MilikMilik

Microsoft and Google Rush Out Major Security Fixes: What to Patch First

Microsoft and Google Rush Out Major Security Fixes: What to Patch First
Interest|High-Quality Software

Why This Patch Wave Matters and What Is at Stake

Patch Tuesday security updates and Chrome’s latest release mark a surge of coordinated security fixes from major software vendors that aim to close dangerous vulnerabilities before attackers can exploit them at scale, forcing IT teams to rapidly prioritize zero-day patches and other high-risk flaws rather than trying to apply every update immediately. Microsoft’s latest Patch Tuesday is its largest on record, with more than 200 CVEs addressed across Windows and related products. At the same time, Google has shipped security updates for 74 Chrome vulnerabilities, including one actively exploited Chrome V8 vulnerability. Together, these releases reflect a new tempo in which AI-assisted bug discovery exposes weaknesses faster than traditional patching cycles can keep up. Security leaders need a clear plan to decide which Windows critical flaws and browser issues to fix first, based on exposure and impact.

Microsoft and Google Rush Out Major Security Fixes: What to Patch First

Critical Microsoft Patches: Priorities for Windows and Servers

Microsoft’s June Patch Tuesday includes over 200 CVEs, with more than 30 rated Critical and several zero-days disclosed ahead of release. Two stand-out network bugs need immediate attention: CVE‑2026‑47291 in Windows HTTP.sys and CVE‑2026‑44815 in Windows DHCP Client. Both can be exploited remotely without authentication or user interaction, making them prime candidates for wormable attacks. Amol Sarwate noted that in the first half of 2026 there was a “roughly 3x increase in critical vulnerabilities (9.0 or above) compared to the same time last year.” Admins should patch internet-facing servers that use HTTP.sys first, then all systems running the Windows DHCP Client. Next in line are the publicly disclosed zero-days, including CVE‑2026‑45586, CVE‑2026‑50507, and CVE‑2026‑49160, which cover privilege escalation, BitLocker bypass, and HTTP.sys denial-of-service risks, respectively.

Chrome V8 Zero-Day CVE-2026-11645: Immediate Browser Action

Google’s latest Chrome update fixes 74 vulnerabilities, but the Chrome V8 vulnerability CVE-2026-11645 should be your top browser priority. This high-severity flaw (CVSS 8.8) is an out-of-bounds memory access in V8, Chrome’s JavaScript and WebAssembly engine. It allows remote attackers to execute arbitrary code inside the browser sandbox via a crafted HTML page. Google has confirmed that an exploit for CVE-2026-11645 exists in the wild, which means the CVE-2026-11645 exploit is not theoretical and users are already being targeted. The bug was reported by the researcher “303f06e3,” who earned a USD 55,000 (approx. RM256,000) bug bounty for responsible disclosure. To stay protected, update Chrome to 149.0.7827.102/.103 on Windows and macOS, and 149.0.7827.102 on Linux, then relaunch the browser. Users of Chromium-based browsers like Edge, Brave, Opera, and Vivaldi must also track and apply their corresponding updates.

A Practical Patch Order for Overloaded IT Teams

With record Patch Tuesday security updates and major browser fixes landing together, IT teams should follow a clear order of operations. First, deploy zero-day patches and exploited flaws: prioritize CVE‑2026‑11645 in Chrome and any Chromium-based browsers, plus publicly exposed Microsoft zero-days like CVE‑2026‑45586, CVE‑2026‑50507, and CVE‑2026‑49160. Second, tackle unauthenticated remote Windows critical flaws with large attack surfaces, especially CVE‑2026‑47291 in HTTP.sys and CVE‑2026‑44815 in the DHCP Client on servers and endpoints. Third, patch remaining Windows critical flaws on systems exposed to the internet or handling sensitive data. Finally, roll out the rest of the updates in scheduled waves, aligned with your change windows and testing capacity. Microsoft advises customers to “triage by exposure and impact, not raw count,” shifting away from patch-everything-now strategies toward risk-based patching supported by network segmentation and strong identity controls.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!