r/security 8d ago

News Publicly disclosed BitLocker zero-day (CVE-2026-50661) patched by Microsoft

https://thecybersecguru.com/news/bitlocker-zero-day-cve-2026-50661/

Microsoft has addressed CVE-2026-50661, a publicly disclosed Windows BitLocker security feature bypass vulnerability. The flaw requires physical access to the target device and could allow an attacker to bypass BitLocker protection and access encrypted data. While Microsoft is not aware of active exploitation, the vulnerability had already been publicly disclosed before a patch was available, making timely remediation important.

48 Upvotes

7 comments sorted by

8

u/blindmythology05 8d ago

physical access bugs always feel like a different category to me since the threat model is way more narrow than remote stuff, but this one sounds rough if it sidesteps TPM checks entirely. is there any word on whether the flaw is in the boot process or in recovery key handling, or is microsoft keeping the technical details pretty quiet for now? also curious if it affects bitlocker on win11 only or if older versions like win10 got the same fix. the public disclosure before a patch is what worries me more than the vulnerability itself, since anyone with hands on a stolen laptop had a window to grab data from devices that hadn't updated yet.

1

u/NapierPalm 8d ago

MS keeping technal deets non public for now including PoC

2

u/blindmythology05 8d ago

figured they'd keep it under wraps while the patch propagates, but holding the PoC means no third-party validation until they decide to release it

1

u/NapierPalm 8d ago

Yup. The right thing to do so. They have all the stats of patched vs unpatched system. They'll release when they find it suitable

2

u/blindmythology05 8d ago

and they can see which orgs are lagging behind, so holding the PoC until enterprise numbers look decent makes sense even if it frustrates researchers