Microsoft Patches Three Windows Zero-Day Vulnerabilities Including Privilege Escalation Flaws
Microsoft's June 2026 Patch Tuesday addressed two zero-day Windows privilege escalation vulnerabilities (SYSTEM-level) and a third BitLocker security feature bypass, collectively tracked as YellowKey, GreenPlasma, and MiniPlasma. A broader patch cycle also resolved a record 208 CVEs including a wormable kernel-level flaw. As of the latest reporting, no in-the-wild exploitation, no named insured losses, and no specific corporate incidents have been confirmed. The event remains at the developing/signal stage with no identified loss pathway to London market specialty books.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Low impact. Loss pathway: None identified. Reporting remains limited to trade media coverage of a routine but elevated Patch Tuesday disclosure, with one corroborating mainstream source describing a record 208-CVE cycle that includes a wormable kernel flaw. No active exploitation campaign, no insured losses, no specific corporate incidents, no claims, and no reserving or capacity implications are documented. The two zero-day privilege escalations and the BitLocker bypass are notable from a cyber hygiene and threat-landscape monitoring perspective, and the wormable kernel flaw raises systemic exposure considerations, but absent evidence of in-the-wild exploitation causing insured losses, the prior low-impact assessment is preserved.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialLloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts