AUTO-UPDATED

Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs

Microsoft has released a record-breaking 206 security patches to address critical vulnerabilities, including several zero-day flaws and remote code execution risks affecting its Windows software portfolio.

Key Points

  • Microsoft addressed 206 vulnerabilities, including 39 critical and 167 important flaws, marking a record volume for a single update cycle.
  • Three critical vulnerabilities (CVE-2026-45657, CVE-2026-47291, and CVE-2026-44815) carry a CVSS score of 9.8, allowing unauthorized remote code execution.
  • Patches include fixes for multiple BitLocker security feature bypasses, such as the "YellowKey" and "bitskrieg" exploits, which allow access to encrypted data.
  • The update mitigates the "HTTP2/Bomb" denial-of-service attack by introducing a new "MaxHeadersCount" registry setting to limit header-based memory exhaustion.
  • Security experts attribute the surge in discovered vulnerabilities to the increasing use of AI-assisted tools in identifying software flaws.

Why it Matters

The unprecedented volume of patches highlights a significant shift in the cybersecurity landscape as AI-driven discovery tools accelerate the identification of software vulnerabilities. Organizations must prioritize these updates to prevent potential system compromises, as many of the addressed flaws require no user interaction to exploit.
Internet Published by info@thehackernews.com (The Hacker News)
Read original