{"id":630788,"date":"2026-06-10T08:25:13","date_gmt":"2026-06-10T08:25:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/630788\/"},"modified":"2026-06-10T08:25:13","modified_gmt":"2026-06-10T08:25:13","slug":"ai-is-making-patch-tuesday-kinda-fun-again","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/630788\/","title":{"rendered":"AI is making Patch Tuesday (kinda) fun again"},"content":{"rendered":"<p>Microsoft set a record with its June Patch Tuesday release, addressing 206 CVEs across its products and shipping fixes for them, with 38 deemed critical and the rest important. Three are listed as publicly known, but none (so far) have been exploited in the wild.<\/p>\n<p>We have no idea how many of these <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Jun\" rel=\"nofollow noopener\" target=\"_blank\">June bugs<\/a> were uncovered using AI tools. Unlike last month\u2019s patching event, when Redmond <a href=\"https:\/\/www.theregister.com\/patches\/2026\/05\/13\/doozy-of-a-patch-tuesday-includes-30-critical-microsoft-cves\/5239224\" rel=\"nofollow noopener\" target=\"_blank\">disclosed<\/a> its agentic bug-hunting system found 16 of the 137 vulnerabilities, there\u2019s no word on any AI assists for new releases.\u00a0<\/p>\n<p>Still, it\u2019s safe to assume AI played a major role. As Tom Gallagher, VP of engineering at Microsoft Security Response Center, said about May&#8217;s Patch Tuesday with a whopping 30 critical flaws: \u201cWe expect releases to continue trending larger for some time.\u201d<\/p>\n<p>June\u2019s Patch Tuesday proved Gallagher correct, surpassing May in both overall volume and critical bugs.<\/p>\n<p>\u201cI\u2019ve been counting CVEs on Patch Tuesday since 2017, and this is by far the largest monthly release in that time,\u201d Zero Day Initiative\u2019s bug hunter in chief Dustin Childs <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2026\/6\/9\/the-june-2026-security-update-review\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> in his review.\u00a0<\/p>\n<p>\u201cIt is extraordinary that Microsoft can produce so many patches in a single month, but it does raise concerns,\u201d he added, asking, as we did: How many were found via AI?<\/p>\n<p>And: \u201cHow many patches were generated using AI to assist in coding or testing? What quality issues may exist in these patches? And likely most importantly, is this the new normal?\u201d<\/p>\n<p>Childs noted that May and <a href=\"https:\/\/www.theregister.com\/security\/2026\/04\/14\/microsofts-massive-patch-tuesday-its-raining-bugs\/5219841\" rel=\"nofollow noopener\" target=\"_blank\">April<\/a> also saw mega releases. <\/p>\n<p>\u201cShould sysadmins adjust their processes for prioritization and patch deployment based on this new volume of updates? Unfortunately, Microsoft is not providing those answers right now,\u201d he wrote, adding in this fun fact: \u201cThe current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018.\u201d<\/p>\n<p>Wowza.\u00a0<\/p>\n<p>While it\u2019s fun to watch from a purely speculative standpoint, as in: &#8220;Will Microsoft top 300 next month?&#8221;, our thoughts and prayers are nonetheless with sysadmins and vulnerability management teams drowning in the AI-induced vulnpocalypse by now.\u00a0<\/p>\n<p>None of the Patch Tuesday security holes are listed as under attack \u2013 at least not yet\u00a0\u2013 but three are listed as publicly known. Let\u2019s take a look at those first.<\/p>\n<p>Three known vulnerabilities<\/p>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-49160\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2026-49160<\/a> is an HTTP.sys denial of service vulnerability that <a href=\"https:\/\/www.theregister.com\/security\/2026\/06\/04\/openais-codex-chains-decade-old-dos-techniques-into-http\/2-bomb\/5251377\" rel=\"nofollow noopener\" target=\"_blank\">we wrote about earlier<\/a> this month. Calif researcher Quang Luong discovered the attack with an assist from OpenAI&#8217;s Codex agent, named it HTTP\/2 Bomb, and said it exploits the HTTP\/2 header compression algorithm by sending thousands of tiny messages to the server, forcing it to rapidly allocate memory and ultimately crash.<\/p>\n<p>At the time, a Microsoft spokesperson told The Register that Redmond was \u201caware and actively investigating appropriate mitigations.\u201d On Tuesday, the tech giant fixed the security issue by introducing a new MaxHeadersCount registry setting, which allows users to limit the number of headers included in HTTP\/2 and HTTP\/3 requests, and should prevent denial-of-service attacks.<\/p>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-50507\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2026-50507<\/a>, a security feature bypass bug in Windows BitLocker, is the second CVE listed as publicly disclosed, and \u201cexploitation more likely.\u201d An attacker with physical access to the vulnerable system could bypass the BitLocker Device Encryption feature and gain access to the device&#8217;s encrypted data, according to the advisory.<\/p>\n<p>This flaw also seems to be a patch for one of the <a href=\"https:\/\/www.theregister.com\/security\/2026\/05\/13\/disgruntled-researcher-releases-two-more-microsoft-zero-days\/5239758\" rel=\"nofollow noopener\" target=\"_blank\">zero-days dropped<\/a> in the <a href=\"https:\/\/www.theregister.com\/security\/2026\/05\/28\/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump\/5248085\" rel=\"nofollow noopener\" target=\"_blank\">ongoing war<\/a> between <a href=\"https:\/\/www.theregister.com\/security\/2026\/06\/02\/microsoft-reaches-for-olive-branch-after-public-dustup-with-0-day-researcher\/5249945\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft and a disgruntled bug hunter<\/a> known as Nightmare Eclipse &#8211; likely the <a href=\"https:\/\/www.theregister.com\/security\/2026\/05\/13\/disgruntled-researcher-releases-two-more-microsoft-zero-days\/5239758\" rel=\"nofollow noopener\" target=\"_blank\">YellowKey vulnerability<\/a> disclosed in May. Nightmare has published details about and in some cases, full proof-of-concept exploit code for six zero-days, and promised a \u201cbone shattering\u201d release on June 14.<\/p>\n<p>The third publicly known bug, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-50507\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2026-45586<\/a>, is a Windows Collaborative Translation Framework (CTFMON) elevation of privilege vulnerability that can be abused by an authorized attacker to elevate privileges locally and gain SYSTEM access. From there, miscreants could deploy malware, steal data, and move laterally through the victim&#8217;s environment &#8211; so patch this one sooner.<\/p>\n<p>Plus these two (of 38) critical bugs<\/p>\n<p>In addition to those three known vulnerabilities that made the rounds before Microsoft issued a patch, a couple of critical-rated 9.8 security flaws are worth highlighting this month.<\/p>\n<p>The first, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-45657\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2026-45657<\/a>, is a Windows kernel remote code execution (RCE) bug that allows remote, unauthenticated attackers to run code with system-level privileges without any user interaction. It\u2019s due to an error in how the Windows kernel processes some TCP\/IP data, and can be exploited by sending malicious network packets to a vulnerable Windows system, thus triggering the flaw.\u00a0<\/p>\n<p>While it\u2019s listed as \u201cexploitation less likely\u201d by Redmond, we like Childs\u2019 response. \u201cRest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit,\u201d he said. \u201cTest and deploy this patch quickly.\u201d<\/p>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-47291\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2026-47291<\/a>, an HTTP.sys RCE vulnerability that also earned a 9.8 CVSS rating, deserves attention as it can also be triggered with zero user interaction and Microsoft says it\u2019s \u201cmore likely\u201d to be exploited.<\/p>\n<p>\u201cThis vulnerability creates severe business risk because HTTP.sys is used by Windows services that process HTTP traffic,\u201d Alex Vovk, CEO and co-founder of patch-management vendor Action1, told The Register. \u201cA successful attack could lead to server takeover, malware deployment, data theft, service disruption, and lateral movement across the environment. Internet-facing systems are especially exposed.\u201d<\/p>\n<p>The good news: systems using the Windows HTTP stack\u2019s default MaxRequestBytes registry value are not affected. In the advisory, Redmond provides detailed instructions on how to edit registry settings, which can buy admins some time (and security) while deploying the patch. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft set a record with its June Patch Tuesday release, addressing 206 CVEs across its products and shipping&hellip;\n","protected":false},"author":2,"featured_media":630789,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-630788","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/630788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=630788"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/630788\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/630789"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=630788"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=630788"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=630788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}