Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

200 fixes, six zero-days, late Exchange

3 min read
16:08UTC

Microsoft's June Patch Tuesday fixed roughly 200 vulnerabilities including six zero-days, and finally shipped the overdue Exchange patch 16 days after its federal deadline.

TechnologyDeveloping
Key takeaway

June's 200-fix cycle finally closed the exploited Exchange flaw, 16 days past its federal deadline.

Microsoft patched roughly 200 vulnerabilities on Tuesday 9 June, including six zero-days, and finally shipped the overdue Exchange fix 16 days after its federal deadline 1. Those six zero-days were each under active attack before the patch landed. The month reverses May's quieter 120-CVE run, which carried no exploited zero-days at all and broke a 22-month streak .

Two fixes stand out for the Windows estate. A Kerberos KDC (Key Distribution Centre, the service that issues domain logon tickets) RCE reaches domain authentication, the layer that, once broken, hands an attacker the whole network. And two separate BitLocker disk-encryption bypasses shipped in a single cycle, a pairing that gives an attacker both access to the data and a route to escalate. An actively-exploited Defender privilege flaw, tracked as RoguePlanet at CVSS 9.6, grants SYSTEM-level control 2.

The Exchange resolution closes the cleanest worked example of the patch-gap problem: CVE-2026-42897 sat on the KEV catalogue from 15 May, exploited, with only a stop-gap mitigation and no full fix until now . For administrators who ran the Emergency Mitigation Service workaround in the interim, the calendar mattered, because that mitigation broke OWA print and inline images while it held the line. The fix arrives, but the 16-day overrun is the data point a buyer should keep: even Microsoft, with the largest patch engineering operation in the industry, missed a federal deadline on an exploited flaw by more than two weeks.

Deep Analysis

In plain English

Once a month, Microsoft releases security fixes for Windows, Office, and its server products in what it calls Patch Tuesday. June 2026's release fixed approximately 200 separate security problems, including six that attackers were already using before the fix existed, known as zero-days. Two of the most notable fixes involve BitLocker, the built-in Windows feature that encrypts the data on a laptop or desktop hard drive to protect it if the machine is stolen. Researchers found two separate ways to bypass BitLocker in the same month. Another actively exploited flaw, called RoguePlanet, let an attacker who already had basic access to a Windows machine take full administrative control of it, the kind of access needed to install malware, extract passwords, or spread through a network. Microsoft also finally shipped a fix for an email server flaw that the US government had required agencies to patch by 29 May, arriving 16 days late.

Deep Analysis
Root Causes

The Exchange CVE-2026-42897 patch delay reflects a known constraint in Microsoft's OWA code base: the Exchange on-premises codebase shares components with Exchange Online but runs on customer-managed infrastructure with a heterogeneous version matrix (2016, 2019, Subscription Edition).

Microsoft's patching velocity for on-premises Exchange consistently lags behind Exchange Online remediations because the on-premises fix must be validated across the full version matrix before release. The Exchange Emergency Mitigation Service (EEMS) workaround was deployed as a compensating control, but its URL-rewrite approach broke OWA features (print, inline images, Light mode), reducing operator willingness to apply it.

The two BitLocker bypasses in a single cycle reflect a known weakness in the Secure Boot chain of trust: BitLocker's pre-boot protection depends on the integrity of the boot loader and the Trusted Platform Module sealing. Research into UEFI and bootloader shim bypass techniques has intensified since 2022, and two independent researchers reaching the same BitLocker bypass surface in a single month indicates the attack surface is now well-understood in offensive security research communities.

What could happen next?
  • Risk

    Two independent BitLocker bypasses confirmed in a single Patch Tuesday suggests concentrated offensive research on Windows disk-encryption trust chains; a third bypass in July or August 2026 would confirm a sustained campaign.

    Short term · Reported
  • Consequence

    Exchange CVE-2026-42897 arriving 16 days past its federal deadline documents a vendor compliance gap that CISA may cite when revising BOD 22-01 timelines for on-premises server products.

    Medium term · Reported
  • Risk

    CVE-2026-47288 Kerberos KDC RCE reaching domain authentication enables Active Directory forest-wide lateral movement from a single compromised endpoint; unpatched domain controllers remain at elevated risk until the June 2026 updates are applied.

    Immediate · Assessed
First Reported In

Update #7 · VPN zero-day, no-patch KEV, late Exchange

BleepingComputer· 14 Jun 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.