Microsoft Patch Tuesday Analysis – June 2026

Executive Summary

On Tuesday, June 09, 2026, Microsoft released its monthly security patch, addressing 204 vulnerabilities across its products.

By severity level:

  • Critical - 38;
  • Important - 166.

Exploited (Zero-Days) and Publicly Disclosed Vulnerabilities

Special attention should be paid to the following 3 vulnerabilities. Fixing them is the highest priority:

  • CVE-2026-45586 (CVSS 7.8; Important) - Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability (Elevation of Privilege). An "incorrect link resolution before file access" vulnerability (CWE-59) in the Windows Collaborative Translation Framework (CTFMON). A local authenticated attacker with low privileges can exploit this issue to manipulate CTF service file operations. By creating symbolic links or NTFS junctions in user-controlled directories, an attacker can redirect file write or delete requests from a highly privileged process to protected system resources, allowing privilege escalation in the system to the SYSTEM level.
  • CVE-2026-49160 (CVSS 7.5; Important) - HTTP.sys Denial of Service Vulnerability (Denial of Service). An uncontrolled resource consumption vulnerability (CWE-400) in the HTTP/2 (and HTTP/3) support implementation handled by the HTTP.sys driver. A remote unauthenticated attacker can cause a Denial of Service (DoS) condition on the web server by sending specially crafted network requests with an abnormally large number of headers. To address the vulnerability and provide preemptive protection, Microsoft introduced a new security update that includes the MaxHeadersCount registry parameter (detailed in KB5102602) to strictly limit the number of headers in requests.
  • CVE-2026-50507 (CVSS 6.8; Important) - Windows BitLocker Security Feature Bypass Vulnerability (Security Feature Bypass). The vulnerability relates to the lack of authentication for a critical function (CWE-306) in the Windows BitLocker protection mechanism. An attacker with physical access to the target device can exploit this flaw to bypass BitLocker Device Encryption and gain unauthorized access to encrypted sensitive data on the system drive.

General Trends

The June 2026 Patch Tuesday will go down in history as one of the largest and heaviest releases in recent years. Microsoft issued patches for 204 vulnerabilities, of which 38 have a "Critical" status. Such a volume of updates indicates a massive security audit of the OS and cloud platform codebases. Key trends for June:

  • Record volume and criticality: Crossing the 200-vulnerability mark makes this month an extreme test for patch management processes in any organization. The presence of nearly 40 critical vulnerabilities (mostly RCE) means that attack vectors are broader than ever.
  • Threat of public disclosure: Although no active "in the wild" exploitation has been recorded at the time of the patch release, 3 vulnerabilities were disclosed publicly at once. This gives hackers a huge head start. Of particular concern is HTTP.sys (DoS), as public knowledge of attack methods on the built-in Windows web server threatens massive infrastructure outages. The disclosure of the BitLocker bypass endangers data on corporate laptops if they are lost.
  • Network perimeter under massive strike: June has been a catastrophic month for network services. Critical RCE vulnerabilities (CVSS 9.8) were patched in DHCP Client and HTTP.sys, along with a scattering of RCEs in Remote Desktop Client (RDP) and RRAS. Vulnerabilities in such foundational protocols carry the risk of "worms" (self-propagating malware) capable of infecting machines without user interaction.
  • Cloud platforms on the edge: This month, a vulnerability with the highest possible rating of CVSS 10.0 in Azure HorizonDB was closed, as well as critical RCEs in Azure Kubernetes Service (AKS) and Azure Stack Edge. This confirms that Microsoft's cloud infrastructure is undergoing deep reverse engineering by researchers and malicious actors.
  • Unceasing stream of EoP and Office vulnerabilities: Traditionally, over 70 patches close local Elevation of Privilege (EoP) loopholes (the publicly disclosed vulnerability in CTFMON stands out). Concurrently, Microsoft is patching dozens of RCEs in Microsoft Office, Word, and Exchange, maintaining a high threat level from phishing campaigns.

Full List of Vulnerabilities

Below is a table with all the vulnerabilities patched this month.

CVETitleTypeCVSSSeverityExploitedPublicly Disclosed
CVE-2026-45586Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoYes
CVE-2026-49160HTTP.sys Denial of Service VulnerabilityDenial of Service7.5ImportantNoYes
CVE-2026-50507Windows BitLocker Security Feature Bypass VulnerabilitySecurity Feature Bypass6.8ImportantNoYes
CVE-2026-48567Azure HorizonDB Elevation of Privilege VulnerabilityElevation of Privilege10.0CriticalNoNo
CVE-2026-26142Nuance PowerScribe Remote Code Execution VulnerabilityRemote Code Execution9.8CriticalNoNo
CVE-2026-44815DHCP Client Service Remote Code Execution VulnerabilityRemote Code Execution9.8CriticalNoNo
CVE-2026-45657Windows Kernel Remote Code Execution VulnerabilityRemote Code Execution9.8CriticalNoNo
CVE-2026-47291HTTP.sys Remote Code Execution VulnerabilityRemote Code Execution9.8CriticalNoNo
CVE-2026-47643Azure Stack Edge Remote Code Execution VulnerabilityRemote Code Execution9.8ImportantNoNo
CVE-2026-42904Windows TCP/IP Elevation of Privilege VulnerabilityElevation of Privilege9.6ImportantNoNo
CVE-2026-47281Visual Studio Code Elevation of Privilege VulnerabilityElevation of Privilege9.6ImportantNoNo
CVE-2026-45602Windows Dynamic Host Configuration Protocol (DHCP) Tampering VulnerabilityTampering9.1ImportantNoNo
CVE-2026-48579Microsoft Exchange Online Information Disclosure VulnerabilityInformation Disclosure9.1CriticalNoNo
CVE-2026-32193Azure Kubernetes Service (AKS) Remote Code Execution VulnerabilityRemote Code Execution8.8CriticalNoNo
CVE-2026-40371Microsoft Dynamics 365 (on-premises) Elevation of Privilege VulnerabilityElevation of Privilege8.8ImportantNoNo
CVE-2026-42985Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution8.8CriticalNoNo
CVE-2026-45484Microsoft SharePoint Elevation of Privilege VulnerabilityElevation of Privilege8.8ImportantNoNo
CVE-2026-45504Microsoft Exchange Server Elevation of Privilege VulnerabilityElevation of Privilege8.8ImportantNoNo
CVE-2026-45648Windows Active Directory Domain Services Remote Code Execution VulnerabilityRemote Code Execution8.8CriticalNoNo
CVE-2026-47289Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution8.8CriticalNoNo
CVE-2026-47653Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution8.8ImportantNoNo
CVE-2026-41098Azure Stack Edge Spoofing VulnerabilitySpoofing8.4ImportantNoNo
CVE-2026-44810Microsoft Cryptographic Services Elevation of Privilege VulnerabilityElevation of Privilege8.4CriticalNoNo
CVE-2026-45456Microsoft Outlook and Word Remote Code Execution VulnerabilityRemote Code Execution8.4CriticalNoNo
CVE-2026-45458Microsoft Outlook and Word Remote Code Execution VulnerabilityRemote Code Execution8.4CriticalNoNo
CVE-2026-45461Microsoft Office Remote Code Execution VulnerabilityRemote Code Execution8.4CriticalNoNo
CVE-2026-45463Microsoft Office Remote Code Execution VulnerabilityRemote Code Execution8.4CriticalNoNo
CVE-2026-45472Microsoft Office Remote Code Execution VulnerabilityRemote Code Execution8.4CriticalNoNo
CVE-2026-45474Microsoft Office Remote Code Execution VulnerabilityRemote Code Execution8.4CriticalNoNo
CVE-2026-45482Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass VulnerabilitySecurity Feature Bypass8.4ImportantNoNo
CVE-2026-45607Windows Hyper-V Remote Code Execution VulnerabilityRemote Code Execution8.4CriticalNoNo
CVE-2026-45641Windows Hyper-V Remote Code Execution VulnerabilityRemote Code Execution8.4CriticalNoNo
CVE-2026-47635Microsoft Outlook and Word Remote Code Execution VulnerabilityRemote Code Execution8.4CriticalNoNo
CVE-2026-44822Microsoft Excel Information Disclosure VulnerabilityInformation Disclosure8.2ImportantNoNo
CVE-2026-45476Microsoft Azure Network Adapter Elevation of Privilege VulnerabilityElevation of Privilege8.2CriticalNoNo
CVE-2026-47652Windows Hyper-V Remote Code Execution VulnerabilityRemote Code Execution8.2CriticalNoNo
CVE-2026-42835Microsoft Teams for Android Information Disclosure VulnerabilityInformation Disclosure8.1ImportantNoNo
CVE-2026-42974Windows Performance Monitor Remote Code Execution VulnerabilityRemote Code Execution8.1ImportantNoNo
CVE-2026-42981Windows Performance Monitor Remote Code Execution VulnerabilityRemote Code Execution8.1ImportantNoNo
CVE-2026-42987Windows Deployment Services (WDS) Remote Code ExecutionRemote Code Execution8.1CriticalNoNo
CVE-2026-45503Microsoft Exchange Server Information Disclosure VulnerabilityInformation Disclosure8.1ImportantNoNo
CVE-2026-45599Windows UPnP Device Host Remote Code Execution VulnerabilityRemote Code Execution8.1ImportantNoNo
CVE-2026-45635Windows UPnP Device Host Remote Code Execution VulnerabilityRemote Code Execution8.1ImportantNoNo
CVE-2026-47631Microsoft Exchange Server Spoofing VulnerabilitySpoofing8.1ImportantNoNo
CVE-2026-45644Microsoft Live Share Canvas SDK Elevation of Privilege VulnerabilityElevation of Privilege8.0ImportantNoNo
CVE-2026-47298Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Execution8.0ImportantNoNo
CVE-2026-45588Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypass7.9ImportantNoNo
CVE-2026-45654Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypass7.9ImportantNoNo
CVE-2026-47656Windows Boot Manager Security Feature Bypass VulnerabilitySecurity Feature Bypass7.9ImportantNoNo
CVE-2026-48568Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypass7.9ImportantNoNo
CVE-2026-48570Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypass7.9ImportantNoNo
CVE-2026-48573Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypass7.9ImportantNoNo
CVE-2026-48575Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypass7.9ImportantNoNo
CVE-2026-48576Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypass7.9ImportantNoNo
CVE-2026-48578Secure Boot Security Feature Bypass VulnerabilityElevation of Privilege7.9ImportantNoNo
CVE-2026-33828Windows Device Health Attestation (DHA) Elevation of Privilege VulnerabilityElevation of Privilege7.8CriticalNoNo
CVE-2026-40404Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-40409Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-41092Microsoft Kinect Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42828Windows Projected File System Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42829Windows Administrator Protection Secure Feature Bypass VulnerabilitySecurity Feature Bypass7.8ImportantNoNo
CVE-2026-42837Windows Projected File System Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42902Microsoft PowerToys Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42905Windows DWM Core Library Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42910Windows Hotpatch Monitoring Service Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42916NT OS Kernel Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42977Windows Push Notifications Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42978Windows Push Notifications Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42979Windows Push Notifications Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42980NT OS Kernel Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42983Windows DWM Core Library Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42986Microsoft Graphics Component Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42989Winlogon Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-42991Windows Push Notifications Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-44802Windows DWM Core Library Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-44803Windows Graphics Component Remote Code Execution VulnerabilityRemote Code Execution7.8CriticalNoNo
CVE-2026-44804Windows DWM Core Library Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-44807Windows DWM Core Library Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-44808Windows DWM Core Library Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-44809Windows Common Log File System Driver Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-44811Windows DWM Core Library Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-44812Windows Graphics Component Remote Code Execution VulnerabilityRemote Code Execution7.8CriticalNoNo
CVE-2026-44813Windows DWM Core Library Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-44817Microsoft Excel Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-44819Microsoft Office Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-44820Microsoft Excel Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-44823Microsoft Excel Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-44824Microsoft Office Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-45457Microsoft Word Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-45469Microsoft Excel Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-45471Microsoft Word Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-45475Microsoft Office Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-45486Microsoft Word Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-45487Windows Program Compatibility Assistant Service Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-45490.NET SDK Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-45592Windows Internet (wininet.dll) Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-45593Windows SDK Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-45600Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-45605Windows Bluetooth Service Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-45636Windows NTFS Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-45637Microsoft DWM Core Library Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-45638Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-45643Microsoft Word Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-45645Microsoft Office Remote Code Execution VulnerabilityRemote Code Execution7.8ImportantNoNo
CVE-2026-45656UEFI Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypass7.8ImportantNoNo
CVE-2026-45658Windows BitLocker Security Feature Bypass VulnerabilitySecurity Feature Bypass7.8ImportantNoNo
CVE-2026-47292Visual Studio Code MSSQL Extension Remote Code Execution VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-48565Windows Narrator Braille Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-48574Windows Media Remote Code Execution VulnerabilityRemote Code Execution7.8CriticalNoNo
CVE-2026-48583Windows Kernel Elevation of Privilege VulnerabilityElevation of Privilege7.8ImportantNoNo
CVE-2026-49161Microsoft PC Manager Security Feature Bypass VulnerabilitySecurity Feature Bypass7.8ImportantNoNo
CVE-2026-45497Microsoft M365 Copilot Remote Code Execution VulnerabilityRemote Code Execution7.7CriticalNoNo
CVE-2026-40376Visual Studio Code Elevation of Privilege VulnerabilityElevation of Privilege7.5ImportantNoNo
CVE-2026-42908Windows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityInformation Disclosure7.5ImportantNoNo
CVE-2026-42909Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution7.5ImportantNoNo
CVE-2026-42913Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution7.5ImportantNoNo
CVE-2026-42992Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution7.5CriticalNoNo
CVE-2026-42993Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution7.5ImportantNoNo
CVE-2026-44799Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution7.5CriticalNoNo
CVE-2026-44801Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution7.5CriticalNoNo
CVE-2026-45583Microsoft Exchange Server Remote Code Execution VulnerabilityRemote Code Execution7.5ImportantNoNo
CVE-2026-45591ASP.NET Core Denial of Service VulnerabilityDenial of Service7.5ImportantNoNo
CVE-2026-45639Windows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityInformation Disclosure7.5ImportantNoNo
CVE-2026-47654Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution7.5CriticalNoNo
CVE-2026-48563Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Execution7.5CriticalNoNo
CVE-2026-45481Microsoft SharePoint Server Spoofing VulnerabilitySpoofing7.3ImportantNoNo
CVE-2026-47634Microsoft SharePoint Server Spoofing VulnerabilitySpoofing7.3ImportantNoNo
CVE-2026-45649Office for Android Spoofing VulnerabilitySpoofing7.1ImportantNoNo
CVE-2026-47288Windows Kerberos Key Distribution Center (KDC) Remote Code ExecutionRemote Code Execution7.1CriticalNoNo
CVE-2026-48569Visual Studio Code Security Feature Bypass VulnerabilitySecurity Feature Bypass7.1ImportantNoNo
CVE-2026-34335Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-41108Windows DNS Client Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-42836Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-42911Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-42912Windows Telephony Service Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-42984Windows Kernel Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-44818Microsoft Excel Remote Code Execution VulnerabilityRemote Code Execution7.0ImportantNoNo
CVE-2026-45596Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-45597Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-45598Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-45601Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-45603Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-45640Windows Bluetooth Port Driver Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-45653Windows Kernel Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-47293Microsoft Office Click-To-Run Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-47648Windows Storage Elevation of Privilege VulnerabilityElevation of Privilege7.0ImportantNoNo
CVE-2026-45608Windows DHCP Client Information Disclosure VulnerabilityInformation Disclosure6.8ImportantNoNo
CVE-2026-42824M365 Copilot Information Disclosure VulnerabilityInformation Disclosure6.5CriticalNoNo
CVE-2026-42903Windows Kerberos Denial of Service VulnerabilityDenial of Service6.5ImportantNoNo
CVE-2026-42907Windows Shell Information Disclosure VulnerabilityInformation Disclosure6.5ImportantNoNo
CVE-2026-45454Microsoft SharePoint Remote Code Execution VulnerabilityRemote Code Execution6.5ImportantNoNo
CVE-2026-45501Microsoft Exchange Server Spoofing VulnerabilitySpoofing6.5ImportantNoNo
CVE-2026-47284Visual Studio Code Information Disclosure VulnerabilityInformation Disclosure6.5ImportantNoNo
CVE-2026-47287Visual Studio Code Tampering VulnerabilityTampering6.5ImportantNoNo
CVE-2026-47644Copilot Chat (Microsoft Edge) Information Disclosure VulnerabilityInformation Disclosure6.5CriticalNoNo
CVE-2026-47655Microsoft Graph Information Disclosure VulnerabilityInformation Disclosure6.5CriticalNoNo
CVE-2026-50508Windows NTLM Spoofing VulnerabilitySpoofing6.5ImportantNoNo
CVE-2026-45491.NET Tampering VulnerabilityTampering6.2ImportantNoNo
CVE-2026-45500Microsoft Exchange Server Spoofing VulnerabilitySpoofing6.1ImportantNoNo
CVE-2026-42915Windows TCP/IP Denial of Service VulnerabilityDenial of Service5.7ImportantNoNo
CVE-2026-42906Windows Shell Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-42968Windows Telephony Server Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-42969Windows Push Notification Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-42970Windows Push Notification Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-42971Windows Push Notification Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-42972Windows Hyper-V Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-42973Windows Push Notification Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-44805Windows Network Controller (NC) Host Agent Denial of Service VulnerabilityDenial of Service5.5ImportantNoNo
CVE-2026-44814Windows DWM Core Library Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-44821Microsoft Office Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-45594Windows Application Identity (AppID) Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-45604Windows Managed Installer Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-45606Microsoft UxTheme Library (uxtheme.dll) Denial of Service VulnerabilityDenial of Service5.5ImportantNoNo
CVE-2026-45634Windows DHCP Client Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-45647Microsoft Defender for Endpoint for Mac Elevation of Privilege VulnerabilityElevation of Privilege5.5ImportantNoNo
CVE-2026-48566Windows DWM Core Library Information Disclosure VulnerabilityInformation Disclosure5.5ImportantNoNo
CVE-2026-33113Microsoft SharePoint Server Spoofing VulnerabilitySpoofing5.4ImportantNoNo
CVE-2026-45453Microsoft SharePoint Server Spoofing VulnerabilitySpoofing5.4ImportantNoNo
CVE-2026-45464Microsoft SharePoint Server Spoofing VulnerabilitySpoofing5.4ImportantNoNo
CVE-2026-45465Microsoft SharePoint Server Spoofing VulnerabilitySpoofing5.4ImportantNoNo
CVE-2026-45595Windows Mark of the Web Security Feature Bypass VulnerabilitySecurity Feature Bypass5.4ImportantNoNo
CVE-2026-47636Microsoft SharePoint Server Spoofing VulnerabilitySpoofing5.4ImportantNoNo
CVE-2026-47639Microsoft SharePoint Server Spoofing VulnerabilitySpoofing5.4ImportantNoNo
CVE-2026-48560Microsoft SharePoint Server Spoofing VulnerabilitySpoofing5.4ImportantNoNo
CVE-2026-42914Windows Kerberos Denial of Service VulnerabilityDenial of Service5.3ImportantNoNo
CVE-2026-45655Windows BitLocker Security Feature Bypass VulnerabilitySecurity Feature Bypass5.3ImportantNoNo
CVE-2026-45502Microsoft Exchange Server Information Disclosure VulnerabilityInformation Disclosure5.0ImportantNoNo
CVE-2026-45460Microsoft Office Information Disclosure VulnerabilityInformation Disclosure4.7CriticalNoNo
CVE-2026-45462Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6ImportantNoNo
CVE-2026-45467Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6ImportantNoNo
CVE-2026-45468Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6ImportantNoNo
CVE-2026-45479Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6ImportantNoNo
CVE-2026-45483Microsoft Office Project Server Spoofing VulnerabilitySpoofing4.6ImportantNoNo
CVE-2026-47637Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6ImportantNoNo
CVE-2026-47638Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6ImportantNoNo
CVE-2026-47640Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6ImportantNoNo
CVE-2026-47641Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6ImportantNoNo
CVE-2026-48562Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6ImportantNoNo
CVE-2026-45650Microsoft Bing Search Spoofing VulnerabilitySpoofing4.3ImportantNoNo
CVE-2026-45642Microsoft Azure Attestation service and Device Health Attestation Service Spoofing VulnerabilitySpoofing3.9ImportantNoNo
CVE-2026-45455Microsoft Excel Information Disclosure VulnerabilityInformation Disclosure3.3ImportantNoNo
CVE-2026-45459Microsoft Excel Security Feature Bypass VulnerabilitySecurity Feature Bypass3.3ImportantNoNo
CVE-2026-45466Microsoft Word Information Disclosure VulnerabilityInformation Disclosure3.3ImportantNoNo
CVE-2026-45485Microsoft Office Information Disclosure VulnerabilityInformation Disclosure3.3ImportantNoNo

Retrospective Vulnerability Analysis

  • CVE-2026-24294 — Windows SMB Server Elevation of Privilege Vulnerability (Elevation of Privilege). This vulnerability is a logical bypass of the patches for CVE-2025-33073 and allows a local attacker to escalate their privileges to the SYSTEM level. Researcher Guillaume André demonstrated that using a new Windows feature (selecting an arbitrary TCP port for SMB connections) allows forcing a privileged service (e.g., LSASS) to authenticate to a controlled local port. This enables an NTLM reflection attack, forwarding the authentication token back to the system's legitimate SMB server. The vulnerability was patched in March 2026.

  • CVE-2026-41089 — Windows Netlogon Remote Code Execution Vulnerability (Remote Code Execution). The vulnerability is a stack-based buffer overflow in the Netlogon service. An unauthenticated attacker can remotely send a specially crafted CLDAP request (UDP port 389) to the domain controller with an excessively long username. Due to incorrect handling of Unicode string sizes in the NetpLogonPutUnicodeString function, an out-of-bounds write occurs in the allocated stack buffer. This leads to the crash of the LSASS process and a forced reboot of the domain controller (Denial of Service), and potentially allows for arbitrary code execution. A PoC is available for this vulnerability. It was patched in May 2026.

  • CVE-2026-41096 — Windows DNS Client Remote Code Execution Vulnerability (Remote Code Execution). The vulnerability is a heap-based buffer overflow in the Windows DNS client that occurs when processing malformed DNS responses. The error happens in the dnsapi.dll library (in the DnsRawTruncateMessageForUdp() function) when parsing the structure of an incoming packet received via the DnsQueryRaw() interface. An attacker can cause a crash or execute arbitrary code without authentication by sending a specially crafted response (e.g., containing zero QDCOUNT queries and a large OPT record). A client-side PoC is available to verify the vulnerability, which triggers a process crash if unpatched. It was patched in May 2026.

  • CVE-2026-40369 — Windows Kernel Elevation of Privilege Vulnerability (Elevation of Privilege). An "untrusted pointer dereference" vulnerability (CWE-822) in the NtQuerySystemInformation system call (class 253), arising from improper handling of a zero-length buffer. A local attacker can use this flaw to gain an additive 12-byte write primitive in kernel space. With this primitive, it is possible to temporarily disable the Feature_RestrictKernelAddressLeaks mitigation to leak kernel object addresses (KASLR-bypass), and then modify the process token state to escalate privileges to the SYSTEM level. A public PoC is available on GitHub. It was patched in May 2026.

Conclusion

The June 2026 update is an event that requires declaring a state of high alert for IT and InfoSec departments. The massive number of patches, 38 of which are critical, demands the fastest possible deployment, as the window of opportunity for attackers is incredibly wide right now.

Patching priority for June:

  1. Neutralize publicly disclosed threats: First and foremost, you must close the vulnerabilities the whole world already knows about. Apply patches to web servers to protect HTTP.sys from Denial of Service attacks (CVE-2026-49160), update workstations to close the CTFMON flaw (CVE-2026-45586), and prevent the BitLocker bypass (CVE-2026-50507).
  2. Protect network communications (RCE): Critical vulnerabilities in DHCP Client, HTTP.sys (which also has an RCE this month), RDP Client, and Exchange require immediate response. These components are network-facing, and their exploitation will lead to instant system compromise.
  3. Cloud and databases: Owners of hybrid and cloud infrastructures must ensure patches are applied for Azure HorizonDB (CVSS 10.0) and AKS.
  4. Endpoints: Given the abundance of RCEs in Microsoft Office, user workstations must be updated in the shortest possible time to prevent breaches via malicious attachments.

Special attention to the retrospective: The Retrospective Vulnerability Analysis section notes the emergence of public and easily accessible exploits (PoCs) for critical May vulnerabilities: Windows Netlogon, Windows DNS Client, and Windows Kernel. If your infrastructure was not updated last month, it is currently absolutely defenseless against automated hacking scripts that are already lying on GitHub. Eliminating the technical debt from May, combined with installing the June patches, is a matter of survival for the corporate network.

Paranoid Security Microsoft Patch Tuesday Analysis – April 2026 April 14
MS Patch Tuesday Microsoft Patch Tuesday Analysis – April 2026
Paranoid Security Microsoft Patch Tuesday Analysis – March 2026 March 10
MS Patch Tuesday Microsoft Patch Tuesday Analysis – March 2026
Paranoid Security Microsoft Patch Tuesday Analysis – February 2026 February 10
MS Patch Tuesday Microsoft Patch Tuesday Analysis – February 2026