Microsoft has released a record-breaking 206 security patches to address critical vulnerabilities, including several zero-day flaws and remote code execution risks affecting its Windows software portfolio.
Key Points
- Microsoft addressed 206 vulnerabilities, including 39 critical and 167 important flaws, marking a record volume for a single update cycle.
- Three critical vulnerabilities (CVE-2026-45657, CVE-2026-47291, and CVE-2026-44815) carry a CVSS score of 9.8, allowing unauthorized remote code execution.
- Patches include fixes for multiple BitLocker security feature bypasses, such as the "YellowKey" and "bitskrieg" exploits, which allow access to encrypted data.
- The update mitigates the "HTTP2/Bomb" denial-of-service attack by introducing a new "MaxHeadersCount" registry setting to limit header-based memory exhaustion.
- Security experts attribute the surge in discovered vulnerabilities to the increasing use of AI-assisted tools in identifying software flaws.