Microsoft June 2026 Patch Tuesday fixes record 206 flaws, 6 zero-days
Microsoft released fixes for a record 206 vulnerabilities in June 2026, including six zero-days. One Exchange Server flaw is under active attack. AI tools are driving a surge in discovery.
Microsoft released its largest Patch Tuesday on record June 10, 2026, fixing 206 security vulnerabilities across its product portfolio. The update includes fixes for six zero-day flaws, one of which is actively exploited in attacks against Exchange Server.
Of the 206 flaws, 39 are rated Critical and 167 are rated Important. The breakdown includes 63 privilege escalation bugs, 56 remote code execution flaws, 30 information disclosure issues, 27 spoofing vulnerabilities, and 20 security feature bypass problems. This surpasses the previous record of 167 flaws set in April 2026.
Exchange Server zero-day under active attack
The most urgent vulnerability is CVE-2026-42897, a high-severity spoofing flaw in Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). Microsoft says remote attackers with no privileges can exploit it by sending a specially crafted email. If a user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript executes in the browser context.
Microsoft first detected the attacks in mid-May and rolled out automatic temporary mitigations through the Exchange Emergency Mitigation Service (EEMS). The Cybersecurity and Infrastructure Security Agency added the flaw to its exploited vulnerabilities list on May 15 and ordered U.S. federal agencies to patch within two weeks. Over the past five years, CISA has listed 20 Exchange Server vulnerabilities as exploited, with ransomware gangs using 14 of them.
AI blamed for vulnerability surge
Microsoft security leadership acknowledged last month that artificial intelligence tools are driving a sharp increase in vulnerability discovery across the industry. Dark Reading reported that AI accelerates both the speed and scale of finding flaws, making voluminous patch updates the new normal. CyberScoop noted that fears about a flood of error-riddled software have materialized.
The three publicly disclosed zero-days in this release add urgency. While Microsoft did not name the specific CVEs, the company confirmed that proof-of-concept code or public disclosure existed before the patch. The remaining two zero-days were privately reported and not known to be exploited.
Administrators should prioritize the Exchange Server update and leave the EEMS mitigations in place for additional protection. Microsoft recommends installing the June 2026 Security Updates as soon as possible. With AI-driven discovery accelerating, organizations should expect similarly large Patch Tuesday releases in coming months.
Fact check
-
Microsoft fixed 206 vulnerabilities in June 2026 Patch Tuesday, a record.
verified · source
-
CVE-2026-42897 is an actively exploited Exchange Server zero-day.
verified · source
-
AI tools are driving a surge in vulnerability discovery, according to Microsoft security leadership.
reported · source
-
39 of the 206 flaws are rated Critical.
verified · source
-
CISA added CVE-2026-42897 to its exploited vulnerabilities list on May 15, 2026.
verified · source
Source reporting (10)
- BleepingComputer · Microsoft patches Exchange Server zero-day exploited in attacks
- The Record by Recorded Future · Microsoft ships largest Patch Tuesday on record, with one bug under active attack
- The Hacker News · Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
- CyberScoop · Microsoft breaks Patch Tuesday record with 206 vulnerabilities
- Dark Reading · Blame AI: Patch Tuesday Hits Record 206 CVEs
- BleepingComputer · Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
- The Hacker News · Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
- BleepingComputer · Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
- Krebs on Security · A Record-Breaking Patch Tuesday for June 2026
- The Register · AI is making Patch Tuesday (kinda) fun again
Join the conversation
You need to be registered and logged in to comment on blog articles.
Related Articles
Zoom CISO Defends AI Role, Microsoft Faces Researcher Backlash, and China-Linked Group Targets Czech Republic and Taiwan
Jun 10, 2026
AI Leaders Warn Frontier Models Could Enable Bioweapons, Urge Mandatory DNA Screening
Jun 9, 2026
Over 900 US Fuel Tank Gauge Systems Exposed Online, Under Active Attack
Jun 9, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.