Microsoft ships its biggest-ever Patch Tuesday — 200 fixes, six zero-days
Microsoft's June security update was its largest single Patch Tuesday on record, fixing around 200 vulnerabilities across Windows, Office, Exchange and Azure. Among them were six zero-day flaws — bugs already public before a fix existed — including one that attackers are actively exploiting: a Microsoft Exchange / Outlook Web Access spoofing bug (CVE-2026-42897) that can run rogue JavaScript in a victim's mailbox.
The update also closed 33 “critical” holes, most of which let an attacker run code remotely, plus two flaws that bypass BitLocker drive encryption on a device someone can physically get to. The fix is the easy part — but only if it actually installs. The danger window is the gap between “update available” and “update applied”.