Microsoft Ships Record 200-Bug Patch Tuesday as 'Nightmare Eclipse' Drops Windows Zero-Days

AI-assisted bug hunting, a confrontational researcher, and a Shai-Hulud worm variant inside Microsoft's own repos shape an outsized June rollup.

ThreatVectr Newsdesk· 3 min read
Microsoft Ships Record 200-Bug Patch Tuesday as 'Nightmare Eclipse' Drops Windows Zero-Days
Share

Microsoft pushed fixes for roughly 200 vulnerabilities this Patch Tuesday, the largest single-month total the company has shipped. Almost three dozen carry a critical rating. Public exploit code already exists for at least three.

The scale isn't coincidence. Vendor engineers and outside researchers are both running LLM-assisted fuzzing and triage pipelines at volume, and one of the June zero-days — a denial-of-service flaw in IIS and other web servers tracked as CVE-2026-49160 — was credited to OpenAI's Codex in Microsoft's advisory.

Tenable's Satnam Narang expects this cadence to hold. "Some surveys put AI usage among security professionals generally at 90%, so it's unsurprising that this volume of patches may be the norm," he said. "Pandora's proverbial box has been opened."

The Nightmare Eclipse problem

Two of the June zero-days appear to trace back to a researcher operating under the handle Nightmare Eclipse, who has been publicly dropping Windows exploits ahead of coordinated disclosure.

One, dubbed GreenPlasma, abuses an elevation-of-privilege bug in the Windows Collaborative Translation Framework. Microsoft addressed it as CVE-2026-45586. A second, YellowKey, targeted a BitLocker weakness that exposes encrypted data to an attacker with physical access; the patch is CVE-2026-50507. Neither advisory credits the researcher.

Microsoft floated the possibility of legal action against Nightmare Eclipse last month, then walked it back, clarifying that it would only refer researchers to authorities for actual criminal conduct. The researcher — who claims, unverified, to be a former Microsoft employee — has promised a "bone shattering" drop on July 14. Hours after today's patches shipped, they published what they describe as a Windows Defender zero-day.

Treat that capability claim as medium confidence pending independent reproduction.

The numbers behind the numbers

The 200 figure undercounts the real workload. Rapid7's Adam Barnett notes Microsoft has shipped patches for 360 Chromium-based browser vulnerabilities this month alone, an order of magnitude above baseline. Microsoft no longer enumerates Chromium CVEs in its Security Update Guide.

A separate Visual Studio Code zero-day allowing one-click GitHub token theft got an out-of-band fix on June 3 after a researcher published exploitation steps. They said they skipped coordinated disclosure because of a prior silent patch with no credit.

Shai-Hulud, again

Microsoft also spent last week cleaning up after a Shai-Hulud worm variant infected at least 72 of its public code repositories. Every affected package tied back to the official Azure Durable Task SDK, which was hit by the same worm family in May. The repeat compromise of a single SDK supply chain suggests the original remediation didn't fully evict the threat actor's persistence vector, though attribution beyond "Shai-Hulud operator cluster" remains thin.

Adobe shipped a large bundle covering Experience Manager, Acrobat Reader and ColdFusion. Chrome 429 vulnerabilities landed June 3.

Back up before patching. See Microsoft's Security Update Guide for the full list.

© 2026 Threat Vectr