Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

200 fixes, six zero-days, late Exchange

3 min read
12:09UTC

Microsoft's June Patch Tuesday fixed roughly 200 vulnerabilities including six zero-days, and finally shipped the overdue Exchange patch 16 days after its federal deadline.

TechnologyDeveloping
Key takeaway

June's 200-fix cycle finally closed the exploited Exchange flaw, 16 days past its federal deadline.

Microsoft patched roughly 200 vulnerabilities on Tuesday 9 June, including six zero-days, and finally shipped the overdue Exchange fix 16 days after its federal deadline 1. Those six zero-days were each under active attack before the patch landed. The month reverses May's quieter 120-CVE run, which carried no exploited zero-days at all and broke a 22-month streak .

Two fixes stand out for the Windows estate. A Kerberos KDC (Key Distribution Centre, the service that issues domain logon tickets) RCE reaches domain authentication, the layer that, once broken, hands an attacker the whole network. And two separate BitLocker disk-encryption bypasses shipped in a single cycle, a pairing that gives an attacker both access to the data and a route to escalate. An actively-exploited Defender privilege flaw, tracked as RoguePlanet at CVSS 9.6, grants SYSTEM-level control 2.

The Exchange resolution closes the cleanest worked example of the patch-gap problem: CVE-2026-42897 sat on the KEV catalogue from 15 May, exploited, with only a stop-gap mitigation and no full fix until now . For administrators who ran the Emergency Mitigation Service workaround in the interim, the calendar mattered, because that mitigation broke OWA print and inline images while it held the line. The fix arrives, but the 16-day overrun is the data point a buyer should keep: even Microsoft, with the largest patch engineering operation in the industry, missed a federal deadline on an exploited flaw by more than two weeks.

Deep Analysis

In plain English

Once a month, Microsoft releases security fixes for Windows, Office, and its server products in what it calls Patch Tuesday. June 2026's release fixed approximately 200 separate security problems, including six that attackers were already using before the fix existed, known as zero-days. Two of the most notable fixes involve BitLocker, the built-in Windows feature that encrypts the data on a laptop or desktop hard drive to protect it if the machine is stolen. Researchers found two separate ways to bypass BitLocker in the same month. Another actively exploited flaw, called RoguePlanet, let an attacker who already had basic access to a Windows machine take full administrative control of it, the kind of access needed to install malware, extract passwords, or spread through a network. Microsoft also finally shipped a fix for an email server flaw that the US government had required agencies to patch by 29 May, arriving 16 days late.

Deep Analysis
Root Causes

The Exchange CVE-2026-42897 patch delay reflects a known constraint in Microsoft's OWA code base: the Exchange on-premises codebase shares components with Exchange Online but runs on customer-managed infrastructure with a heterogeneous version matrix (2016, 2019, Subscription Edition).

Microsoft's patching velocity for on-premises Exchange consistently lags behind Exchange Online remediations because the on-premises fix must be validated across the full version matrix before release. The Exchange Emergency Mitigation Service (EEMS) workaround was deployed as a compensating control, but its URL-rewrite approach broke OWA features (print, inline images, Light mode), reducing operator willingness to apply it.

The two BitLocker bypasses in a single cycle reflect a known weakness in the Secure Boot chain of trust: BitLocker's pre-boot protection depends on the integrity of the boot loader and the Trusted Platform Module sealing. Research into UEFI and bootloader shim bypass techniques has intensified since 2022, and two independent researchers reaching the same BitLocker bypass surface in a single month indicates the attack surface is now well-understood in offensive security research communities.

What could happen next?
  • Risk

    Two independent BitLocker bypasses confirmed in a single Patch Tuesday suggests concentrated offensive research on Windows disk-encryption trust chains; a third bypass in July or August 2026 would confirm a sustained campaign.

    Short term · Reported
  • Consequence

    Exchange CVE-2026-42897 arriving 16 days past its federal deadline documents a vendor compliance gap that CISA may cite when revising BOD 22-01 timelines for on-premises server products.

    Medium term · Reported
  • Risk

    CVE-2026-47288 Kerberos KDC RCE reaching domain authentication enables Active Directory forest-wide lateral movement from a single compromised endpoint; unpatched domain controllers remain at elevated risk until the June 2026 updates are applied.

    Immediate · Assessed
First Reported In

Update #7 · VPN zero-day, no-patch KEV, late Exchange

BleepingComputer· 14 Jun 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.