Microsoft June 2026 Patch Tuesday — 198+ CVEs Including CVE-2026-49160 (HTTP.sys 'HTTP/2 Bomb' DoS), CVE-2026-50507 (BitLocker 'YellowKey' Bypass) and CVE-2026-45586 (Collaborative Translation Framework EoP) — Threadlinqs Intelligence
As of 2026-06-09, Microsoft June 2026 Patch Tuesday — 198+ CVEs Including CVE-2026-49160 (HTTP.sys 'HTTP/2 Bomb' DoS), CVE-2026-50507 (BitLocker 'YellowKey' Bypass) and CVE-2026-45586 (Collaborative Translation Framework EoP) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0732 · Severity: HIGH · CVSS: 7.8 · Status: ACTIVE · Category: VULNERABILITY
Microsoft's June 2026 Patch Tuesday is the largest on record, addressing roughly 198-200 CVEs (32-33 Critical). Three vulnerabilities were publicly disclosed before a patch was available:
On 9 June 2026 Microsoft shipped its largest Patch Tuesday to date, remediating approximately 198-200 CVEs (sources vary between 198 and 200 depending on counting of Edge/Chromium and republished advisories), of which 32-33 are rated Critical and the remainder Important. The headline items are three vulnerabilities that were publicly disclosed prior to patch availability, each flagged by Microsoft as 'Exploitation More Likely.'
CVE-2026-49160 (HTTP.sys Denial of Service, CVSS 7.5, CWE-400 Uncontrolled Resource Consumption) was disclosed by researchers at the offensive-security firm Calif.io as 'HTTP/2 Bomb.' The technique abuses HTTP/2 header compression (HPACK) and flow-control management: an unauthenticated remote attacker sends a very small volume of crafted data that forces the kernel-mode HTTP.sys driver to allocate disproportionately large amounts of memory, and manipulates flow-control window settings so allocated resources are never released, exhausting memory and taking internet-facing services offline. Because HTTP.sys sits beneath IIS, WinRM, WSL networking and many other Windows services, any HTTP/2- or HTTP/3-exposed endpoint is at risk. Microsoft's fix introduces a new MaxHeadersCount registry value that caps the number of headers accepted in HTTP/2 and HTTP/3 requests (delivered in update KB5102602). No in-the-wild exploitation was confirmed at release.
CVE-2026-50507 (Windows BitLocker Security Feature Bypass, CVSS 6.8, CWE-288/CWE-1299) was disclosed by researcher 'Nightmare Eclipse' as 'YellowKey,' with a proof-of-concept previously released. An attacker with physical access stages specially crafted files on a USB drive or the EFI system partition, boots the device into the Windows Recovery Environment (WinRE), and holds the CTRL key to spawn an unrestricted command shell that grants access to data on BitLocker-protected, TPM-only volumes — defeating the encryption control organizations rely on for lost or stolen devices. Affected configurations include TPM-only BitLocker protection on Windows 11 and Windows Server 2022/2025.
CVE-2026-45586 (Windows Collaborative Translation Framework / CTFMON Elevation of Privilege, CVSS 7.8, CWE-59 Improper Link Resolution Before File Access) lets a local low-privileged attacker abuse a link-following ('link following') weakness in the CTFMON voice/handwriting recognition subsystem to elevate to SYSTEM. It was reported by an anonymous researcher and was known to attackers before patch.
Beyond the zero-days, the release contains a cluster of 11 Remote Desktop Client RCEs (CVE-2026-42909, -42913, -42985, -42992, -42993, -44799, -44801, -47289, -47653, -47654, -48563), 7 of which are Critical, exploiting heap-based buffer overflows triggered when a victim RDP client connects to an attacker-controlled server (CVSS 7.5-8.8; CVE-2026-42985 rated 'Exploitation More Likely'). The overall category breakdown is approximately 54-65 Elevation of Privilege, 54-55 Remote Code Execution, 27 Spoofing, 26-30 Information Disclosure, 18-19 Security Feature Bypass, and 7 Denial of Service across 98+ affected product families including the Windows kernel, Office, Exchange, Teams, Azure, Defender, Hyper-V, RDP, DNS, plus third-party components.
Weaknesses (CWE)
CWE-400, CWE-59, CWE-288, CWE-1299, CWE-122
Target sectors: government, financial, healthcare, technology, hosting, education, energy
Target regions: Global, North America, Europe, Asia
Related threats
- HTTP/2 Bomb — Remote DoS via HPACK Indexed-Reference Compression Bomb + Zero-Window Flow-Control Hold Affecting nginx, Apache httpd, IIS, Envoy & Cloudflare Pingora (CVE-2026-49975, Public PoC)
- F5 Out-of-Band Patches for Critical NGINX HTTP/3 Use-After-Free and Proxy/gRPC Heap Overflow (CVE-2026-42530, CVE-2026-42055) plus NGINX Gateway Fabric Config Injection (CVE-2026-11311, CVE-2026-50107)
- Microsoft's MDASH AI Scanning Harness Uncovers 16 Windows CVEs, Including Four Critical RCE Flaws in TCP/IP, IKEv2, Netlogon, and DNS
- CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2
- CVE-2026-55407: Unbounded Heap Allocation DoS in Anthropic's Buffa Rust Protobuf Library (decode_unknown_field)
- Nginx-poolslip CVE-2026-9256 — Pre-Auth Heap Buffer Overflow in NGINX ngx_http_rewrite_module (Patch Bypass of CVE-2026-42945 'NGINX Rift')
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-49160, CVE-2026-50507, CVE-2026-45586, CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, T1595, T1592, T1588, T1587, T1190, T1200, T1203, T1059, T1068, T1574