Microsoft has disclosed a publicly known zero-day vulnerability in BitLocker that could allow an attacker with physical access to bypass Windows’ built-in disk encryption and access data stored on an encrypted drive.
The vulnerability, tracked as CVE-2026-50661, was fixed as part of Microsoft’s July 2026 Patch Tuesday updates. The company classifies the issue as a Security Feature Bypass and says it stems from a failure in BitLocker’s protection mechanism rather than a flaw in the underlying encryption itself. Microsoft has not observed the vulnerability being exploited in the wild but confirmed that it had been publicly disclosed before patches became available
Unlike most Windows vulnerabilities disclosed each month, this one cannot be exploited remotely. An attacker must first obtain physical access to the target device. Even so, the issue deserves attention because BitLocker is specifically designed to protect data when a laptop or server falls into someone else’s hands.

What the vulnerability does
Microsoft’s advisory states that a successful attacker can bypass BitLocker Device Encryption on the system storage device.
The company has released few technical details, which is typical while patches are still being deployed. Based on Microsoft’s description, the flaw affects the protection mechanisms surrounding BitLocker rather than the encryption algorithms themselves. That distinction matters.
BitLocker relies on several security components working together before Windows unlocks an encrypted volume. These include Secure Boot, the Trusted Platform Module (TPM), boot integrity checks, recovery workflows, and authentication policies. If one of those protective layers can be bypassed, an attacker may be able to access an encrypted drive without possessing the BitLocker recovery key or PIN.
Microsoft has not published proof-of-concept code or disclosed the precise attack sequence, likely to reduce the chance of copycat attacks while organizations roll out updates.
Why physical attacks still matter
Because exploitation requires someone to have the device in their possession, the vulnerability does not present the same widespread risk as a remotely exploitable Windows flaw. However, physical attacks remain a realistic threat.
Corporate laptops are stolen every day. Devices are lost while travelling. Servers can be seized during investigations or stolen from poorly secured branch offices. In those situations, BitLocker is often the final barrier preventing sensitive files from being read offline.
If that barrier can be bypassed, attackers may gain access to confidential documents, cached credentials, browser data, source code, certificates, or other information stored on the system drive. For organizations that rely on encryption to satisfy regulatory or contractual requirements, that changes the risk associated with device theft.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →Part of a broader pattern
CVE-2026-50661 is not the first vulnerability to target BitLocker without attacking the encryption itself. Over the past few years, researchers have repeatedly demonstrated ways to weaken Windows disk encryption by exploiting weaknesses in the boot process, recovery environments, or trust relationships established before the operating system fully starts.
Previous research, including the “YellowKey” BitLocker bypass, focused on similar attack paths involving Windows Recovery Environment and boot-time protections rather than attempting to defeat the AES encryption used by BitLocker.
The latest vulnerability appears to follow that same direction. Instead of breaking encryption, it targets the mechanisms responsible for protecting access to encrypted data.
Affected Windows versions
Microsoft has released security updates for supported Windows client and server releases.
Affected platforms include:
- Windows 10
- Windows 11
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
- Windows Server 2025
The fixes are included in the July 14 cumulative updates, including:
- KB5099535 – Windows 10 Version 1607 and Windows Server 2016
- KB5099538 – Windows 10 Version 1809 and Windows Server 2019
- KB5099539 – Windows 10 Versions 21H2 and 22H2
- KB5099540 – Windows Server 2022
- KB5101649 and KB5101650 – Windows 11 (24H2, 25H2, 26H1) and Windows Server 2025
Administrators should install these updates as soon as practical, particularly on mobile devices that regularly leave secured offices.
Microsoft’s assessment
Microsoft rates the vulnerability as Exploitation Less Likely in its Exploitability Index.
That rating reflects several limitations:
- Physical access to the device is required.
- The attack does not execute remotely.
- No active exploitation has been observed.
- Microsoft has not released technical details describing the attack.
Even with those constraints, organizations should avoid treating the issue as low priority. Encryption is intended to protect systems after they have already been lost or stolen, making vulnerabilities in that layer especially relevant for enterprises with mobile workforces.
What administrators should do
The immediate recommendation is to deploy the July 2026 security updates across affected Windows systems.
Security teams should also review their BitLocker deployments and verify that devices continue to use recommended configurations after patching.
Microsoft also continues to recommend enabling Secure Boot, using TPM-backed protection, securely storing BitLocker recovery keys, and enabling additional authentication such as pre-boot PINs where appropriate.
Final thoughts
Microsoft has not indicated that CVE-2026-50661 is being exploited, and there is currently no public evidence suggesting widespread attacks.
Still, vulnerabilities affecting BitLocker tend to receive close attention from security researchers because they target one of Windows’ most widely deployed security features. For organizations that depend on disk encryption to protect lost or stolen devices, applying this month’s updates should be considered routine maintenance rather than an optional hardening exercise.









