CVE detail
CVE-2026-50507
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.1 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
14 source links · newest first
- 15th June – Threat Intelligence ReportCheck Point Research
ysts, this breach is part of a larger wave of attacks targeting more than 100 organizations by ShinyHunters, exploiting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft that allows remote code execution. Check Point IPS provides protection against this threat (Oracle PeopleSoft Enterprise PeopleTools Server-Side Request Forgery (C
vendorresearch.checkpoint.comJun 15, 2026, 1:40 PM June’s Patch Tuesday security updates have arrived, with SAP fixing four critical vulnerabilities and Microsoft addressing over 200 CVEs. Microsoft’s to-do list includes fixes for three zero days, 32 patches rated as ‘critical’, and a batch of other high-risk vulnerabilities that need urgent assessment. There’s also one older flaw under exploit, and some patches affecting […]
newswww.csoonline.comJun 10, 2026, 2:53 PMJune 2026 is the largest Patch Tuesday in history, fixing 206 vulnerabilities and three publicly disclosed zero-days.
newswww.malwarebytes.comJun 10, 2026, 12:43 PMExploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM.
newswww.securityweek.comJun 10, 2026, 11:44 AM- Record Microsoft Patch Tuesday, fresh zero-dayHelp Net Security
Microsoft marked its largest-ever Patch Tuesday this month, by shipping fixes for nearly 200 vulnerabilities. Within hours, “Nightmare Eclipse”, the researcher behind weeks of escalating Windows exploit releases, dropped a proof-of-concept exploit for a new zero-day: “RoguePlanet”, which abuses a race condition in Windows Defender to spawn a command shell running with SYSTEM-level privileges. Various researchers have confirmed that the PoC exploit works to achieve local privilege escalation. “In initial development, it was confirmed that … More →
newswww.helpnetsecurity.comJun 10, 2026, 10:56 AM - Microsoft Releases Record-Breaking Patch Tuesday With 208 CVEsSecurity Affairs
Microsoft Patch Tuesday security updates for June 2026 fix a record 208 CVEs, including one actively exploited zero-day and multiple critical RCE flaws. Microsoft Patch Tuesday security updates for June 2026 mark a record. Microsoft shipped fixes for 208 CVEs across Windows, Office, Azure, Exchange, Hyper-V, Secure Boot, BitLocker, and a range of AI tooling. […]
newssecurityaffairs.comJun 9, 2026, 10:55 PM - A Record-Breaking Patch Tuesday for June 2026Krebs on Security
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available.
newskrebsonsecurity.comJun 9, 2026, 10:07 PM tack. Talos highlights 4 critical vulnerabilities as Microsoft has determined that their exploitation is “more likely:” CVE-2026-42985 is a critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Remote Desktop Client which allows an unauthorized attacker to execute code over a network. CVE-2026-47291 is a critical Remote Code
vendorblog.talosintelligence.comJun 9, 2026, 9:21 PMy to respond without out-of-cycle patches. At time of writing, Microsoft has provided mitigation advice and patches for CVE-2026-33825 , CVE-2026-45585 , CVE-2026-45498 , and CVE-2026-41091 , leaving only two elevation of privilege vulnerabilities unpatched, known as MiniPlasma and GreenPlasma. However, a recent blog post by Nightmare Eclipse with the
vendorwww.rapid7.comJun 9, 2026, 9:04 PMication denial-of-service, and arbitrary code execution. Zero-day Vulnerabilities Patched in June Patch Tuesday Edition CVE-2026-49160: HTTP.sys Denial of Service Vulnerability Uncontrolled resource consumption in HTTP/2 could allow an unauthenticated attacker to deny service over a network. CVE-2026-45586: Windows Collaborative Translation Framework (
vendorblog.qualys.comJun 9, 2026, 8:52 PM- Microsoft Patches 200 VulnerabilitiesSecurityWeek
Three of the vulnerabilities fixed with the latest Patch Tuesday updates were publicly disclosed before Microsoft addressed them.
newswww.securityweek.comJun 9, 2026, 7:04 PM be the flaw known as Bitskrieg and a collaboration between Chaotic Eclipse (Nightmare Eclipse) and Jonas L . Important CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability CVE-2026-49160 is a denial of service (DoS) vulnerability affecting HTTP.sys. It received a CVSSv3 score of 7.5 and is rated as important. It was assessed as “Exploitation More
vendorwww.tenable.comJun 9, 2026, 6:19 PM- The June 2026 Security Update ReviewZero Day Initiative
loser look at some of the more interesting updates for this month, starting with the bug being exploited in the wild. - CVE-2026-41091 - Microsoft Defender Elevation of Privilege Vulnerability Since Microsoft doesn’t provide info on how widespread exploitation is, we must read some tea leaves. For this patch, several different people were acknowledged,
vendorwww.thezdi.comJun 9, 2026, 6:12 PM Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
vendormsrc.microsoft.comJun 9, 2026, 2:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-26160CVSS 7.8 · High
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-26159CVSS 7.8 · High
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-50451CVSS 7.1 · High
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-68820CVSS 7.0 · High
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-59138CVSS 6.5 · Medium
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
- CVE-2026-59137CVSS 5.5 · Medium
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.