Microsoft sets a Patch Tuesday record with 206 fixes, and finally patches every zero-day Nightmare Eclipse disclosed

Microsoft's June 2026 Patch Tuesday update fixes 206 vulnerabilities, including all zero-days disclosed by Nightmare Eclipse and one active exploit.

Microsoft sets a Patch Tuesday record with 206 fixes, and finally patches every zero-day Nightmare Eclipse disclosed
Comment IconFacebook IconX IconReddit Icon
Tech Reporter
Published
1 minute & 30 seconds read time
TL;DR: Microsoft's June 2026 Patch Tuesday update fixed a record 206 vulnerabilities, including 33 critical flaws and five zero-days. It addresses all zero-days disclosed by researcher Nightmare Eclipse and patches an actively exploited Elevation of Privilege flaw in Microsoft Defender. AI-assisted discovery contributed to the high patch count.
Voice: Hassam Nasir
0:00 / 2:59
Use left and right arrow keys to seek audio.

Microsoft has released its June 2026 Patch Tuesday update, and it is a record-breaker. The company patched 206 vulnerabilities this month, surpassing the previous record of 175 set in October 2025. Of the 206 vulnerabilities patched, 33 are rated Critical, with 28 of those being remote code execution flaws.

The full breakdown covers 65 Elevation of Privilege vulnerabilities, 55 Remote Code Execution vulnerabilities, 30 Information Disclosure vulnerabilities, 27 Spoofing vulnerabilities, 19 Security Feature Bypass vulnerabilities, and 7 Denial of Service vulnerabilities. Five are zero-day vulnerabilities, and one is already being actively exploited in the wild.

CVE-2026-41091 is an Elevation of Privilege flaw in Microsoft Defender that lets attackers gain system privileges. Microsoft has already pushed out a fix through the daily automatic Defender updates, with the patched Malware Protection Engine carrying version 1.1.26040.8 or later. To check your engine version, open Settings > Privacy and Security > Windows Security > About.

Microsoft sets a Patch Tuesday record with 206 fixes, and finally patches every zero-day Nightmare Eclipse disclosed 2

This month's update also closes out several vulnerabilities tied to security researcher Nightmare Eclipse, who has been publicly disclosing Windows zero-days in protest of Microsoft's bug bounty and disclosure practices.

The patched flaws include GreenPlasma, a Windows CTFMON privilege-escalation exploit, YellowKey, a BitLocker bypass that could grant access to encrypted drives, and MiniPlasma, a privilege-escalation flaw originally reported in 2020 that Nightmare Eclipse claimed was never fully fixed. With this update, all of Nightmare Eclipse's publicly disclosed vulnerabilities have now been patched.

Part of the reason for the record patch count appears to be AI-assisted vulnerability discovery, a trend that shows no signs of slowing. Dustin Childs of TrendAI's Zero Day Initiative added that the number of CVEs Microsoft has shipped this year already exceeds the total for all of 2018.

Photo of the Microsoft AC Adapter
Best Deals: Microsoft AC Adapter
Today7 days ago30 days ago
--
--
--
--
--
--
Check PriceCheck Price
* Prices last scanned 6/10/2026 at 5:40 pm CDT - prices may be inaccurate. As an Amazon Associate, we earn from qualifying purchases. We earn affiliate commission from any Newegg or PCCG sales.

Tech Reporter

Email IconX IconLinkedIn Icon

Hassam is a veteran tech journalist and editor with over eight years of experience embedded in the consumer electronics industry. His obsession with hardware began with childhood experiments involving semiconductors, a curiosity that evolved into a career dedicated to deconstructing the complex silicon that powers our world. From benchmarking PC internals to stress-testing flagship CPUs and GPUs, Hassam specializes in translating high-level engineering into deep, unbiased insights for the enthusiast community.

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News
Newsletter Subscription