Microsoft Patch Tuesday Analysis – June 2026
Executive Summary
On Tuesday, June 09, 2026, Microsoft released its monthly security patch, addressing 204 vulnerabilities across its products.
By severity level:
- Critical - 38;
- Important - 166.
Exploited (Zero-Days) and Publicly Disclosed Vulnerabilities
Special attention should be paid to the following 3 vulnerabilities. Fixing them is the highest priority:
- CVE-2026-45586 (CVSS 7.8; Important) - Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability (Elevation of Privilege). An "incorrect link resolution before file access" vulnerability (CWE-59) in the Windows Collaborative Translation Framework (CTFMON). A local authenticated attacker with low privileges can exploit this issue to manipulate CTF service file operations. By creating symbolic links or NTFS junctions in user-controlled directories, an attacker can redirect file write or delete requests from a highly privileged process to protected system resources, allowing privilege escalation in the system to the SYSTEM level.
- CVE-2026-49160 (CVSS 7.5; Important) - HTTP.sys Denial of Service Vulnerability (Denial of Service). An uncontrolled resource consumption vulnerability (CWE-400) in the HTTP/2 (and HTTP/3) support implementation handled by the HTTP.sys driver. A remote unauthenticated attacker can cause a Denial of Service (DoS) condition on the web server by sending specially crafted network requests with an abnormally large number of headers. To address the vulnerability and provide preemptive protection, Microsoft introduced a new security update that includes the MaxHeadersCount registry parameter (detailed in KB5102602) to strictly limit the number of headers in requests.
- CVE-2026-50507 (CVSS 6.8; Important) - Windows BitLocker Security Feature Bypass Vulnerability (Security Feature Bypass). The vulnerability relates to the lack of authentication for a critical function (CWE-306) in the Windows BitLocker protection mechanism. An attacker with physical access to the target device can exploit this flaw to bypass BitLocker Device Encryption and gain unauthorized access to encrypted sensitive data on the system drive.
General Trends
The June 2026 Patch Tuesday will go down in history as one of the largest and heaviest releases in recent years. Microsoft issued patches for 204 vulnerabilities, of which 38 have a "Critical" status. Such a volume of updates indicates a massive security audit of the OS and cloud platform codebases. Key trends for June:
- Record volume and criticality: Crossing the 200-vulnerability mark makes this month an extreme test for patch management processes in any organization. The presence of nearly 40 critical vulnerabilities (mostly RCE) means that attack vectors are broader than ever.
- Threat of public disclosure: Although no active "in the wild" exploitation has been recorded at the time of the patch release, 3 vulnerabilities were disclosed publicly at once. This gives hackers a huge head start. Of particular concern is HTTP.sys (DoS), as public knowledge of attack methods on the built-in Windows web server threatens massive infrastructure outages. The disclosure of the BitLocker bypass endangers data on corporate laptops if they are lost.
- Network perimeter under massive strike: June has been a catastrophic month for network services. Critical RCE vulnerabilities (CVSS 9.8) were patched in DHCP Client and HTTP.sys, along with a scattering of RCEs in Remote Desktop Client (RDP) and RRAS. Vulnerabilities in such foundational protocols carry the risk of "worms" (self-propagating malware) capable of infecting machines without user interaction.
- Cloud platforms on the edge: This month, a vulnerability with the highest possible rating of CVSS 10.0 in Azure HorizonDB was closed, as well as critical RCEs in Azure Kubernetes Service (AKS) and Azure Stack Edge. This confirms that Microsoft's cloud infrastructure is undergoing deep reverse engineering by researchers and malicious actors.
- Unceasing stream of EoP and Office vulnerabilities: Traditionally, over 70 patches close local Elevation of Privilege (EoP) loopholes (the publicly disclosed vulnerability in CTFMON stands out). Concurrently, Microsoft is patching dozens of RCEs in Microsoft Office, Word, and Exchange, maintaining a high threat level from phishing campaigns.
Full List of Vulnerabilities
Below is a table with all the vulnerabilities patched this month.
| CVE | Title | Type | CVSS | Severity | Exploited | Publicly Disclosed |
|---|---|---|---|---|---|---|
| CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | Yes |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | Denial of Service | 7.5 | Important | No | Yes |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability | Security Feature Bypass | 6.8 | Important | No | Yes |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability | Elevation of Privilege | 10.0 | Critical | No | No |
| CVE-2026-26142 | Nuance PowerScribe Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical | No | No |
| CVE-2026-44815 | DHCP Client Service Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical | No | No |
| CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical | No | No |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical | No | No |
| CVE-2026-47643 | Azure Stack Edge Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Important | No | No |
| CVE-2026-42904 | Windows TCP/IP Elevation of Privilege Vulnerability | Elevation of Privilege | 9.6 | Important | No | No |
| CVE-2026-47281 | Visual Studio Code Elevation of Privilege Vulnerability | Elevation of Privilege | 9.6 | Important | No | No |
| CVE-2026-45602 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability | Tampering | 9.1 | Important | No | No |
| CVE-2026-48579 | Microsoft Exchange Online Information Disclosure Vulnerability | Information Disclosure | 9.1 | Critical | No | No |
| CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical | No | No |
| CVE-2026-40371 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important | No | No |
| CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical | No | No |
| CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important | No | No |
| CVE-2026-45504 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important | No | No |
| CVE-2026-45648 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical | No | No |
| CVE-2026-47289 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical | No | No |
| CVE-2026-47653 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important | No | No |
| CVE-2026-41098 | Azure Stack Edge Spoofing Vulnerability | Spoofing | 8.4 | Important | No | No |
| CVE-2026-44810 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Elevation of Privilege | 8.4 | Critical | No | No |
| CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2026-45482 | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability | Security Feature Bypass | 8.4 | Important | No | No |
| CVE-2026-45607 | Windows Hyper-V Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2026-45641 | Windows Hyper-V Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2026-47635 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical | No | No |
| CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability | Information Disclosure | 8.2 | Important | No | No |
| CVE-2026-45476 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability | Elevation of Privilege | 8.2 | Critical | No | No |
| CVE-2026-47652 | Windows Hyper-V Remote Code Execution Vulnerability | Remote Code Execution | 8.2 | Critical | No | No |
| CVE-2026-42835 | Microsoft Teams for Android Information Disclosure Vulnerability | Information Disclosure | 8.1 | Important | No | No |
| CVE-2026-42974 | Windows Performance Monitor Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Important | No | No |
| CVE-2026-42981 | Windows Performance Monitor Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Important | No | No |
| CVE-2026-42987 | Windows Deployment Services (WDS) Remote Code Execution | Remote Code Execution | 8.1 | Critical | No | No |
| CVE-2026-45503 | Microsoft Exchange Server Information Disclosure Vulnerability | Information Disclosure | 8.1 | Important | No | No |
| CVE-2026-45599 | Windows UPnP Device Host Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Important | No | No |
| CVE-2026-45635 | Windows UPnP Device Host Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Important | No | No |
| CVE-2026-47631 | Microsoft Exchange Server Spoofing Vulnerability | Spoofing | 8.1 | Important | No | No |
| CVE-2026-45644 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability | Elevation of Privilege | 8.0 | Important | No | No |
| CVE-2026-47298 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Remote Code Execution | 8.0 | Important | No | No |
| CVE-2026-45588 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | 7.9 | Important | No | No |
| CVE-2026-45654 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | 7.9 | Important | No | No |
| CVE-2026-47656 | Windows Boot Manager Security Feature Bypass Vulnerability | Security Feature Bypass | 7.9 | Important | No | No |
| CVE-2026-48568 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | 7.9 | Important | No | No |
| CVE-2026-48570 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | 7.9 | Important | No | No |
| CVE-2026-48573 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | 7.9 | Important | No | No |
| CVE-2026-48575 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | 7.9 | Important | No | No |
| CVE-2026-48576 | Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | 7.9 | Important | No | No |
| CVE-2026-48578 | Secure Boot Security Feature Bypass Vulnerability | Elevation of Privilege | 7.9 | Important | No | No |
| CVE-2026-33828 | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Critical | No | No |
| CVE-2026-40404 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-40409 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-41092 | Microsoft Kinect Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42828 | Windows Projected File System Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42829 | Windows Administrator Protection Secure Feature Bypass Vulnerability | Security Feature Bypass | 7.8 | Important | No | No |
| CVE-2026-42837 | Windows Projected File System Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42902 | Microsoft PowerToys Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42910 | Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42916 | NT OS Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42977 | Windows Push Notifications Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42978 | Windows Push Notifications Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42979 | Windows Push Notifications Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42983 | Windows DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-42991 | Windows Push Notifications Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-44802 | Windows DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Critical | No | No |
| CVE-2026-44804 | Windows DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-44807 | Windows DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-44808 | Windows DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-44809 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-44811 | Windows DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Critical | No | No |
| CVE-2026-44813 | Windows DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-45457 | Microsoft Word Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-45486 | Microsoft Word Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-45487 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-45490 | .NET SDK Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-45592 | Windows Internet (wininet.dll) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-45593 | Windows SDK Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-45600 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-45605 | Windows Bluetooth Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-45636 | Windows NTFS Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-45637 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-45638 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-45643 | Microsoft Word Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-45645 | Microsoft Office Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important | No | No |
| CVE-2026-45656 | UEFI Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | 7.8 | Important | No | No |
| CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability | Security Feature Bypass | 7.8 | Important | No | No |
| CVE-2026-47292 | Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-48565 | Windows Narrator Braille Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-48574 | Windows Media Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Critical | No | No |
| CVE-2026-48583 | Windows Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important | No | No |
| CVE-2026-49161 | Microsoft PC Manager Security Feature Bypass Vulnerability | Security Feature Bypass | 7.8 | Important | No | No |
| CVE-2026-45497 | Microsoft M365 Copilot Remote Code Execution Vulnerability | Remote Code Execution | 7.7 | Critical | No | No |
| CVE-2026-40376 | Visual Studio Code Elevation of Privilege Vulnerability | Elevation of Privilege | 7.5 | Important | No | No |
| CVE-2026-42908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Information Disclosure | 7.5 | Important | No | No |
| CVE-2026-42909 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Important | No | No |
| CVE-2026-42913 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Important | No | No |
| CVE-2026-42992 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Critical | No | No |
| CVE-2026-42993 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Important | No | No |
| CVE-2026-44799 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Critical | No | No |
| CVE-2026-44801 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Critical | No | No |
| CVE-2026-45583 | Microsoft Exchange Server Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Important | No | No |
| CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability | Denial of Service | 7.5 | Important | No | No |
| CVE-2026-45639 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Information Disclosure | 7.5 | Important | No | No |
| CVE-2026-47654 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Critical | No | No |
| CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 7.5 | Critical | No | No |
| CVE-2026-45481 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 7.3 | Important | No | No |
| CVE-2026-47634 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 7.3 | Important | No | No |
| CVE-2026-45649 | Office for Android Spoofing Vulnerability | Spoofing | 7.1 | Important | No | No |
| CVE-2026-47288 | Windows Kerberos Key Distribution Center (KDC) Remote Code Execution | Remote Code Execution | 7.1 | Critical | No | No |
| CVE-2026-48569 | Visual Studio Code Security Feature Bypass Vulnerability | Security Feature Bypass | 7.1 | Important | No | No |
| CVE-2026-34335 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-41108 | Windows DNS Client Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-42836 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-42911 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-42912 | Windows Telephony Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-42984 | Windows Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability | Remote Code Execution | 7.0 | Important | No | No |
| CVE-2026-45596 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-45597 | Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-45598 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-45601 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-45603 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-45640 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-45653 | Windows Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-47293 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-47648 | Windows Storage Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | Important | No | No |
| CVE-2026-45608 | Windows DHCP Client Information Disclosure Vulnerability | Information Disclosure | 6.8 | Important | No | No |
| CVE-2026-42824 | M365 Copilot Information Disclosure Vulnerability | Information Disclosure | 6.5 | Critical | No | No |
| CVE-2026-42903 | Windows Kerberos Denial of Service Vulnerability | Denial of Service | 6.5 | Important | No | No |
| CVE-2026-42907 | Windows Shell Information Disclosure Vulnerability | Information Disclosure | 6.5 | Important | No | No |
| CVE-2026-45454 | Microsoft SharePoint Remote Code Execution Vulnerability | Remote Code Execution | 6.5 | Important | No | No |
| CVE-2026-45501 | Microsoft Exchange Server Spoofing Vulnerability | Spoofing | 6.5 | Important | No | No |
| CVE-2026-47284 | Visual Studio Code Information Disclosure Vulnerability | Information Disclosure | 6.5 | Important | No | No |
| CVE-2026-47287 | Visual Studio Code Tampering Vulnerability | Tampering | 6.5 | Important | No | No |
| CVE-2026-47644 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability | Information Disclosure | 6.5 | Critical | No | No |
| CVE-2026-47655 | Microsoft Graph Information Disclosure Vulnerability | Information Disclosure | 6.5 | Critical | No | No |
| CVE-2026-50508 | Windows NTLM Spoofing Vulnerability | Spoofing | 6.5 | Important | No | No |
| CVE-2026-45491 | .NET Tampering Vulnerability | Tampering | 6.2 | Important | No | No |
| CVE-2026-45500 | Microsoft Exchange Server Spoofing Vulnerability | Spoofing | 6.1 | Important | No | No |
| CVE-2026-42915 | Windows TCP/IP Denial of Service Vulnerability | Denial of Service | 5.7 | Important | No | No |
| CVE-2026-42906 | Windows Shell Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-42968 | Windows Telephony Server Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-42969 | Windows Push Notification Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-42970 | Windows Push Notification Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-42971 | Windows Push Notification Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-42972 | Windows Hyper-V Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-42973 | Windows Push Notification Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-44805 | Windows Network Controller (NC) Host Agent Denial of Service Vulnerability | Denial of Service | 5.5 | Important | No | No |
| CVE-2026-44814 | Windows DWM Core Library Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-44821 | Microsoft Office Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-45594 | Windows Application Identity (AppID) Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-45604 | Windows Managed Installer Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-45606 | Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability | Denial of Service | 5.5 | Important | No | No |
| CVE-2026-45634 | Windows DHCP Client Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-45647 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | Elevation of Privilege | 5.5 | Important | No | No |
| CVE-2026-48566 | Windows DWM Core Library Information Disclosure Vulnerability | Information Disclosure | 5.5 | Important | No | No |
| CVE-2026-33113 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 5.4 | Important | No | No |
| CVE-2026-45453 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 5.4 | Important | No | No |
| CVE-2026-45464 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 5.4 | Important | No | No |
| CVE-2026-45465 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 5.4 | Important | No | No |
| CVE-2026-45595 | Windows Mark of the Web Security Feature Bypass Vulnerability | Security Feature Bypass | 5.4 | Important | No | No |
| CVE-2026-47636 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 5.4 | Important | No | No |
| CVE-2026-47639 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 5.4 | Important | No | No |
| CVE-2026-48560 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 5.4 | Important | No | No |
| CVE-2026-42914 | Windows Kerberos Denial of Service Vulnerability | Denial of Service | 5.3 | Important | No | No |
| CVE-2026-45655 | Windows BitLocker Security Feature Bypass Vulnerability | Security Feature Bypass | 5.3 | Important | No | No |
| CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability | Information Disclosure | 5.0 | Important | No | No |
| CVE-2026-45460 | Microsoft Office Information Disclosure Vulnerability | Information Disclosure | 4.7 | Critical | No | No |
| CVE-2026-45462 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 4.6 | Important | No | No |
| CVE-2026-45467 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 4.6 | Important | No | No |
| CVE-2026-45468 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 4.6 | Important | No | No |
| CVE-2026-45479 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 4.6 | Important | No | No |
| CVE-2026-45483 | Microsoft Office Project Server Spoofing Vulnerability | Spoofing | 4.6 | Important | No | No |
| CVE-2026-47637 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 4.6 | Important | No | No |
| CVE-2026-47638 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 4.6 | Important | No | No |
| CVE-2026-47640 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 4.6 | Important | No | No |
| CVE-2026-47641 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 4.6 | Important | No | No |
| CVE-2026-48562 | Microsoft SharePoint Server Spoofing Vulnerability | Spoofing | 4.6 | Important | No | No |
| CVE-2026-45650 | Microsoft Bing Search Spoofing Vulnerability | Spoofing | 4.3 | Important | No | No |
| CVE-2026-45642 | Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability | Spoofing | 3.9 | Important | No | No |
| CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability | Information Disclosure | 3.3 | Important | No | No |
| CVE-2026-45459 | Microsoft Excel Security Feature Bypass Vulnerability | Security Feature Bypass | 3.3 | Important | No | No |
| CVE-2026-45466 | Microsoft Word Information Disclosure Vulnerability | Information Disclosure | 3.3 | Important | No | No |
| CVE-2026-45485 | Microsoft Office Information Disclosure Vulnerability | Information Disclosure | 3.3 | Important | No | No |
Retrospective Vulnerability Analysis
CVE-2026-24294 — Windows SMB Server Elevation of Privilege Vulnerability (Elevation of Privilege). This vulnerability is a logical bypass of the patches for CVE-2025-33073 and allows a local attacker to escalate their privileges to the SYSTEM level. Researcher Guillaume André demonstrated that using a new Windows feature (selecting an arbitrary TCP port for SMB connections) allows forcing a privileged service (e.g., LSASS) to authenticate to a controlled local port. This enables an NTLM reflection attack, forwarding the authentication token back to the system's legitimate SMB server. The vulnerability was patched in March 2026.
CVE-2026-41089 — Windows Netlogon Remote Code Execution Vulnerability (Remote Code Execution). The vulnerability is a stack-based buffer overflow in the Netlogon service. An unauthenticated attacker can remotely send a specially crafted CLDAP request (UDP port 389) to the domain controller with an excessively long username. Due to incorrect handling of Unicode string sizes in the NetpLogonPutUnicodeString function, an out-of-bounds write occurs in the allocated stack buffer. This leads to the crash of the LSASS process and a forced reboot of the domain controller (Denial of Service), and potentially allows for arbitrary code execution. A PoC is available for this vulnerability. It was patched in May 2026.
CVE-2026-41096 — Windows DNS Client Remote Code Execution Vulnerability (Remote Code Execution). The vulnerability is a heap-based buffer overflow in the Windows DNS client that occurs when processing malformed DNS responses. The error happens in the dnsapi.dll library (in the DnsRawTruncateMessageForUdp() function) when parsing the structure of an incoming packet received via the DnsQueryRaw() interface. An attacker can cause a crash or execute arbitrary code without authentication by sending a specially crafted response (e.g., containing zero QDCOUNT queries and a large OPT record). A client-side PoC is available to verify the vulnerability, which triggers a process crash if unpatched. It was patched in May 2026.
CVE-2026-40369 — Windows Kernel Elevation of Privilege Vulnerability (Elevation of Privilege). An "untrusted pointer dereference" vulnerability (CWE-822) in the NtQuerySystemInformation system call (class 253), arising from improper handling of a zero-length buffer. A local attacker can use this flaw to gain an additive 12-byte write primitive in kernel space. With this primitive, it is possible to temporarily disable the Feature_RestrictKernelAddressLeaks mitigation to leak kernel object addresses (KASLR-bypass), and then modify the process token state to escalate privileges to the SYSTEM level. A public PoC is available on GitHub. It was patched in May 2026.
Conclusion
The June 2026 update is an event that requires declaring a state of high alert for IT and InfoSec departments. The massive number of patches, 38 of which are critical, demands the fastest possible deployment, as the window of opportunity for attackers is incredibly wide right now.
Patching priority for June:
- Neutralize publicly disclosed threats: First and foremost, you must close the vulnerabilities the whole world already knows about. Apply patches to web servers to protect HTTP.sys from Denial of Service attacks (CVE-2026-49160), update workstations to close the CTFMON flaw (CVE-2026-45586), and prevent the BitLocker bypass (CVE-2026-50507).
- Protect network communications (RCE): Critical vulnerabilities in DHCP Client, HTTP.sys (which also has an RCE this month), RDP Client, and Exchange require immediate response. These components are network-facing, and their exploitation will lead to instant system compromise.
- Cloud and databases: Owners of hybrid and cloud infrastructures must ensure patches are applied for Azure HorizonDB (CVSS 10.0) and AKS.
- Endpoints: Given the abundance of RCEs in Microsoft Office, user workstations must be updated in the shortest possible time to prevent breaches via malicious attachments.
Special attention to the retrospective: The Retrospective Vulnerability Analysis section notes the emergence of public and easily accessible exploits (PoCs) for critical May vulnerabilities: Windows Netlogon, Windows DNS Client, and Windows Kernel. If your infrastructure was not updated last month, it is currently absolutely defenseless against automated hacking scripts that are already lying on GitHub. Eliminating the technical debt from May, combined with installing the June patches, is a matter of survival for the corporate network.