Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed

Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed

3d ago MyabtTenableComputerweeklyCybersecuritynewsIsc.Sans.Edu+33 89% similarity 70.5
Share:

Article Content

Browse articles
ThreatCluster

On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as remote code execution (RCE) vulnerabilities. The update included CVE-2026-47291, an RCE flaw in HTTP.sys, rated CVSS 9.8, and CVE-2026-45586, an elevation of privilege vulnerability in Windows CTFMON. Microsoft confirmed that none of the vulnerabilities are currently exploited in the wild, but the sheer volume of flaws indicates a significant uptick in vulnerability discovery, likely driven by AI tools. The update also featured patches for vulnerabilities affecting various Microsoft products, including Windows, Office, and Azure services. Security professionals are urged to prioritize patching due to the high number of critical vulnerabilities and the potential for exploitation.

Key Points: • Microsoft's June 2026 Patch Tuesday addressed a record 206 vulnerabilities, including three zero-days. • 32 vulnerabilities were classified as critical, with significant RCE flaws like CVE-2026-47291 rated CVSS 9.8. • The increase in vulnerabilities is attributed to AI tools accelerating vulnerability discovery.

ThreatCluster AI

Timeline

2026-04-14
CVE-2026-33825 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-19
CVE-2026-45585 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-20
CVE-2026-45498 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-20
CVE-2026-41091 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-45497 published
A remote code execution vulnerability in Microsoft 365 Copilot was disclosed, rated CVSS 7.7.
Myabt
2026-06-04
CVE-2026-47644 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-42824 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
Public exploit for CVE-2026-49975 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-06-04
CVE-2026-47655 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-48579 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →