Myabt Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
Article Content
- •Microsoft's June 2026 Patch Tuesday addressed a record 206 vulnerabilities, including three zero-days.
- •32 vulnerabilities were classified as critical, with significant RCE flaws like CVE-2026-47291 rated CVSS 9.8.
- •The increase in vulnerabilities is attributed to AI tools accelerating vulnerability discovery.
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as remote code execution (RCE) vulnerabilities. The update included CVE-2026-47291, an RCE flaw in HTTP.sys, rated CVSS 9.8, and CVE-2026-45586, an elevation of privilege vulnerability in Windows CTFMON. Microsoft confirmed that none of the vulnerabilities are currently exploited in the wild, but the sheer volume of flaws indicates a significant uptick in vulnerability discovery, likely driven by AI tools. The update also featured patches for vulnerabilities affecting various Microsoft products, including Windows, Office, and Azure services. Security professionals are urged to prioritize patching due to the high number of critical vulnerabilities and the potential for exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (57)
Following this threat?
Track WannaCry, Chaotic Eclipse and Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing significant risks to…
Unisoc Modem Vulnerability Allows Remote Code Execution via Video Calls Researchers have discovered a critical vulnerability in Unisoc modem firmware that allows attackers to gain root access to various Android devices through a video call exploit. This vulnerability affects multiple budget smartphones powered by Unisoc chipsets, including the Realme C33, Xiaomi Redmi A5, and Motorola…