Microsoft Patches 198 Vulnerabilities in June 2026 Security Update

Microsoft has released its June 2026 Patch Tuesday security update, addressing 198 vulnerabilities across its product ecosystem, one of the largest single-month patches in recent memory.

The update includes fixes for 3 zero-day vulnerabilities that were publicly disclosed before patching, along with 32 Critical-severity flaws and 166 Important-severity issues requiring immediate attention from administrators and end users.

Impact TypeCount
Elevation of Privilege63
Remote Code Execution54
Spoofing29
Information Disclosure26
Security Feature Bypass18
Denial of Service7
Tampering3

Microsoft Patch Tuesday June 2026

Three publicly disclosed zero-days headline this month’s release, all rated Important in severity:

  • CVE-2026-50507 – Windows BitLocker Security Feature Bypass Vulnerability: A publicly disclosed flaw in Windows BitLocker that allows an attacker to bypass the drive encryption security feature. This is particularly concerning for organizations relying on BitLocker for data-at-rest protection on endpoint devices.
  • CVE-2026-49160 – HTTP.sys Denial of Service Vulnerability: A publicly disclosed vulnerability in the HTTP/2 stack (HTTP.sys) that could allow an unauthenticated attacker to crash or destabilize Windows web servers. Organizations running IIS or any HTTP.sys-dependent services should treat this patch as high-priority.
  • CVE-2026-45586 – (Zero-day #3): This vulnerability rounds out the trio of zero-days addressed in this month’s update and requires immediate customer action per Microsoft’s advisory.

Among the 32 Critical-rated vulnerabilities, Remote Code Execution (RCE) flaws dominate with 54 RCE issues total across all severities.

CVE-2026-47652 – Windows Hyper-V RCE is a critical flaw enabling remote code execution within Hyper-V hypervisor environments, posing severe risk to virtualized infrastructure.

CVE-2026-47288 – Windows Kerberos KDC RCE targets the Kerberos Key Distribution Center and could allow attackers to execute code against domain authentication infrastructure a worst-case scenario for Active Directory environments.

CVE-2026-47291 – HTTP.sys RCE represents a separate critical RCE in Windows HTTP.sys, distinct from the zero-day DoS variant, enabling potential pre-authentication remote code execution on exposed servers. 

CVE-2026-45648 – Active Directory Domain Services RCE is a critical flaw that could allow attackers to execute code on domain controllers, making it a top-priority patch for all enterprise environments.

Beyond the Windows core, this update spans a wide range of Microsoft products. SharePoint Server received patches for at least 10 spoofing vulnerabilities across CVE-2026-47636 through CVE-2026-48562. 

Remote Desktop Client was patched for multiple Critical and Important RCE flaws, including CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, CVE-2026-42992, and CVE-2026-47654. 

Windows Secure Boot received a cluster of Security Feature Bypass fixes, and Visual Studio Code was addressed for elevation-of-privilege, information-disclosure, and tampering vulnerabilities.

Here is the complete table of all 198 CVEs from the June 2026 Patch

CVETitleSeverityImpactProduct
CVE-2026-50507Windows BitLocker Security Feature BypassImportantSecurity Feature BypassWindows BitLocker
CVE-2026-49160HTTP.sys Denial of ServiceImportantDenial of ServiceHTTP/2
CVE-2026-45586Windows Collaborative Translation Framework (CTFMON) EoPImportantElevation of PrivilegeWindows CTFMON
CVE-2026-50508Windows NTLM SpoofingImportantSpoofingWindows NTLM
CVE-2026-49161Microsoft PC Manager Security Feature BypassImportantSecurity Feature BypassMicrosoft PC Manager
CVE-2026-48583Windows Kernel Elevation of PrivilegeImportantElevation of PrivilegeWindows Kernel
CVE-2026-48578Secure Boot Security Feature BypassImportantElevation of PrivilegeWindows Secure Boot
CVE-2026-48576Secure Boot Security Feature BypassImportantSecurity Feature BypassWindows Secure Boot
CVE-2026-48575Secure Boot Security Feature BypassImportantSecurity Feature BypassWindows Secure Boot
CVE-2026-48574Windows Media Remote Code ExecutionCriticalRemote Code ExecutionWindows Media
CVE-2026-48573Secure Boot Security Feature BypassImportantSecurity Feature BypassWindows Secure Boot
CVE-2026-48570Secure Boot Security Feature BypassImportantSecurity Feature BypassWindows Secure Boot
CVE-2026-48569Visual Studio Code Security Feature BypassImportantSecurity Feature BypassVisual Studio Code
CVE-2026-48568Secure Boot Security Feature BypassImportantSecurity Feature BypassWindows Secure Boot
CVE-2026-48566Windows DWM Core Library Information DisclosureImportantInformation DisclosureWindows DWM Core Library
CVE-2026-48565Windows Narrator Braille Elevation of PrivilegeImportantElevation of PrivilegeWindows Narrator Braille
CVE-2026-48563Remote Desktop Client RCECriticalRemote Code ExecutionRemote Desktop Client
CVE-2026-48562Microsoft SharePoint Server SpoofingImportantSpoofingMicrosoft Office SharePoint
CVE-2026-48560Microsoft SharePoint Server SpoofingImportantSpoofingMicrosoft Office SharePoint
CVE-2026-47656Windows Boot Manager Security Feature BypassImportantSecurity Feature BypassWindows Boot Manager
CVE-2026-47654Remote Desktop Client RCECriticalRemote Code ExecutionRemote Desktop Client
CVE-2026-47653Remote Desktop Client RCEImportantRemote Code ExecutionRemote Desktop Client
CVE-2026-47652Windows Hyper-V RCECriticalRemote Code ExecutionWindows Hyper-V
CVE-2026-47648Windows Storage Elevation of PrivilegeImportantElevation of PrivilegeWindows Storage
CVE-2026-47643Azure Stack Edge RCEImportantRemote Code ExecutionAzure Stack Edge
CVE-2026-47641Microsoft SharePoint Server SpoofingImportantSpoofingMicrosoft Office SharePoint
CVE-2026-47640Microsoft SharePoint Server SpoofingImportantSpoofingMicrosoft Office SharePoint
CVE-2026-47639Microsoft SharePoint Server SpoofingImportantSpoofingMicrosoft Office SharePoint
CVE-2026-47638Microsoft SharePoint Server SpoofingImportantSpoofingMicrosoft Office SharePoint
CVE-2026-47637Microsoft SharePoint Server SpoofingImportantSpoofingMicrosoft Office SharePoint
CVE-2026-47636Microsoft SharePoint Server SpoofingImportantSpoofingMicrosoft Office SharePoint
CVE-2026-47635Microsoft Outlook and Word RCECriticalRemote Code ExecutionMicrosoft Office
CVE-2026-47634Microsoft SharePoint Server SpoofingImportantSpoofingMicrosoft Office SharePoint
CVE-2026-47631Microsoft Exchange Server SpoofingImportantSpoofingMicrosoft Exchange Server
CVE-2026-47298Microsoft SharePoint Server RCEImportantRemote Code ExecutionMicrosoft Office SharePoint
CVE-2026-47293Microsoft Office Click-To-Run EoPImportantElevation of PrivilegeMicrosoft Office Click-To-Run
CVE-2026-47292Visual Studio Code MSSQL Extension RCEImportantElevation of PrivilegeVisual Studio Code
CVE-2026-47291HTTP.sys Remote Code ExecutionCriticalRemote Code ExecutionWindows HTTP.sys
CVE-2026-47289Remote Desktop Client RCECriticalRemote Code ExecutionRemote Desktop Client
CVE-2026-47288Windows Kerberos KDC RCECriticalRemote Code ExecutionWindows Kerberos
CVE-2026-47287Visual Studio Code TamperingImportantTamperingVisual Studio Code
CVE-2026-47284Visual Studio Code Information DisclosureImportantInformation DisclosureVisual Studio Code
CVE-2026-47281Visual Studio Code Elevation of PrivilegeImportantElevation of PrivilegeVisual Studio Code
CVE-2026-45658Windows BitLocker Security Feature BypassImportantSecurity Feature BypassWindows BitLocker
CVE-2026-45657Windows Kernel RCECriticalRemote Code ExecutionWindows Kernel
CVE-2026-45656UEFI Secure Boot Security Feature BypassImportantSecurity Feature BypassWindows UEFI
CVE-2026-45655Windows BitLocker Security Feature BypassImportantSecurity Feature BypassWindows BitLocker
CVE-2026-45654Secure Boot Security Feature BypassImportantSecurity Feature BypassWindows Secure Boot
CVE-2026-45653Windows Kernel Elevation of PrivilegeImportantElevation of PrivilegeWindows Kernel
CVE-2026-45650Microsoft Bing Search SpoofingImportantSpoofingMicrosoft Bing
CVE-2026-45649Office for Android SpoofingImportantSpoofingOffice for Android
CVE-2026-45648Windows Active Directory Domain Services RCECriticalRemote Code ExecutionActive Directory Domain Services
CVE-2026-45647Microsoft Defender for Endpoint for Mac EoPImportantElevation of PrivilegeMicrosoft Defender for Endpoint
CVE-2026-45645Microsoft Office RCEImportantRemote Code ExecutionMicrosoft Office
CVE-2026-45644Microsoft Live Share Canvas SDK EoPImportantElevation of PrivilegeMicrosoft Live Share Canvas SDK
CVE-2026-45643Microsoft Word RCEImportantRemote Code ExecutionMicrosoft Office Word
CVE-2026-45642Microsoft Azure Attestation Service SpoofingImportantSpoofingAzure Attestation Service
CVE-2026-44804Windows DWM Core Library EoPImportantElevation of PrivilegeWindows DWM Core Library
CVE-2026-44803Windows Graphics Component RCECriticalRemote Code ExecutionWindows Win32K – GRFX
CVE-2026-44802Windows DWM Core Library EoPImportantElevation of PrivilegeWindows DWM Core Library
CVE-2026-44801Remote Desktop Client RCECriticalRemote Code ExecutionRemote Desktop Client
CVE-2026-44799Remote Desktop Client RCECriticalRemote Code ExecutionRemote Desktop Client
CVE-2026-42993Remote Desktop Client RCEImportantRemote Code ExecutionRemote Desktop Client
CVE-2026-42992Remote Desktop Client RCECriticalRemote Code ExecutionRemote Desktop Client
CVE-2026-42991Windows Push Notifications EoPImportantElevation of PrivilegeWindows Push Notifications
CVE-2026-42989Winlogon Elevation of PrivilegeImportantElevation of PrivilegeWinlogon
CVE-2026-42987Windows Deployment Services (WDS) RCECriticalRemote Code ExecutionWindows Deployment Services
CVE-2026-42986Microsoft Graphics Component EoPImportantElevation of PrivilegeMicrosoft Graphics Component
CVE-2026-42985Remote Desktop Client RCECriticalRemote Code ExecutionRemote Desktop Client
CVE-2026-42984Windows Kernel Elevation of PrivilegeImportantElevation of PrivilegeWindows Kernel
CVE-2026-42983Windows DWM Core Library EoPImportantElevation of PrivilegeWindows DWM Core Library
CVE-2026-42981Windows Performance Monitor RCEImportantRemote Code ExecutionWindows Performance Monitor
CVE-2026-42980NT OS Kernel Elevation of PrivilegeImportantElevation of PrivilegeWindows NT OS Kernel
CVE-2026-42979Windows Push Notifications EoPImportantElevation of PrivilegeWindows Push Notifications
CVE-2026-42978Windows Push Notifications EoPImportantElevation of PrivilegeWindows Push Notifications
CVE-2026-42977Windows Push Notifications EoPImportantElevation of PrivilegeWindows Push Notifications
CVE-2026-42974Windows Performance Monitor RCEImportantRemote Code ExecutionWindows Performance Monitor
CVE-2026-42973Windows Push Notification Information DisclosureImportantInformation DisclosureWindows Push Notifications
CVE-2026-42972Windows Hyper-V Information DisclosureImportantInformation DisclosureWindows Hyper-V
CVE-2026-42971Windows Push Notification Information DisclosureImportantInformation DisclosureWindows Push Notifications
CVE-2026-42970Windows Push Notification Information DisclosureImportantInformation DisclosureWindows Push Notifications
CVE-2026-42969Windows Push Notification Information DisclosureImportantInformation DisclosureWindows Push Notifications
CVE-2026-42968Windows Telephony Server Information DisclosureImportantInformation DisclosureWindows Telephony Service
CVE-2026-42916NT OS Kernel Elevation of PrivilegeImportantElevation of PrivilegeWindows NT OS Kernel
CVE-2026-42915Windows TCP/IP Denial of ServiceImportantDenial of ServiceWindows TCP/IP

Organizations should apply the June 2026 cumulative updates as soon as possible. The combination of publicly disclosed zero-days and a high volume of Critical RCE vulnerabilities makes this Patch Tuesday one of the most consequential of the year.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories