YellowKey CVE-2026-45585 Bypasses BitLocker Before a Patch Lands
Microsoft has issued a mitigation for CVE-2026-45585, a publicly disclosed BitLocker bypass zero-day dubbed YellowKey, while a full patch is still pending. CVSS 6.8 understates the risk for encrypted-disk-dependent security models.