero-days—named BlueHammer, MiniPlasma, RedSun, UnDefend, GreenPlasma, and YellowKey—in protest of how Microsoft handles bug bounties. While Microsoft’s June patches addressed GreenPlasma and YellowKey, three others from the same campaign (BlueHammer, RedSun, and UnDefend) were reported as actively exploited in early June, prompting CISA to add them to its Known Exploited Vulnerabilities catalog .
The mandatory June updates for Windows 11 delivered more than security fixes. Two primary cumulative updates were released: KB5094126 for versions 25H2 (build 26200.8457) and 24H2 (build 26100.8457), and KB5093998 for version 23H2 (build 22631.7079) . Microsoft also released an extended security update, KB5094127, for Windows 10
.
Key new features in the Windows 11 update include :
On the same day, Adobe released 11 security advisories plugging 123 vulnerabilities across products including Acrobat Reader, ColdFusion, InDesign, and Experience Manager. Of those, 47 were rated Critical and could lead to arbitrary code execution, privilege escalation, or denial-of-service .
Combined, Microsoft and Adobe pushed out fixes for a total of 329 vulnerabilities on June 9, 2026 . The broader ecosystem also saw action, with Google patching a massive 360 flaws in Microsoft Edge/Chromium earlier in the month—vulnerabilities that fall outside the standard Patch Tuesday count
.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Microsoft’s June 2026 Patch Tuesday addressed nearly 200 vulnerabilities—the most ever in a single month—including three publicly disclosed zero days, though none were actively exploited in the wild.
Microsoft’s June 2026 Patch Tuesday addressed nearly 200 vulnerabilities—the most ever in a single month—including three publicly disclosed zero days, though none were actively exploited in the wild. The patches fixed two exploits from a protest campaign by researcher Nightmare Eclipse (GreenPlasma and YellowKey) and a critical HTTP/2 denial of service flaw dubbed the “HTTP/2 Bomb” (CVE 2026 49160).
Combined with Adobe’s 123 fixes, the day resolved 329 vulnerabilities. The mandatory Windows 11 update also delivered new consumer features like Xbox Mode, Shared Audio, and Task Manager NPU monitoring.