Microsoft Blames Uncoordinated Zero‑Day Disclosures After Six Windows Vulnerabilities Exploited
Notify: Adopt a coordinated vulnerability disclosure process with vendors to reduce the risk of public exploits.
Notify: Implement a coordinated vulnerability disclosure policy in your organization.
Summary
Microsoft announced on 28 May 2026 that six previously unknown Windows zero‑day vulnerabilities—RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma—had been publicly disclosed and were already being exploited. Three of the bugs, BlueHammer, RedSun and UnDefend, are in active use by attackers, while YellowKey (CVE‑2026‑45585) has a working proof‑of‑concept and is expected to be widely abused shortly. The exploits were released by security researcher Nightmare Eclipse after Microsoft refused to coordinate the disclosure and subsequently deleted his Microsoft Security Response Center (MSRC) account, withholding the promised bounty payments. Microsoft’s blog denounced the uncoordinated release, threatened legal action against the researcher, and warned that the Digital Crimes Unit would pursue any attackers who used the vulnerabilities.
The incident underscores a dramatic shift in the patch cycle, with enterprise systems now facing attacks that can be executed within hours rather than days. Microsoft pledged to honour bounties for properly coordinated reports and to improve its communication about real‑world risks. The company also announced plans to tighten its vulnerability disclosure processes, aiming to reduce the window between discovery and patching. The fallout highlights the need for faster patch deployment and stronger collaboration between vendors and independent researchers.
Reactions from the security community have been mixed. Some experts praise Microsoft’s stance on coordinated disclosure, while others criticize the company for not providing a clear path for responsible reporting. The bug hunter’s decision to publish the exploits publicly has sparked debate over the ethics of “responsible” versus “public” disclosure. Meanwhile, the Digital Crimes Unit’s threat of legal action signals a more aggressive posture toward researchers who bypass official channels. The broader implication is a call for clearer guidelines and better incentives to ensure that zero‑day vulnerabilities are reported and patched before they can be weaponised.
Key changes
- Microsoft publicly endorses Coordinated Vulnerability Disclosure (CVD)
- Chaotic Eclipse disclosed multiple zero‑day vulnerabilities before patching
- CVD gives vendors time to assess and mitigate risks
- Encourages collaboration between researchers and vendors
- Microsoft supports responsible disclosure via its Bug Bounty program
- Organizations should review and adopt disclosure policies
- The shift aims to accelerate patch cycles and improve ecosystem security
- The policy strengthens trust and reduces public exploitation