INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Copilot SearchLeak Attack Allows 1-Click Data Theft
| 2026-06-15 19:27 CRITICAL HIGH AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH
Executive Summary
AI-generated
The threat of a sophisticated attack is looming, with the latest incident data revealing a novel vulnerability in Microsoft Copilot that could allow attackers to silently exfiltrate user files. This three-stage vulnerability, dubbed parameter-to-prompt Injection (P2P), works as an unknown subset of indirect prompt-injection attacks and needs to be on defender radar screens. The attack can be crafted using the link itself, which opens Microsoft 365 Copilot Search, structured so that whatever prompt is behind the "q" parameter is accepted by the search. This allows attackers to use this link structure as a opening to craft malicious prompts that victims' Enterprise Copilot systems will interpret and respond to. The vulnerability has been patched with a critical score of 6.5 for CVE-2026-42824, but its impact extends beyond just Microsoft Copilot, exposing organizations to unnecessary data exposure and treating AI systems as part of their attack surface rather than trusted abstraction.
Technical Mitigations AI-generated
* Implement Prompt Isolation: Microsoft should implement prompt isolation to prevent indirect prompt-injection attacks like SearchLeak. This can be achieved by using a combination of Content Security Policy (CSP) and input validation mechanisms.
* Use Input Validation and Sanitization: Implement robust input validation and sanitization mechanisms in AI-powered enterprise assistants, such as Copilot, to prevent malicious prompts from being executed. This includes validating user input before passing it through the system.
* Implement Output Rendering Isolation: Microsoft should implement output rendering isolation to prevent attackers from manipulating the output of search results or other interactive components. This can be achieved by using a combination of CSP and content security policy mechanisms.
* Regularly Update and Patch AI-Powered Enterprise Assistants: Regular updates and patches for AI-powered enterprise assistants, such as Copilot, should be implemented to ensure that known vulnerabilities are addressed promptly. Microsoft should also provide clear instructions on how users can update their software to prevent exploitation of these vulnerabilities.
* Monitor User Activity and Report Suspicious Behavior: Implement a monitoring system to detect suspicious behavior in user activity, such as search queries or file access patterns. If any unusual activity is detected, the system should report it to Microsoft's security team for further investigation and potential patching.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
sn•••••.org
ha•••••.com
at•••••.com
ht•••••.sys
hxxp://••••••••••••••••••••
im•••••.png
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
PandoraPandoraShai-HuludShai-Hulud
CVE-2026-45472CVE-2026-45472
CVE-2026-45481CVE-2026-45481
CVE-2026-42992CVE-2026-42992
CVE-2026-45463CVE-2026-45463
CVE-2026-48579CVE-2026-48579
CVE-2026-44801CVE-2026-44801
CVE-2026-47652CVE-2026-47652
CVE-2026-45586CVE-2026-45586
CVE-2026-45460CVE-2026-45460
CVE-2026-42989CVE-2026-42989
CVE-2026-45658CVE-2026-45658
CVE-2026-44810CVE-2026-44810
CVE-2026-44803CVE-2026-44803
CVE-2026-47655CVE-2026-47655
CVE-2026-41615CVE-2026-41615
CVE-2026-26142CVE-2026-26142
CVE-2026-47289CVE-2026-47289
CVE-2026-45458CVE-2026-45458
CVE-2026-45607CVE-2026-45607
CVE-2026-47291CVE-2026-47291
CVE-2026-45461CVE-2026-45461
CVE-2026-32193CVE-2026-32193
CVE-2026-48574CVE-2026-48574
CVE-2026-42986CVE-2026-42986
CVE-2026-47635CVE-2026-47635
CVE-2026-45497CVE-2026-45497
CVE-2026-49160CVE-2026-49160
CVE-2026-48563CVE-2026-48563
CVE-2026-44799CVE-2026-44799
CVE-2026-44815CVE-2026-44815
CVE-2026-47634CVE-2026-47634
CVE-2026-42985CVE-2026-42985
CVE-2026-45476CVE-2026-45476
CVE-2026-42980CVE-2026-42980
CVE-2026-42987CVE-2026-42987
CVE-2026-41089CVE-2026-41089
CVE-2026-47654CVE-2026-47654
CVE-2026-42905CVE-2026-42905
CVE-2026-44812CVE-2026-44812
CVE-2026-45641CVE-2026-45641
CVE-2026-47644CVE-2026-47644
CVE-2026-33828CVE-2026-33828
CVE-2026-47288CVE-2026-47288
CVE-2026-50507CVE-2026-50507
CVE-2026-45456CVE-2026-45456
CVE-2026-45648CVE-2026-45648
CVE-2026-48567CVE-2026-48567
CVE-2026-42824CVE-2026-42824
CVE-2026-45474CVE-2026-45474
CVE-2026-45657CVE-2026-45657
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
healthhealth
Incident Timeline
October 2003
Threat actors exploited multiple vulnerabilities and zero-day exploits to target Microsoft systems during the June 2026 Patch Tuesday.
2026/05/10
Microsoft received heavy blowback on social media after announcing it was considering taking legal action against Nightmare Eclipse, a security researcher who had released an exploit for the Windows BitLocker vulnerability CVE-2026-50507.
Click on any entity below to view its context and source!
industry
Media
Microsoft received heavy blowback on social media last month after it said in
a blog post
that it was considering taking legal action against the security researcher.
Microsoft received heavily blowback on social media last month after it said in
a blog post
that it was considering taking legal action against the security researcher.
industry
Legal
Microsoft received heavy blowback on social media last month after it said in
a blog post
that it was considering taking legal action against the security researcher.
Microsoft received heavily blowback on social media last month after it said in
a blog post
that it was considering taking legal action against the security researcher.
infrastructure
Windows
Nightmare Eclipse also last month released “YellowKey,” an exploit for a Windows BitLocker vulnerability that allows an attacker with physical access to view encrypted data, and
CVE-2026-50507
is a patch for an elevation of privilege bug in BitLocker.
vulnerability
CVE-2026-50507
Nightmare Eclipse also last month released “YellowKey,” an exploit for a Windows BitLocker vulnerability that allows an attacker with physical access to view encrypted data, and
CVE-2026-50507
is a patch for an elevation of privilege bug in BitLocker.
organisation
YellowKey
Nightmare Eclipse also last month released “YellowKey,” an exploit for a Windows BitLocker vulnerability that allows an attacker with physical access to view encrypted data, and
CVE-2026-50507
is a patch for an elevation of privilege bug in BitLocker.
organisation
BitLocker
Nightmare Eclipse also last month released “YellowKey,” an exploit for a Windows BitLocker vulnerability that allows an attacker with physical access to view encrypted data, and
CVE-2026-50507
is a patch for an elevation of privilege bug in BitLocker.
2026/06/02
Shai-Hulud infected Microsoft's public code repositories.
Click on any entity below to view its context and source!
malware
Shai-Hulud
Microsoft battled its own internal zero-day emergencies last week, after at least 72 of the company’s public code repositories were infected with
a variant of the Shai-Hulud worm
.
general_metric
72 week
Microsoft battled its own internal zero-day emergencies last week, after at least 72 of the company’s public code repositories were infected with
a variant of the Shai-Hulud worm
.
June 3
Google resolved a whopping 429 vulnerabilities in its latest Chrome browser update on June 3.
Click on any entity below to view its context and source!
general_metric
429 whopping vulnerabilities
On June 3,
Google
resolved
a whopping 429 vulnerabilities
in its latest
Chrome
browser update (Chrome automatically downloads updates but installing them usually requires a complete restart of the browser).
2026/06/09
One researcher published an exploit for a zero-day bug in Windows Defender after Microsoft released software updates to patch nearly 200 security holes across its Windows operating systems.
Click on any entity below to view its context and source!
organisation
Microsoft
Microsoft
today released software updates to plug nearly 200 security holes across its
Windows
operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.
infrastructure
Windows
Microsoft
today released software updates to plug nearly 200 security holes across its
Windows
operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.
One of those, dubbed “GreenPlasma,” leverages an elevation of privilege weakness in the Windows Collaborative Translation Framework, the same framework patched today in
CVE-2026-45586
.
Immediately following the release of Microsoft patches today, the researcher
published an exploit
for what they claimed was a zero-day bug in Windows Defender.
general_metric
200 security holes
Microsoft
today released software updates to plug nearly 200 security holes across its
Windows
operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.
vulnerability
CVE-2026-45586
One of those, dubbed “GreenPlasma,” leverages an elevation of privilege weakness in the Windows Collaborative Translation Framework, the same framework patched today in
CVE-2026-45586
.
organisation
GreenPlasma
One of those, dubbed “GreenPlasma,” leverages an elevation of privilege weakness in the Windows Collaborative Translation Framework, the same framework patched today in
CVE-2026-45586
.
organisation
the Windows Collaborative Translation Framework
One of those, dubbed “GreenPlasma,” leverages an elevation of privilege weakness in the Windows Collaborative Translation Framework, the same framework patched today in
CVE-2026-45586
.
2026/06/10
Threat actors exploited a previously unknown vulnerability in Microsoft's June 2026 Patch Tuesday updates to gain unauthorized access.
2026/06/15
Microsoft released patches on June 15, 2026, to fix multiple vulnerabilities including a zero-day flaw.
2022/2025
Threat actors exploited a use-after-free condition in the Windows 11 and Server 2022/2025 operating systems to target devices running T1584.004, specifically Windows 11.
Click on any entity below to view its context and source!
infrastructure
Windows
It is a use-after-free condition (a memory glitch involving a program accessing data from a deleted slot) that basically lets attackers use specialised network traffic to hack x64 and ARM64 devices/systems running Windows 11 and Windows Server 2022/2025.
tactic
T1584.004 - Server
It is a use-after-free condition (a memory glitch involving a program accessing data from a deleted slot) that basically lets attackers use specialised network traffic to hack x64 and ARM64 devices/systems running Windows 11 and Windows Server 2022/2025.
general_metric
11 Windows
It is a use-after-free condition (a memory glitch involving a program accessing data from a deleted slot) that basically lets attackers use specialised network traffic to hack x64 and ARM64 devices/systems running Windows 11 and Windows Server 2022/2025.
2012-2025
Threat actors exploited a memory bug in Windows Server 2012-2025 to execute code on affected systems by sending malformed network packets.
Click on any entity below to view its context and source!
infrastructure
Windows
tactic
T1584.004 - Server
general_metric
10 Windows
By sending a malformed network packet (a corrupted data package), hackers can execute code on Windows 10, 11, and Windows Server (2012-2025) systems using large traffic limits.
2026/06/15
Microsoft released June's Patch Tuesday updates, addressing 73 critical vulnerabilities across various software applications and services.
Click on any entity below to view its context and source!
infrastructure
Microsoft 365
The link itself opens Microsoft 365 Copilot Search, and is structured so that whatever prompt is behind the "q" parameter, the search accepts (structured as "
The attacker can use this link structure as an opening to craft a malicious prompt that the victim's
Enterprise Copilot
interprets and responds to.
"
Related:
Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover
"That said," Yardeni continues, "organizations also have a role: minimizing unnecessary data exposure and treating AI systems as part of their attack surface rather than a trusted abstraction."
organisation
Microsoft 365 Copilot Search
The link itself opens Microsoft 365 Copilot Search, and is structured so that whatever prompt is behind the "q" parameter, the search accepts (structured as "
The attacker can use this link structure as an opening to craft a malicious prompt that the victim's
Enterprise Copilot
interprets and responds to.
organisation
CVSS
New Spin on Shai-Hulud
SearchLeak: No Immediate User Action Required
Microsoft patched the SearchLeak vulnerability, which it tracks as CVE-2026-42824 and labeled critical (although its
CVSS
score is 6.5).
organisation
Azure Durable Task SDK
Researchers found that all of the affected packages were connected to Microsoft official Azure Durable Task SDK, which got
hit by the same Shai-Hulud worm
in May.
organisation
Microsoft Copilot
A novel
Microsoft Copilot attack
that researchers dubbed "SearchLeak" would have enabled an attacker to silently exfiltrate user files, including emails, meeting notes, OneDrive files, SharePoint documents, and other business files the user has access to.
organisation
OneDrive
A novel
Microsoft Copilot attack
that researchers dubbed "SearchLeak" would have enabled an attacker to silently exfiltrate user files, including emails, meeting notes, OneDrive files, SharePoint documents, and other business files the user has access to.
organisation
SharePoint
A novel
Microsoft Copilot attack
that researchers dubbed "SearchLeak" would have enabled an attacker to silently exfiltrate user files, including emails, meeting notes, OneDrive files, SharePoint documents, and other business files the user has access to.
organisation
Slack
The attack works like this: the threat actor sends the victim a Copilot link through any channel, such as email or Slack.
organisation
Copilot
The attacker instructions tell the Copilot to perform a task like a search for a specific email received (such as a multifactor authentication code) and put requested information into a URL that sends the information to an attacker-controlled server.
Collectively, the
update
issues patches for bugs found inside a wide range of software, most notably being Windows Media, NTFS, Hyper-V, BitLocker, Bluetooth drivers, Boot Manager, Copilot, and Exchange Server, among others.
infrastructure
Windows
Collectively, the
update
issues patches for bugs found inside a wide range of software, most notably being Windows Media, NTFS, Hyper-V, BitLocker, Bluetooth drivers, Boot Manager, Copilot, and Exchange Server, among others.
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
CVE-2026-48574
is a critical Remote Code Execution vulnerability in Windows Media due to Heap-based buffer overflow which allows an unauthorized attacker to execute the malicious code locally.
CVE-2026-33828
is a critical Elevation of Privilege Vulnerability in Windows Device Health Attestation (DHA).
Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"
CVE-2026-42905
: Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42980
: NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-42986
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-42989
: Winlogon Elevation of Privilege Vulnerability
CVE-2026-45481
: Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45586
: Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
CVE-2026-45658
and
CVE-2026-50507:
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-47634
: Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-49160
: Windows HTTP Protocol Stack (http.sys) Denial of Service Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
CVE-2026-47291
is a critical Remote Code Execution Vulnerability due to Integer overflow or wraparound in Windows HTTP Protocol Stack (http.sys).
CVE-2026-44803
and
CVE-2026-44812
are critical Remote Code Execution Vulnerability in the Windows Graphics component.
This vulnerability is due to Integer overflow or wraparound in Windows Win32K – GRFX subsystem (graphics component).
Talos highlights 23 critical vulnerabilities as Microsoft has determined that their exploitation is “less likely:”
CVE-2026-42992
,
CVE-2026-44799
,
CVE-2026-44801
,
CVE-2026-47289
and
CVE-2026-48563
are critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Windows Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-45607
,
CVE-2026-45641
and
CVE-2026-47652
are critical Remote Code Execution vulnerabilities in Windows Hyper-V that arise from Out-of-bounds reads, which enable an unauthorized attacker to execute code locally.
CVE-2026-45657
is a critical use after free vulnerability in Windows Kernel which allows an unauthorized attacker to execute malicious code over a network.
An attacker could exploit this vulnerability by sending specially crafted network traffic to a vulnerable Windows system.
With the successful exploitation attempt, the malicious network packets could trigger a flaw in how the Windows kernel processes certain TCP/IP data, potentially allowing the attacker to run code with system-level privileges without needing to sign in or interact with a user.
CVE-2026-42987
is a critical Remote Code Execution vulnerability in Windows Deployment Services (WDS).
This vulnerability is due to the use after free flaw in Windows Deployment Services and an unauthorized attacker, exploiting this vulnerability, can execute malicious code over a network.
CVE-2026-44815
is a critical Remote Code Execution vulnerability due to the Stack-based buffer overflow in Windows DHCP Client which allows an unauthorized attacker to execute code over a network.
CVE-2026-44810
is a critical Improper authentication flaw in Windows Cryptographic Services, when exploited, allows an unauthorized attacker to elevate privileges locally.
CVE-2026-45648
is a critical Remote Code Execution Vulnerability in Windows Active Directory Domain services due to a Stack-based buffer overflow flaw in Active Directory Domain services.
CVE-2026-47288
is a critical Remote Code Execution Vulnerability in Windows Kerberos Key Distribution Center (KDC) due to the Integer overflow or wraparound in Windows Kerberos, when exploited, allows an authorized attacker to execute malicious code over an adjacent network.
This vulnerability is due to the trust boundary violation in Windows Attestation which when exploited, allows an authorized attacker to elevate privileges locally.
Two of the zero-days addressed this month appear to stem from recent vulnerability disclosures by
Nightmare Eclipse
, the nickname chosen by a security researcher who has been dropping exploits for various Windows flaws.
The company introduced the monthly update schedule after the Blaster worm caused disruption in the early days of Windows.
How to apply patches and check if you’re protected
These updates fix security problems and keep your Windows PC protected.
Open
Settings
Click the
Start
button (the Windows logo at the bottom left of your screen).
Windows will search for the latest Patch Tuesday updates.
5. Double-check you’re up to date
After restarting, go back to
Windows Update
and check again.
This flaw in Windows BitLocker is tracked as
CVE-2026-50507
(
CVSS score
: 6.8 out of 10) and its description states:
“a protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.”
BitLocker is a built-in Windows security feature that encrypts your entire hard drive, securing your data from unauthorized access if your device is lost or stolen.
The third to discuss is
CVE-2026-45586
(CVSS score: 7.8 out of 10) in the Windows Collaborative Translation Framework (CTFMON).
CVE-2026-45586
is a privilege escalation vulnerability in the Windows CTFMON service that local attackers can exploit to obtain system-level administrator rights.
Included in these flaws is
CVE-2026-49160
, a denial-of-service DoS vulnerability inside HTTP.sys that allows attackers to remotely crash targeted Windows servers by sending custom web requests.
Third is
CVE-2026-50507
, a security feature bypass flaw allowing a physical attacker to circumvent Windows BitLocker drive encryption.
Core Windows Kernel Flaws (CVSS 9.8)
Several exploitable core operating system bugs were fixed that could’ve let hackers infiltrate systems without using any passwords, including
CVE-2026-45657
.
Web and Network Stack Issues (CVSS 9.8)
CVE-2026-47291
impacts HTTP.sys, which handles incoming web traffic on Windows PCs.
Identity Control and Server Automation (CVSS 9.8)
Identity and network configuration systems face major threats this month, especially
CVE-2026-41089
, which is a stack-based buffer overflow issue (memory overload that releases data outside its boundaries) found within Windows domain controllers.
Another bug, tracked as
CVE-2026-44815
, causes a memory overflow in which the system processes malicious traffic sent to its automatic internet setup service to target enterprise networks running Windows 10.
These allow attackers to run code if a user previews or opens an infected file in Windows File Explorer or Android Office apps.
While the vulnerability does not expose data or allow code execution, it can disrupt services that depend on affected Windows systems.
On the privilege elevation threat (CVE-2026-45586), Alex Vovk, CEO and Co-Founder of Action1, stated that, “This elevation of privilege vulnerability in Windows Collaborative Translation Framework, also known as CTFMON, could allow a local authenticated attacker to gain SYSTEM privileges.
A low-privilege foothold can become full system control when Windows follows the wrong link at the wrong time.”
organisation
BitLocker
Collectively, the
update
issues patches for bugs found inside a wide range of software, most notably being Windows Media, NTFS, Hyper-V, BitLocker, Bluetooth drivers, Boot Manager, Copilot, and Exchange Server, among others.
BitLocker is a built-in Windows security feature that encrypts your entire hard drive, securing your data from unauthorized access if your device is lost or stolen.
organisation
NTFS
Collectively, the
update
issues patches for bugs found inside a wide range of software, most notably being Windows Media, NTFS, Hyper-V, BitLocker, Bluetooth drivers, Boot Manager, Copilot, and Exchange Server, among others.
organisation
Miasma Supply Chain Worm Burrows Into
Related:
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
Skipping Past Copilot Guardrails
Varonis found that while guardrails would prevent certain versions of this attack, the attacker could put the attacker-controlled server link in an image tag that exists on the back of a Bing search-by-image link.
organisation
Microsoft Repositories
Related:
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
Skipping Past Copilot Guardrails
Varonis found that while guardrails would prevent certain versions of this attack, the attacker could put the attacker-controlled server link in an image tag that exists on the back of a Bing search-by-image link.
infrastructure
73 Skipping Guardrails Varonis
Related:
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
Skipping Past Copilot Guardrails
Varonis found that while guardrails would prevent certain versions of this attack, the attacker could put the attacker-controlled server link in an image tag that exists on the back of a Bing search-by-image link.
organisation
TITLE
replace $TITLE in $me=<img src="
This works for two reasons.
organisation
Microsoft
One, the image tag enables a race condition which triggers the
AI
response before Microsoft is able to sanitize the prompt.
Microsoft’s biggest-ever Patch Tuesday fixes 206 bugs, including 3 zero-days.
organisation
CSP
The browser's CSP [Content Security Policy]?
organisation
Content Security
The browser's CSP [Content Security Policy]?
organisation
Varonis
That said, Dor Yardeni, director of security research at Varonis, tells Dark Reading that SearchLeak is more than a single issue in a single AI application.
organisation
SearchLeak
That said, Dor Yardeni, director of security research at Varonis, tells Dark Reading that SearchLeak is more than a single issue in a single AI application.
organisation
Remote Desktop Client
Talos highlights 4 critical vulnerabilities as Microsoft has determined that their exploitation is “more likely:”
CVE-2026-42985
is a critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Remote Desktop Client which allows an unauthorized attacker to execute code over a network.
organisation
Microsoft Office
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
CVE-2026-45456
,
CVE-2026-45458
, and
CVE-2026-47635
are critical Remote Code Execution vulnerabilities in Microsoft Outlook and Word, caused by the access of resources using an incompatible type ('type confusion') in Microsoft Office.
CVE-2026-45461
,
CVE-2026-45463
,
CVE-2026-45472
and
CVE-2026-45474
are critical Use after free flaw in Microsoft office when exploited, allows an unauthorized attacker to execute malicious code locally.
CVE-2026-45460
is a critical Information disclosure vulnerability in Microsoft Office due to a buffer over-read flaw which when exploited allows an unauthorized attacker to disclose information locally.
organisation
Microsoft Windows
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
Windows Active Directory
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
Windows Kerberos Key Distribution Centre
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
KDC
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
Windows Graphics
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
Windows Remote Desktop
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
Windows Deployment Services
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
WDS
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
DHCP Client
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
Azure Kubernetes Service
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
AKS
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
Microsoft Outlook
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
Microsoft SQL
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
organisation
Elevation of Privilege Vulnerability
CVE-2026-33828
is a critical Elevation of Privilege Vulnerability in Windows Device Health Attestation (DHA).
organisation
DHA
CVE-2026-33828
is a critical Elevation of Privilege Vulnerability in Windows Device Health Attestation (DHA).
organisation
Windows Collaborative Translation Framework
Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"
CVE-2026-42905
: Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42980
: NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-42986
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-42989
: Winlogon Elevation of Privilege Vulnerability
CVE-2026-45481
: Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45586
: Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
CVE-2026-45658
and
CVE-2026-50507:
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-47634
: Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-49160
: Windows HTTP Protocol Stack (http.sys) Denial of Service Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
On the privilege elevation threat (CVE-2026-45586), Alex Vovk, CEO and Co-Founder of Action1, stated that, “This elevation of privilege vulnerability in Windows Collaborative Translation Framework, also known as CTFMON, could allow a local authenticated attacker to gain SYSTEM privileges.
organisation
CTFMON
Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"
CVE-2026-42905
: Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42980
: NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-42986
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-42989
: Winlogon Elevation of Privilege Vulnerability
CVE-2026-45481
: Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45586
: Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
CVE-2026-45658
and
CVE-2026-50507:
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-47634
: Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-49160
: Windows HTTP Protocol Stack (http.sys) Denial of Service Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
The third to discuss is
CVE-2026-45586
(CVSS score: 7.8 out of 10) in the Windows Collaborative Translation Framework (CTFMON).
On the privilege elevation threat (CVE-2026-45586), Alex Vovk, CEO and Co-Founder of Action1, stated that, “This elevation of privilege vulnerability in Windows Collaborative Translation Framework, also known as CTFMON, could allow a local authenticated attacker to gain SYSTEM privileges.
organisation
CVE-2026
CVE-2026-44803
and
CVE-2026-44812
are critical Remote Code Execution Vulnerability in the Windows Graphics component.
“Pandora’s proverbial box has been opened, and as more advanced AI models become available, we expect the norm to continue upward across the board, not just for Patch Tuesday.”
June’s zero-day bugs include
CVE-2026-49160
, a denial of service vulnerability affecting a range of web servers, including Microsoft
Internet Information Services
(IIS).
Mobile Authentication Exploits (CVSS 9.6)
Smartphones are also a target for data theft with
CVE-2026-41615
, as it leaks sign-in access tokens on Android and iOS, because of which attackers can send fake requests to steal work credentials if a user taps approve.
organisation
the Windows Graphics
CVE-2026-44803
and
CVE-2026-44812
are critical Remote Code Execution Vulnerability in the Windows Graphics component.
organisation
Integer
This vulnerability is due to Integer overflow or wraparound in Windows Win32K – GRFX subsystem (graphics component).
organisation
Windows Remote Desktop Client
Talos highlights 23 critical vulnerabilities as Microsoft has determined that their exploitation is “less likely:”
CVE-2026-42992
,
CVE-2026-44799
,
CVE-2026-44801
,
CVE-2026-47289
and
CVE-2026-48563
are critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Windows Remote Desktop Client allows an unauthorized attacker to execute code over a network.
organisation
TCP
With the successful exploitation attempt, the malicious network packets could trigger a flaw in how the Windows kernel processes certain TCP/IP data, potentially allowing the attacker to run code with system-level privileges without needing to sign in or interact with a user.
organisation
IP
With the successful exploitation attempt, the malicious network packets could trigger a flaw in how the Windows kernel processes certain TCP/IP data, potentially allowing the attacker to run code with system-level privileges without needing to sign in or interact with a user.
organisation
Windows DHCP Client
CVE-2026-44815
is a critical Remote Code Execution vulnerability due to the Stack-based buffer overflow in Windows DHCP Client which allows an unauthorized attacker to execute code over a network.
organisation
Windows Cryptographic Services
CVE-2026-44810
is a critical Improper authentication flaw in Windows Cryptographic Services, when exploited, allows an unauthorized attacker to elevate privileges locally.
organisation
Stack
CVE-2026-45648
is a critical Remote Code Execution Vulnerability in Windows Active Directory Domain services due to a Stack-based buffer overflow flaw in Active Directory Domain services.
organisation
Nightmare
Two of the zero-days addressed this month appear to stem from recent vulnerability disclosures by
Nightmare Eclipse
, the nickname chosen by a security researcher who has been dropping exploits for various Windows flaws.
organisation
Windows Update
5. Double-check you’re up to date
After restarting, go back to
Windows Update
and check again.
organisation
the Windows Collaborative Translation Framework
The third to discuss is
CVE-2026-45586
(CVSS score: 7.8 out of 10) in the Windows Collaborative Translation Framework (CTFMON).
organisation
DoS
Included in these flaws is
CVE-2026-49160
, a denial-of-service DoS vulnerability inside HTTP.sys that allows attackers to remotely crash targeted Windows servers by sending custom web requests.
infrastructure
9.8
Core Windows Kernel Flaws (CVSS 9.8)
Several exploitable core operating system bugs were fixed that could’ve let hackers infiltrate systems without using any passwords, including
CVE-2026-45657
.
Identity Control and Server Automation (CVSS 9.8)
Identity and network configuration systems face major threats this month, especially
CVE-2026-41089
, which is a stack-based buffer overflow issue (memory overload that releases data outside its boundaries) found within Windows domain controllers.
Healthcare Software Threats (CVSS 9.8)
Hospitals face a direct threat from
CVE-2026-26142
, a deserialization bug where an application incorrectly decodes raw data and runs hidden commands.
organisation
Core Windows Kernel Flaws
Core Windows Kernel Flaws (CVSS 9.8)
Several exploitable core operating system bugs were fixed that could’ve let hackers infiltrate systems without using any passwords, including
CVE-2026-45657
.
organisation
HTTP.sys
Web and Network Stack Issues (CVSS 9.8)
CVE-2026-47291
impacts HTTP.sys, which handles incoming web traffic on Windows PCs.
organisation
Identity Control
Identity Control and Server Automation (CVSS 9.8)
Identity and network configuration systems face major threats this month, especially
CVE-2026-41089
, which is a stack-based buffer overflow issue (memory overload that releases data outside its boundaries) found within Windows domain controllers.
organisation
Identity
Identity Control and Server Automation (CVSS 9.8)
Identity and network configuration systems face major threats this month, especially
CVE-2026-41089
, which is a stack-based buffer overflow issue (memory overload that releases data outside its boundaries) found within Windows domain controllers.
infrastructure
Android
These allow attackers to run code if a user previews or opens an infected file in Windows File Explorer or Android Office apps.
Mobile Authentication Exploits (CVSS 9.6)
Smartphones are also a target for data theft with
CVE-2026-41615
, as it leaks sign-in access tokens on Android and iOS, because of which attackers can send fake requests to steal work credentials if a user taps approve.
organisation
Windows File Explorer
These allow attackers to run code if a user previews or opens an infected file in Windows File Explorer or Android Office apps.
organisation
Android Office
These allow attackers to run code if a user previews or opens an infected file in Windows File Explorer or Android Office apps.
organisation
Powerscribe
CVE-2026-26142
is a remote code execution vulnerability due to deserialization of untrusted data in Nuance Powerscribe.
It lets network attackers execute code inside medical dictation tools like PowerScribe 360 and PowerScribe One.
organisation
Heap
CVE-2026-47654
is a critical Remote Code Execution Vulnerability in Remote Desktop Client due to the Heap-based buffer overflow flaw which when exploited allows an unauthorized attacker to execute malicious code over a network.
organisation
Co-Founder of Action1
On the high-priority network risk targeting web infrastructure (CVE-2026-49160), Mike Walters, President and Co-Founder of Action1, explained that “An uncontrolled resource consumption vulnerability in HTTP.sys could allow an unauthenticated attacker to cause a denial of service over the network.
organisation
DHCP
An authenticated user could exploit this vulnerability by sending specially crafted network traffic to a server configured for use as a Dynamic Host Configuration Protocol (DHCP) Server.
organisation
File Explorer and Desktop Preview Flaws
File Explorer and Desktop Preview Flaws (CVSS 7.8)
Desktops can be compromised from everyday file viewing because of
CVE-2026-44812
and
CVE-2026-44803
.
organisation
Desktops
File Explorer and Desktop Preview Flaws (CVSS 7.8)
Desktops can be compromised from everyday file viewing because of
CVE-2026-44812
and
CVE-2026-44803
.
infrastructure
Ios
Mobile Authentication Exploits (CVSS 9.6)
Smartphones are also a target for data theft with
CVE-2026-41615
, as it leaks sign-in access tokens on Android and iOS, because of which attackers can send fake requests to steal work credentials if a user taps approve.
organisation
Mobile Authentication
Mobile Authentication Exploits (CVSS 9.6)
Smartphones are also a target for data theft with
CVE-2026-41615
, as it leaks sign-in access tokens on Android and iOS, because of which attackers can send fake requests to steal work credentials if a user taps approve.
organisation
Microsoft Azure Network Adapter
CVE-2026-45476
is a critical Elevation of Privilege vulnerability in Microsoft Azure Network Adapter.
infrastructure
Linux
The vulnerability is due to use after free flaw in Linux MANA Driver.
organisation
Copilot Chat
CVE-2026-47644
is a critical information disclosure vulnerability due to the Improper neutralization of special elements in output used by a downstream component('injection') in Copilot Chat (Microsoft Edge).
organisation
Microsoft Edge
CVE-2026-47644
is a critical information disclosure vulnerability due to the Improper neutralization of special elements in output used by a downstream component('injection') in Copilot Chat (Microsoft Edge).
organisation
Microsoft Exchange Online
CVE-2026-48579
is a critical information disclosure vulnerability in Microsoft Exchange Online caused by improper authorization.
organisation
Microsoft Graph
CVE-2026-47655
is a critical information disclosure vulnerability in Microsoft Graph that allows an authorized attacker to expose sensitive information to an unauthorized actor over a network.
organisation
Network
Microsoft states that this vulnerability can be exploited by an attacker who can run an untrusted container configured with host Network could send specially crafted requests to a host level service that was not intended for unauthenticated access.
organisation
Cisco Security Firewall
Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU.
organisation
SRU
Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU.
organisation
Snort 3
The following Snort 3 rules are also available: 301523-301525, 301527-301529, 301531, 301532.
organisation
Patch Tuesday
While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s
Adam Barnett
.
infrastructure
Visual Studio Code
Microsoft also patched a zero-day vulnerability in
Visual Studio Code
that allows attackers to steal GitHub tokens with a single click.
organisation
OpenAI’s
Microsoft says the flaw was reported by OpenAI’s Codex.
organisation
the Security Update Guide
Indeed, the vast, and presumably sustained, uptick in the number of browser vulnerabilities has led to Microsoft no longer enumerating Chromium CVEs in the Security Update Guide.”
organisation
Redmond
The researcher said they opted not to work with Microsoft because of a recent experience wherein Redmond silently patched a flaw they reported without offering credit or recognition.
organisation
Microsoft’s Security Update Guide
Action1
Further reading:
Microsoft’s Security Update Guide
Action1’s Patch Tuesday breakdown
SANS Internet Storm Center notes on Patch Tuesday
organisation
Storm Center
Further reading:
Microsoft’s Security Update Guide
Action1’s Patch Tuesday breakdown
SANS Internet Storm Center notes on Patch Tuesday
organisation
Restart
In which case you may see a
Restart required
message.
organisation
BitLocker Device Encryption
However, this vulnerability could allow an attacker with physical access to bypass BitLocker Device Encryption and gain access to encrypted data.
infrastructure
4 Download
4.
Download and install
If updates are found, they’ll start downloading automatically.
organisation
Remote Work Risks
Remote Work Risks (CVSS 8.8)
organisation
Hackread.com
What to Do
Autonomous patch management experts at Action1 shared a detailed analysis of Microsoft’s Patch Tuesday with Hackread.com, complete with crucial tips for administrators to stay safe, which is available
here
.
organisation
Vulnerability Research
The unusually high volume reflects a broader shift in vulnerability research, as AI-assisted analysis and initiatives like Mythos enable researchers to identify security flaws faster than ever,” said Jack Bicer, Director of Vulnerability Research at Action1
“With three zero-days already being exploited in the wild, this month’s updates should be treated as a priority, and IT teams should move quickly to assess their exposure and deploy patches across affected systems,” Jack advised.
June 2026
Microsoft released a Patch Tuesday update for June 2026, which fixed 206 security vulnerabilities in various products.
Click on any entity below to view its context and source!
organisation
Microsoft
Microsoft has released its monthly security update for June 2026, which includes 206 vulnerabilities affecting a range of products, including 32 that Microsoft marked as “critical”.
Microsoft June 2026 Patch Tuesday Fixes 206 Flaws and 3 Zero-Days.
general_metric
206 vulnerabilities
Microsoft has released its monthly security update for June 2026, which includes 206 vulnerabilities affecting a range of products, including 32 that Microsoft marked as “critical”.
Microsoft June 2026 Patch Tuesday Fixes 206 Flaws and 3 Zero-Days.
Microsoft’s June 2026
Patch Tuesday
update is here, and this time it is massive, with fixes released for a whopping 206 security bugs.
general_metric
32 products
Microsoft has released its monthly security update for June 2026, which includes 206 vulnerabilities affecting a range of products, including 32 that Microsoft marked as “critical”.
general_metric
3 Snort
Microsoft June 2026 Patch Tuesday Fixes 206 Flaws and 3 Zero-Days.
organisation
Fixes 206 Flaws
Microsoft June 2026 Patch Tuesday Fixes 206 Flaws and 3 Zero-Days.
Tuesday for June 2026
Microsoft released a large number of security patches on June 2026, including fixes for multiple known vulnerabilities and zero-day exploits.
Click on any entity below to view its context and source!
organisation
Microsoft Patch
Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities.
organisation
Snort
Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities.
July 14
Nightmare Eclipse is expected to release a batch of zero-day exploits for Windows on July 14.
Click on any entity below to view its context and source!
infrastructure
Windows
Nightmare Eclipse has pledged to release even more zero-day exploits for Windows in what they called a “bone shattering” drop planned for July 14 (the same day as next month’s Patch Tuesday).
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
The link itself opens Microsoft 365 Copilot Search, and is structured so that whatever prompt is behind the "q" parameter, the search accepts (structured as "
The attacker can use this link structure as an opening to craft a malicious prompt that…
"
Related:
Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover
"That said," Yardeni continues, "organizations also have a role: minimizing unnecessary data exposure and treating AI systems as part of their attack surface rather than…
Metrics
infrastructure
73
Skipping Guardrails Varonis
Related:
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
Skipping Past Copilot Guardrails
Varonis found that while guardrails would prevent certain versions of this attack, the attacker could put the attacker-controlled server link i…
Metrics
infrastructure
Windows
Affected Product
Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows…
CVE-2026-48574
is a critical Remote Code Execution vulnerability in Windows Media due to Heap-based buffer overflow which allows an unauthorized attacker to execute the malicious code locally.
CVE-2026-33828
is a critical Elevation of Privilege Vulnerability in Windows Device Health Attestation (DHA).
…owing "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"
CVE-2026-42905
: Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42980
: NT OS Kernel Elevation of Privilege Vulnerab…
CVE-2026-47291
is a critical Remote Code Execution Vulnerability due to Integer overflow or wraparound in Windows HTTP Protocol Stack (http.sys).
CVE-2026-44803
and
CVE-2026-44812
are critical Remote Code Execution Vulnerability in the Windows Graphics component.
This vulnerability is due to Integer overflow or wraparound in Windows Win32K – GRFX subsystem (graphics component).
…2026-44799
,
CVE-2026-44801
,
CVE-2026-47289
and
CVE-2026-48563
are critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Windows Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-45607
,
CVE-2026-45641
and
CVE-2026-47652
are critical Remote Code Execution vulnerabilities in Windows Hyper-V that arise from Out-of-bounds reads, which enable an unauthorized attacker to execute code locally.
CVE-2026-45657
is a critical use after free vulnerability in Windows Kernel which allows an unauthorized attacker to execute malicious code over a network.
An attacker could exploit this vulnerability by sending specially crafted network traffic to a vulnerable Windows system.
With the successful exploitation attempt, the malicious network packets could trigger a flaw in how the Windows kernel processes certain TCP/IP data, potentially allowing the attacker to run code with system-level privileges without needing to sign…
CVE-2026-42987
is a critical Remote Code Execution vulnerability in Windows Deployment Services (WDS).
This vulnerability is due to the use after free flaw in Windows Deployment Services and an unauthorized attacker, exploiting this vulnerability, can execute malicious code over a network.
CVE-2026-44815
is a critical Remote Code Execution vulnerability due to the Stack-based buffer overflow in Windows DHCP Client which allows an unauthorized attacker to execute code over a network.
CVE-2026-44810
is a critical Improper authentication flaw in Windows Cryptographic Services, when exploited, allows an unauthorized attacker to elevate privileges locally.
CVE-2026-45648
is a critical Remote Code Execution Vulnerability in Windows Active Directory Domain services due to a Stack-based buffer overflow flaw in Active Directory Domain services.
CVE-2026-47288
is a critical Remote Code Execution Vulnerability in Windows Kerberos Key Distribution Center (KDC) due to the Integer overflow or wraparound in Windows Kerberos, when exploited, allows an authorized attacker to execute malicious co…
This vulnerability is due to the trust boundary violation in Windows Attestation which when exploited, allows an authorized attacker to elevate privileges locally.
Microsoft
today released software updates to plug nearly 200 security holes across its
Windows
operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.
Two of the zero-days addressed this month appear to stem from recent vulnerability disclosures by
Nightmare Eclipse
, the nickname chosen by a security researcher who has been dropping exploits for various Windows flaws.
One of those, dubbed “GreenPlasma,” leverages an elevation of privilege weakness in the Windows Collaborative Translation Framework, the same framework patched today in
CVE-2026-45586
.
Nightmare Eclipse also last month released “YellowKey,” an exploit for a Windows BitLocker vulnerability that allows an attacker with physical access to view encrypted data, and
CVE-2026-50507
is a patch for an elevation of privilege bug in BitLo…
Nightmare Eclipse has pledged to release even more zero-day exploits for Windows in what they called a “bone shattering” drop planned for July 14 (the same day as next month’s Patch Tuesday).
Immediately following the release of Microsoft patches today, the researcher
published an exploit
for what they claimed was a zero-day bug in Windows Defender.
The company introduced the monthly update schedule after the Blaster worm caused disruption in the early days of Windows.
How to apply patches and check if you’re protected
These updates fix security problems and keep your Windows PC protected.
Open
Settings
Click the
Start
button (the Windows logo at the bottom left of your screen).
Windows will search for the latest Patch Tuesday updates.
5. Double-check you’re up to date
After restarting, go back to
Windows Update
and check again.
This flaw in Windows BitLocker is tracked as
CVE-2026-50507
(
CVSS score
: 6.8 out of 10) and its description states:
“a protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph…
BitLocker is a built-in Windows security feature that encrypts your entire hard drive, securing your data from unauthorized access if your device is lost or stolen.
The third to discuss is
CVE-2026-45586
(CVSS score: 7.8 out of 10) in the Windows Collaborative Translation Framework (CTFMON).
Collectively, the
update
issues patches for bugs found inside a wide range of software, most notably being Windows Media, NTFS, Hyper-V, BitLocker, Bluetooth drivers, Boot Manager, Copilot, and Exchange Server, among others.
CVE-2026-45586
is a privilege escalation vulnerability in the Windows CTFMON service that local attackers can exploit to obtain system-level administrator rights.
Included in these flaws is
CVE-2026-49160
, a denial-of-service DoS vulnerability inside HTTP.sys that allows attackers to remotely crash targeted Windows servers by sending custom web requests.
Third is
CVE-2026-50507
, a security feature bypass flaw allowing a physical attacker to circumvent Windows BitLocker drive encryption.
Core Windows Kernel Flaws (CVSS 9.8)
Several exploitable core operating system bugs were fixed that could’ve let hackers infiltrate systems without using any passwords, including
CVE-2026-45657
.
…a use-after-free condition (a memory glitch involving a program accessing data from a deleted slot) that basically lets attackers use specialised network traffic to hack x64 and ARM64 devices/systems running Windows 11 and Windows Server 2022/2025.
Web and Network Stack Issues (CVSS 9.8)
CVE-2026-47291
impacts HTTP.sys, which handles incoming web traffic on Windows PCs.
By sending a malformed network packet (a corrupted data package), hackers can execute code on Windows 10, 11, and Windows Server (2012-2025) systems using large traffic limits.
…Identity and network configuration systems face major threats this month, especially
CVE-2026-41089
, which is a stack-based buffer overflow issue (memory overload that releases data outside its boundaries) found within Windows domain controllers.
Another bug, tracked as
CVE-2026-44815
, causes a memory overflow in which the system processes malicious traffic sent to its automatic internet setup service to target enterprise networks running Windows 10.
It is a memory bug impacting the OS installation utility on Windows Server 2012-2025.
These allow attackers to run code if a user previews or opens an infected file in Windows File Explorer or Android Office apps.
While the vulnerability does not expose data or allow code execution, it can disrupt services that depend on affected Windows systems.
…reat (CVE-2026-45586), Alex Vovk, CEO and Co-Founder of Action1, stated that, “This elevation of privilege vulnerability in Windows Collaborative Translation Framework, also known as CTFMON, could allow a local authenticated attacker to gain SYSTEM…
A low-privilege foothold can become full system control when Windows follows the wrong link at the wrong time.”
Metrics
infrastructure
Microsoft Office
Affected Product
…op client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack.
CVE-2026-45456
,
CVE-2026-45458
, and
CVE-2026-47635
are critical Remote Code Execution vulnerabilities in Microsoft Outlook and Word, caused by the access of resources using an incompatible type ('type confusion') in Microsoft Office.
CVE-2026-45461
,
CVE-2026-45463
,
CVE-2026-45472
and
CVE-2026-45474
are critical Use after free flaw in Microsoft office when exploited, allows an unauthorized attacker to execute malicious code locally.
CVE-2026-45460
is a critical Information disclosure vulnerability in Microsoft Office due to a buffer over-read flaw which when exploited allows an unauthorized attacker to disclose information locally.
Metrics
infrastructure
Linux
Affected Product
The vulnerability is due to use after free flaw in Linux MANA Driver.
Metrics
infrastructure
Visual Studio Code
Affected Product
Microsoft also patched a zero-day vulnerability in
Visual Studio Code
that allows attackers to steal GitHub tokens with a single click.
Metrics
infrastructure
4
Download
4.
Download and install
If updates are found, they’ll start downloading automatically.
Metrics
infrastructure
9.8
Software Version
Healthcare Software Threats (CVSS 9.8)
Hospitals face a direct threat from
CVE-2026-26142
, a deserialization bug where an application incorrectly decodes raw data and runs hidden commands.
Core Windows Kernel Flaws (CVSS 9.8)
Several exploitable core operating system bugs were fixed that could’ve let hackers infiltrate systems without using any passwords, including
CVE-2026-45657
.
Identity Control and Server Automation (CVSS 9.8)
Identity and network configuration systems face major threats this month, especially
CVE-2026-41089
, which is a stack-based buffer overflow issue (memory overload that releases data outside its…
Metrics
infrastructure
Android
Affected Product
…tion Exploits (CVSS 9.6)
Smartphones are also a target for data theft with
CVE-2026-41615
, as it leaks sign-in access tokens on Android and iOS, because of which attackers can send fake requests to steal work credentials if a user taps approve.
These allow attackers to run code if a user previews or opens an infected file in Windows File Explorer or Android Office apps.
Metrics
infrastructure
Ios
Affected Product
…tion Exploits (CVSS 9.6)
Smartphones are also a target for data theft with
CVE-2026-41615
, as it leaks sign-in access tokens on Android and iOS, because of which attackers can send fake requests to steal work credentials if a user taps approve.
Intelligence Sources
Dark Reading
2026-06-15
HackRead
2026-06-10
Krebs On Security
2026-06-09
A Record-Breaking Patch Tuesday for June 2026
Krebs On Security
Malware Bytes
2026-06-10
Krebs On Security
2026-06-09
A Record-Breaking Patch Tuesday for June 2026
Krebs On Security
Talos Intelligence
2026-06-09
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
89x
organisation
Identified Entity
Microsoft 365 Copilot Search
entity
50x
vulnerability
Exploited CVE
CVE-2026-42824
cve
15x
timeline
Temporal Reference
2026/06/15
date
7x
infrastructure
Affected Product
Microsoft 365
software
5x
industry
Targeted Sector
Media
sector
5x
tactic
Cyber Operation Type
Remote Code Execution
tactic
5x
vulnerability
CVSS Score
10
score
3x
general metric
Score
6
score
3x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
malware
Malware Payload
Shai-Hulud
tool
2x
general metric
Critical Vulnerabilities
23
critical vulnerabilities
2x
general metric
Vulnerabilities
206
vulnerabilities
2x
general metric
Windows
11
windows
Contextual Telemetry
Context Block
19 METRICS
general metric
Microsoft Copilot Search
365
microsoft copilot search
infrastructure
Skipping Guardrails Varonis
73
skipping guardrails varonis
general metric
Title
4
title
general metric
Critical Entries
28
critical entries
general metric
Nt Os Kernel Elevation
42,986
nt os kernel elevation
general metric
Products
32
products
general metric
Rules
2
rules
general metric
Snort
3
snort
target region
Target Country
United States
country
general metric
Security Holes
200
security holes
general metric
Week
72
week
general metric
Whopping Vulnerabilities
429
whopping vulnerabilities
general metric
%
90
%
general metric
Browser Vulnerabilities
360
browser vulnerabilities
general metric
Cvss Score
7
cvss score
infrastructure
Download
4
download
infrastructure
Software Version
9.8
version
general metric
Critical Important Vulnerabilities
33
critical important vulnerabilities
general metric
Critical
167
critical
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.