You didn’t have any other work plans in June, did you? Microsoft on Tuesday released 209 patches affecting 24 product families. Thirty-eight of the addressed issues are considered by Microsoft to be of Critical severity, and 16 of those are expected to be exploited within the next 30 days. An additional CVE, related to the Chaotic Eclipse (aka Nightmare Eclipse) disclosures of the previous weeks, already is. Forty-two have a CVSS base score of 8.0 or higher. Four were publicly disclosed as of release day and just one is acknowledged to be under active exploit in the wild. The numbers in the previous sentence are somewhat confusing in light of (again) the Chaotic Eclipse affair, as we’ll discuss further below.
If the patch count sounds daunting, try the advisory count – 388 of them. As ever, the majority are Edge-related, assigned by Chrome, and patched days in advance of Patch Tuesday. Twenty-three, affecting Adobe Reader and ColdFusion, were issued by Adobe. Two more affect Windows but were issued by CNAs other than Microsoft (specifically, CERT/CC and Arm Limited). As always, we cover all advisories in Appendix D.
Various of this month’s issues are amenable to direct detection by Sophos protections, and we include information on those in the usual table below. These protections include a variety of items targeting the ongoing Chaotic Eclipse vulnerabilities – and, because that situation is volatile as of this writing, we caution that the list in that Sophos Protections section may not reflect all protections we are delivering to customers.
We are as always including at the end of this post appendices listing all Microsoft’s patches sorted by severity (Appendix A), by predicted exploitability timeline and CVSS Base score (Appendix B), and by product family (Appendix C). Appendix D lists this month’s advisories. Appendix E provides a breakout of 114 CVEs affecting various versions of Windows Server, including one advisory from CERT/CC that is otherwise not counted in the patch totals for the month. Our analysis of CWE (Common Weakness Enumeration) information made available for this month’s patches appears in Appendix F.
By the numbers
- Total CVEs: 209
- Publicly disclosed: 4
- Exploit detected: 1
- Severity
- Critical: 38
- Important: 172
- Impact:
- Denial of Service: 7
- Elevation of Privilege: 68
- Information Disclosure: 30
- Remote Code Execution: 55
- Spoofing: 27
- Security Feature Bypass: 19
- Tampering: 3
- CVSS base score 9.0 or greater: 10
- CVSS base score 8.0 or greater: 42

Figure 1: Amid the chaos of June’s Patch Tuesday, Security Feature Bypass and Spoofing are having a moment, while Denial of Service continues to lag
Products
- .NET: 3
- ASP.NET: 1
- 365: 29
- Azure: 5
- Bing Search for Android: 1
- Defender: 1
- Dynamics 365: 1
- Edge / Copilot Chat: 1
- Excel: 10
- Exchange: 8
- Live Share Canvas SDK: 1
- Dynamics 365: 1
- Edge / Copilot: 1
- Microsoft Graph: 1
- Microsoft Live Share Canvas SDK: 1
- MMPC*: 1
- Nuance PowerScribe: 1
- Office: 28
- PC Manager: 3
- PowerPoint: 3
- PowerToys: 1
- SharePoint: 30
- Teams for Android: 1
- Visual Studio: 8
- Windows: 119
- Windows Narrator Braille: 1
- Word: 10
* It is unclear from context why this CVE is assigned to MMPC rather than Defender, but we leave it as presented to us.
As is our custom for this list, CVEs that apply to more than one product family are counted once for each family they affect. We note, by the way, that CVE names don’t always reflect affected product families closely. In particular, some CVEs names in the Office family may mention products that don’t appear in the list of products affected by the CVE, and vice versa.

Figure 2: Twenty-four families show up in June’s Patch Tuesday count, including some unusual sightings such as Windows Narrator Braille, which users can easily patch by updating the feature through the Settings → Accessibility → Narrator → Use Braille display → Download BRLTTY menu. Windows, of course, continues to run the game.

Figure 3: We are halfway through the year, three months (more or less) into the AI Bug-Hunting Era, and dangerously low on colored pixels with which to make this chart
Notable June updates
In addition to the issues discussed above, a few items merit general attention.
CVE-2020-17103 – Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-41091 – Microsoft Defender Elevation of Privilege Vulnerability
CVE-2026-45585 – Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-45586 – Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
Microsoft connects these four CVEs to specific items disclosed by the Chaotic Eclipse researcher earlier this month – respectively, these touch MiniPlasma, RedSun, YellowKey, and GreenPlasma. All are Important-severity issues, and Microsoft judges two of them (CVE-2026-45585, CVE-2026-45586) as more likely to be exploited within the next 30 days; in fact, CVE-2026-45585 is already known to be exploited in the wild. Sharp eyes will notice that one of these bugs is much, much, much older than the others – CVE-2020-17103 was indeed patched back in December 2020 after a responsible disclosure by Google Project Zero’s James Forshaw. To address issues recently uncovered in that patch, Microsoft recommends applying the new update – but will continue to credit Forshaw with the original find.
CVE-2026-44812 – Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-45456 – Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-45458 – Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-45460 – Microsoft Office Information Disclosure Vulnerability
CVE-2026-45461 – Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45463 – Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45472 – Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45474 – Microsoft Office Remote Code Execution Vulnerability
CVE-2026-47635 – Microsoft Outlook and Word Remote Code Execution Vulnerability
All nine of these CVEs have a working vector in Preview Pane and should thus be prioritized – but one of them is unusual. CVE-2026-44812 (more about this one in a minute) can be triggered by viewing in the File Explorer Preview Pane rather than the usual Outlook. All are Critical-severity, but only CVE-2026-44812 is predicted to be exploited in the next 30 days. Speaking of that CVE…
CVE-2026-44803 – Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-44812 – Windows Graphics Component Remote Code Execution Vulnerability
Here’s something else you don’t see every month: A CVE that affects both Windows itself and various Office components – Excel, PowerPoint, Word. (And now the File Explorer aspect of CVE-2026-44812 makes more sense, right?) These are both Critical-severity integer overflow / wraparound bugs that Microsoft deems more likely to be exploited within the next 30 days, so they’re worth prioritizing.
28 CVEs – Exchange and SharePoint issues
Two of the toughest Microsoft products to update are, as many observers know, usually managed in groups during what we used to know as “quieter” months, unless of course something was on fire. In 2026, the largest CVE release in history includes over two dozen patches for Exchange or SharePoint. The good news, if there is any, is that only two of the SharePoint issues (CVE-2026-45456, CVE-2026-45458) are Critical-severity, and only two of the Exchange issues (CVE-2026-45481, CVE-2026-47634) are judged by Microsoft as more likely to be exploited within the next 30 days. It’s something at least.
CVE-2026-41092 – Microsoft Kinect Elevation of Privilege Vulnerability
With a CVSS base score of 7.8 and a ruling that it’s less likely to be exploited in the next 30 days, this patch, which affects all supported Windows client and server versions, probably won’t trouble your sleep – but it may make you nostalgic for your ancient Kinect games.
Sophos protections
| CVE | Sophos Intercept X/Endpoint IPS | Sophos XGS Firewall |
| CVE-2020-17103 | Troj/MiPlasma-A | Troj/MiPlasma-A |
| CVE-2026-41091 | ATK/RedSun-A | ATK/RedSun-A |
| CVE-2026-42791 | sid:2312591, sid:2312588 | sid:2312591, sid:2312588 |
| CVE-2026-42905 | Exp/2642905-A | Exp/2642905-A |
| CVE-2026-42980 | Exp/2642980-A | Exp/2642980-A |
| CVE-2026-42986 | Exp/2642986-A | Exp/2642986-A |
| CVE-2026-42989 | Exp/2642989-A | Exp/2642989-A |
| CVE-2026-45585 | Troj/YellowKy-A | Troj/YellowKy-A |
| CVE-2026-45586 | Exp/2645586-A, Troj/GrPlasma-A | Exp/2645586-A, Troj/GrPlasma-A |
| CVE-2026-49160 | Exp/2649160-A | Exp/2649160-A |
As noted above, we caution readers that due to volatility around certain disclosure-related issues, the table above may or may not reflect all protections currently in place.
As you can every month, if you don’t want to wait for your system to pull down Microsoft’s updates itself, you can download them manually from the Windows Update Catalog website. Run the winver.exe tool to determine which build of Windows you’re running, then download the Cumulative Update package for your specific system’s architecture and build number.
Appendix A: Vulnerability Impact and Severity
This is a list of June patches sorted by impact, then sub-sorted by severity. Each list is further arranged by CVE.
Elevation of Privilege (68 CVEs)
| Critical severity | |
| CVE-2026-33828 | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability |
| CVE-2026-44810 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability |
| Important severity | |
| CVE-2020-17103 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-34335 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-40371 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability |
| CVE-2026-40376 | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-40404 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-40409 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability |
| CVE-2026-41092 | Microsoft Kinect Elevation of Privilege Vulnerability |
| CVE-2026-41108 | Windows DNS Client Elevation of Privilege Vulnerability |
| CVE-2026-42828 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-42836 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
| CVE-2026-42837 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-42902 | Microsoft PowerToys Elevation of Privilege Vulnerability |
| CVE-2026-42904 | Windows TCP/IP Elevation of Privilege Vulnerability |
| CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-42910 | Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability |
| CVE-2026-42911 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-42912 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-42916 | NT OS Kernel Elevation of Privilege Vulnerability |
| CVE-2026-42977 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42978 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42979 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability |
| CVE-2026-42983 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-42984 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability |
| CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability |
| CVE-2026-42991 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-44802 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44804 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44807 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44808 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44809 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-44811 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44813 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-45476 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability |
| CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-45487 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
| CVE-2026-45490 | .NET SDK Elevation of Privilege Vulnerability |
| CVE-2026-45504 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability |
| CVE-2026-45592 | Windows Internet (wininet.dll) Elevation of Privilege Vulnerability |
| CVE-2026-45593 | Windows SDK Elevation of Privilege Vulnerability |
| CVE-2026-45596 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45597 | Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability |
| CVE-2026-45598 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45600 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-45601 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45603 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45605 | Windows Bluetooth Service Elevation of Privilege Vulnerability |
| CVE-2026-45637 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-45638 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45640 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability |
| CVE-2026-45644 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability |
| CVE-2026-45647 | Microsoft Defender Elevation of Privilege Vulnerability |
| CVE-2026-45653 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-47281 | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-47292 | Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability |
| CVE-2026-47293 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
| CVE-2026-47648 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-48565 | Windows Narrator Braille Elevation of Privilege Vulnerability |
| CVE-2026-48578 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48583 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50511 | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-50512 | Microsoft PC Manager Elevation of Privilege Vulnerability |
Remote Code Execution (55 CVEs)
| Critical severity | |
| CVE-2026-26142 | Nuance PowerScribe Remote Code Execution Vulnerability |
| CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability |
| CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42987 | Windows Deployment Services (WDS) Remote Code Execution |
| CVE-2026-42992 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44799 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44801 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44815 | DHCP Client Service Remote Code Execution Vulnerability |
| CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45497 | Microsoft M365 Copilot Remote Code Execution Vulnerability |
| CVE-2026-45607 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-45641 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-45648 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability |
| CVE-2026-47288 | Windows Kerberos Key Distribution Center (KDC) Remote Code Execution |
| CVE-2026-47289 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability |
| CVE-2026-47635 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-47652 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-47654 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-48574 | Windows Media Remote Code Execution Vulnerability |
| Important severity | |
| CVE-2026-42909 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42913 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42974 | Windows Performance Monitor Remote Code Execution Vulnerability |
| CVE-2026-42981 | Windows Performance Monitor Remote Code Execution Vulnerability |
| CVE-2026-42993 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45454 | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-45457 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45486 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45583 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-45599 | Windows UPnP Device Host Remote Code Execution Vulnerability |
| CVE-2026-45635 | Windows UPnP Device Host Remote Code Execution Vulnerability |
| CVE-2026-45636 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-45643 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45645 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-47298 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-47643 | Azure Stack Edge Remote Code Execution Vulnerability |
| CVE-2026-47653 | Remote Desktop Client Remote Code Execution Vulnerability |
Information Disclosure (30 CVEs)
| Critical severity | |
| CVE-2026-42824 | M365 Copilot Information Disclosure Vulnerability |
| CVE-2026-45460 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-47644 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability |
| CVE-2026-47655 | Microsoft Graph Information Disclosure Vulnerability |
| CVE-2026-48579 | Microsoft Exchange Online Information Disclosure Vulnerability |
| Important severity | |
| CVE-2026-42835 | Microsoft Teams for Android Information Disclosure Vulnerability |
| CVE-2026-42906 | Windows Shell Information Disclosure Vulnerability |
| CVE-2026-42907 | Windows Shell Information Disclosure Vulnerability |
| CVE-2026-42908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-42968 | Windows Telephony Server Information Disclosure Vulnerability |
| CVE-2026-42969 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42970 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42971 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42972 | Windows Hyper-V Information Disclosure Vulnerability |
| CVE-2026-42973 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-44814 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-44821 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-45466 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-45485 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2026-45503 | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2026-45594 | Windows Application Identity (AppID) Information Disclosure Vulnerability |
| CVE-2026-45604 | Windows Managed Installer Information Disclosure Vulnerability |
| CVE-2026-45608 | Windows DHCP Client Information Disclosure Vulnerability |
| CVE-2026-45634 | Windows DHCP Client Information Disclosure Vulnerability |
| CVE-2026-45639 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-47284 | Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-48566 | Windows DWM Core Library Information Disclosure Vulnerability |
Spoofing (27 CVEs)
| Important severity | |
| CVE-2026-33113 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-41098 | Azure Stack Edge Spoofing Vulnerability |
| CVE-2026-45453 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45462 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45464 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45465 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45467 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45468 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45479 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45481 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45483 | Microsoft Office Project Server Spoofing Vulnerability |
| CVE-2026-45500 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-45501 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-45642 | Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability |
| CVE-2026-45649 | Office for Android Spoofing Vulnerability |
| CVE-2026-45650 | Microsoft Bing Search Spoofing Vulnerability |
| CVE-2026-47631 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-47634 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47636 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47637 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47638 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47639 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47640 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47641 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-48560 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-48562 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-50508 | Windows NTLM Spoofing Vulnerability |
Security Feature Bypass (19 CVEs)
| Important severity | |
| CVE-2026-42829 | Windows Administrator Protection Secure Feature Bypass Vulnerability |
| CVE-2026-45459 | Microsoft Excel Security Feature Bypass Vulnerability |
| CVE-2026-45482 | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability |
| CVE-2026-45585 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-45588 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-45595 | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2026-45654 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-45655 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-45656 | UEFI Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-47656 | Windows Boot Manager Security Feature Bypass Vulnerability |
| CVE-2026-48568 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48569 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-48570 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48573 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48575 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48576 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-49161 | Microsoft PC Manager Security Feature Bypass Vulnerability |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability |
Denial of Service (7 CVEs)
| Important severity | |
| CVE-2026-42903 | Windows Kerberos Denial of Service Vulnerability |
| CVE-2026-42914 | Windows Kerberos Denial of Service Vulnerability |
| CVE-2026-42915 | Windows TCP/IP Denial of Service Vulnerability |
| CVE-2026-44805 | Windows Network Controller (NC) Host Agent Denial of Service Vulnerability |
| CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-45606 | Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability |
Tampering (3 CVEs)
| Important severity | |
| CVE-2026-45491 | .NET Tampering Vulnerability |
| CVE-2026-45602 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability |
| CVE-2026-47287 | Visual Studio Code Tampering Vulnerability |
Appendix B: Exploitability and CVSS
This is a list of the 16 June CVEs judged by Microsoft to be more likely to be exploited in the wild within the first 30 days post-release, as well as the single CVE acknowledged as already under attack. The list is arranged by CVE.
| Exploitation detected | |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability |
| Exploitation more likely in the next 30 days | |
| CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability |
| CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability |
| CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-45481 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45585 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability |
| CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability |
| CVE-2026-47634 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-50508 | Windows NTLM Spoofing Vulnerability |
These are the June CVEs with a Microsoft-assessed CVSS Base score of 8.0 or higher. They are arranged by score and further sorted by CVE. (Please note that the 10.0-scoerd Azure issue noted below has already been mitigated; no action is necessary and we have chosen not to give it further space in this very long writeup.) For more information on how CVSS works, please see our series on patch prioritization schema.
| CVSS Base | CVSS Temporal | CVE | Title |
| 10.0 | 8.7 | CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability |
| 9.8 | 8.5 | CVE-2026-26142 | Nuance PowerScribe Remote Code Execution Vulnerability |
| 9.8 | 8.5 | CVE-2026-44815 | DHCP Client Service Remote Code Execution Vulnerability |
| 9.8 | 8.5 | CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability |
| 9.8 | 8.5 | CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability |
| 9.8 | 8.5 | CVE-2026-47643 | Azure Stack Edge Remote Code Execution Vulnerability |
| 9.6 | 8.3 | CVE-2026-42904 | Windows TCP/IP Elevation of Privilege Vulnerability |
| 9.6 | 8.3 | CVE-2026-47281 | Visual Studio Code Elevation of Privilege Vulnerability |
| 9.1 | 7.9 | CVE-2026-45602 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability |
| 9.1 | 7.9 | CVE-2026-48579 | Microsoft Exchange Online Information Disclosure Vulnerability |
| 8.8 | 7.7 | CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability |
| 8.8 | 7.7 | CVE-2026-40371 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability |
| 8.8 | 7.7 | CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability |
| 8.8 | 7.7 | CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| 8.8 | 7.7 | CVE-2026-45504 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| 8.8 | 7.7 | CVE-2026-45648 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| 8.8 | 7.7 | CVE-2026-47289 | Remote Desktop Client Remote Code Execution Vulnerability |
| 8.8 | 7.7 | CVE-2026-47653 | Remote Desktop Client Remote Code Execution Vulnerability |
| 8.4 | 7.3 | CVE-2026-41098 | Azure Stack Edge Spoofing Vulnerability |
| 8.4 | 7.3 | CVE-2026-44810 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
| 8.4 | 7.3 | CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| 8.4 | 7.8 | CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| 8.4 | 7.3 | CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability |
| 8.4 | 7.3 | CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability |
| 8.4 | 7.3 | CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability |
| 8.4 | 7.3 | CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability |
| 8.4 | 7.3 | CVE-2026-45482 | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability |
| 8.4 | 7.3 | CVE-2026-45607 | Windows Hyper-V Remote Code Execution Vulnerability |
| 8.4 | 7.3 | CVE-2026-45641 | Windows Hyper-V Remote Code Execution Vulnerability |
| 8.4 | 7.3 | CVE-2026-47635 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| 8.2 | 7.1 | CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability |
| 8.2 | 7.1 | CVE-2026-45476 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability |
| 8.2 | 7.1 | CVE-2026-47652 | Windows Hyper-V Remote Code Execution Vulnerability |
| 8.1 | 7.1 | CVE-2026-42835 | Microsoft Teams for Android Information Disclosure Vulnerability |
| 8.1 | 7.1 | CVE-2026-42974 | Windows Performance Monitor Remote Code Execution Vulnerability |
| 8.1 | 7.1 | CVE-2026-42981 | Windows Performance Monitor Remote Code Execution Vulnerability |
| 8.1 | 7.1 | CVE-2026-42987 | Windows Deployment Services (WDS) Remote Code Execution |
| 8.1 | 7.1 | CVE-2026-45503 | Microsoft Exchange Server Information Disclosure Vulnerability |
| 8.1 | 7.1 | CVE-2026-45599 | Windows UPnP Device Host Remote Code Execution Vulnerability |
| 8.1 | 7.1 | CVE-2026-45635 | Windows UPnP Device Host Remote Code Execution Vulnerability |
| 8.1 | 7.1 | CVE-2026-47631 | Microsoft Exchange Server Spoofing Vulnerability |
| 8.0 | 7.0 | CVE-2026-45644 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability |
| 8.0 | 7.0 | CVE-2026-47298 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
Appendix C: Products Affected
This is a list of June’s patches sorted by product family, then sub-sorted by severity. Each list is further arranged by CVE. Patches that are shared among multiple product families are listed multiple times, once for each product family. All CVE titles are accurate as made available by Microsoft. For further information on why certain products may appear in titles and not product families (or vice versa), please consult Microsoft.
Windows (119 CVEs)
| Critical severity | |
| CVE-2026-33828 | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability |
| CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42987 | Windows Deployment Services (WDS) Remote Code Execution |
| CVE-2026-42992 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44799 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44801 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44810 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44815 | DHCP Client Service Remote Code Execution Vulnerability |
| CVE-2026-45607 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-45641 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-45648 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability |
| CVE-2026-47288 | Windows Kerberos Key Distribution Center (KDC) Remote Code Execution |
| CVE-2026-47289 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability |
| CVE-2026-47652 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-47654 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-48574 | Windows Media Remote Code Execution Vulnerability |
| Important severity | |
| CVE-2020-17103 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-34335 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-40404 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-40409 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-41092 | Microsoft Kinect Elevation of Privilege Vulnerability |
| CVE-2026-41108 | Windows DNS Client Elevation of Privilege Vulnerability |
| CVE-2026-42828 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-42829 | Windows Administrator Protection Secure Feature Bypass Vulnerability |
| CVE-2026-42836 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
| CVE-2026-42837 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-42903 | Windows Kerberos Denial of Service Vulnerability |
| CVE-2026-42904 | Windows TCP/IP Elevation of Privilege Vulnerability |
| CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-42906 | Windows Shell Information Disclosure Vulnerability |
| CVE-2026-42907 | Windows Shell Information Disclosure Vulnerability |
| CVE-2026-42908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-42909 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42910 | Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability |
| CVE-2026-42911 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-42912 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-42913 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42914 | Windows Kerberos Denial of Service Vulnerability |
| CVE-2026-42915 | Windows TCP/IP Denial of Service Vulnerability |
| CVE-2026-42916 | NT OS Kernel Elevation of Privilege Vulnerability |
| CVE-2026-42968 | Windows Telephony Server Information Disclosure Vulnerability |
| CVE-2026-42969 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42970 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42971 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42972 | Windows Hyper-V Information Disclosure Vulnerability |
| CVE-2026-42973 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42974 | Windows Performance Monitor Remote Code Execution Vulnerability |
| CVE-2026-42977 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42978 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42979 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability |
| CVE-2026-42981 | Windows Performance Monitor Remote Code Execution Vulnerability |
| CVE-2026-42983 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-42984 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability |
| CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability |
| CVE-2026-42991 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42993 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44802 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44804 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44805 | Windows Network Controller (NC) Host Agent Denial of Service Vulnerability |
| CVE-2026-44807 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44808 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44809 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-44811 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44813 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44814 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-45487 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
| CVE-2026-45585 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability |
| CVE-2026-45588 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-45592 | Windows Internet (wininet.dll) Elevation of Privilege Vulnerability |
| CVE-2026-45593 | Windows SDK Elevation of Privilege Vulnerability |
| CVE-2026-45594 | Windows Application Identity (AppID) Information Disclosure Vulnerability |
| CVE-2026-45595 | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2026-45596 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45597 | Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability |
| CVE-2026-45598 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45599 | Windows UPnP Device Host Remote Code Execution Vulnerability |
| CVE-2026-45600 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-45601 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45602 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability |
| CVE-2026-45603 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45604 | Windows Managed Installer Information Disclosure Vulnerability |
| CVE-2026-45605 | Windows Bluetooth Service Elevation of Privilege Vulnerability |
| CVE-2026-45606 | Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability |
| CVE-2026-45608 | Windows DHCP Client Information Disclosure Vulnerability |
| CVE-2026-45634 | Windows DHCP Client Information Disclosure Vulnerability |
| CVE-2026-45635 | Windows UPnP Device Host Remote Code Execution Vulnerability |
| CVE-2026-45636 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-45637 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-45638 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45639 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-45640 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability |
| CVE-2026-45642 | Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability |
| CVE-2026-45653 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-45654 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-45655 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-45656 | UEFI Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-47648 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-47653 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-47656 | Windows Boot Manager Security Feature Bypass Vulnerability |
| CVE-2026-48566 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-48568 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48570 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48573 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48575 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48576 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48578 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48583 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-50508 | Windows NTLM Spoofing Vulnerability |
SharePoint (30 CVEs)
| Critical severity | |
| CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| Important severity | |
| CVE-2026-33113 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-44821 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45453 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45454 | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-45462 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45464 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45465 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45467 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45468 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45479 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45481 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45483 | Microsoft Office Project Server Spoofing Vulnerability |
| CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-45485 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-47298 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-47634 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47636 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47637 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47638 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47639 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47640 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47641 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-48560 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-48562 | Microsoft SharePoint Server Spoofing Vulnerability |
365 (29 CVEs)
| Critical severity | |
| CVE-2026-42824 | M365 Copilot Information Disclosure Vulnerability |
| CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45460 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45497 | Microsoft M365 Copilot Remote Code Execution Vulnerability |
| Important severity | |
| CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44821 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-45457 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45459 | Microsoft Excel Security Feature Bypass Vulnerability |
| CVE-2026-45466 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45485 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-45486 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45643 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45645 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-47293 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
Office (28 CVEs)
| Critical severity | |
| CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45460 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-47635 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| Important severity | |
| CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44821 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-45457 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45459 | Microsoft Excel Security Feature Bypass Vulnerability |
| CVE-2026-45466 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45485 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-45486 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45643 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45645 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-47293 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
Excel (10 CVEs)
| Critical severity | |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability |
| Important severity | |
| CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-45649 | Office for Android Spoofing Vulnerability |
Word (10 CVEs)
| Critical severity | |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| Important severity | |
| CVE-2026-44821 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45485 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-45649 | Office for Android Spoofing Vulnerability |
Exchange (8 CVEs)
| Critical severity | |
| CVE-2026-48579 | Microsoft Exchange Online Information Disclosure Vulnerability |
| Important severity | |
| CVE-2026-45500 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-45501 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2026-45503 | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2026-45504 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-45583 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-47631 | Microsoft Exchange Server Spoofing Vulnerability |
Visual Studio (8 CVEs)
| Important severity | |
| CVE-2026-40376 | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-45482 | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability |
| CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-47281 | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-47284 | Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-47287 | Visual Studio Code Tampering Vulnerability |
| CVE-2026-47292 | Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability |
| CVE-2026-48569 | Visual Studio Code Security Feature Bypass Vulnerability |
Azure (5 CVEs)
| Important severity | |
| CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability |
| CVE-2026-45476 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability |
| CVE-2026-41098 | Azure Stack Edge Spoofing Vulnerability |
| CVE-2026-47643 | Azure Stack Edge Remote Code Execution Vulnerability |
.NET (3 CVEs)
| Important severity | |
| CVE-2026-45490 | .NET SDK Elevation of Privilege Vulnerability |
| CVE-2026-45491 | .NET Tampering Vulnerability |
| CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability |
PowerPoint (3 CVEs)
| Critical severity | |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability |
| Important severity | |
| CVE-2026-45649 | Office for Android Spoofing Vulnerability |
PC Manager (3 CVEs)
| Important severity | |
| CVE-2026-49161 | Microsoft PC Manager Security Feature Bypass Vulnerability |
| CVE-2026-50511 | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-50512 | Microsoft PC Manager Elevation of Privilege Vulnerability |
ASP.NET (1 CVE)
| Important severity | |
| CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability |
Bing Search for Android (1 CVE)
| Important severity | |
| CVE-2026-45650 | Microsoft Bing Search Spoofing Vulnerability |
Defender (1 CVE)
| Important severity | |
| CVE-2026-45647 | Microsoft Defender Elevation of Privilege Vulnerability |
See MMPC table below for information on CVE-2026-41091.
Dynamics 365 (1 CVE)
| Important severity | |
| CVE-2026-40371 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability |
Edge – Copilot Chat (1 CVE)
| Critical severity | |
| CVE-2026-47644 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability |
Microsoft Graph (1 CVE)
| Critical severity | |
| CVE-2026-47655 | Microsoft Graph Information Disclosure Vulnerability |
Microsoft Live Share Canvas SDK (1 CVE)
| Important severity | |
| CVE-2026-45644 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability |
MMPC (1 CVE)
| Important severity | |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability |
Nuance PowerScribe (1 CVE)
| Critical severity | |
| CVE-2026-26142 | Nuance PowerScribe Remote Code Execution Vulnerability |
PowerToys (1 CVE)
| Important severity | |
| CVE-2026-42902 | Microsoft PowerToys Elevation of Privilege Vulnerability |
Teams for Android (1 CVE)
| Important severity | |
| CVE-2026-42835 | Microsoft Teams for Android Information Disclosure Vulnerability |
Windows Narrator Braille (1 CVE)
| Important severity | |
| CVE-2026-48565 | Windows Narrator Braille Elevation of Privilege Vulnerability |
Appendix D: Advisories and Other Products
There are 388 Edge-related advisories listed in June’s release, all but three from Chrome. Because virtually all these patches shipped before Patch Tuesday, and because this post is already horrifically long, we are down to just listing those Edge CVEs and exhorting readers to patch, patch, patch.
| CVE-2026-10881 | CVE-2026-10990 | CVE-2026-11095 | CVE-2026-11201 |
| CVE-2026-10882 | CVE-2026-10991 | CVE-2026-11096 | CVE-2026-11203 |
| CVE-2026-10884 | CVE-2026-10992 | CVE-2026-11098 | CVE-2026-11206 |
| CVE-2026-10886 | CVE-2026-10993 | CVE-2026-11099 | CVE-2026-11207 |
| CVE-2026-10887 | CVE-2026-10994 | CVE-2026-11100 | CVE-2026-11208 |
| CVE-2026-10888 | CVE-2026-10995 | CVE-2026-11101 | CVE-2026-11209 |
| CVE-2026-10889 | CVE-2026-10996 | CVE-2026-11102 | CVE-2026-11210 |
| CVE-2026-10890 | CVE-2026-10997 | CVE-2026-11103 | CVE-2026-11211 |
| CVE-2026-10891 | CVE-2026-10998 | CVE-2026-11104 | CVE-2026-11212 |
| CVE-2026-10893 | CVE-2026-10999 | CVE-2026-11105 | CVE-2026-11213 |
| CVE-2026-10894 | CVE-2026-11000 | CVE-2026-11106 | CVE-2026-11216 |
| CVE-2026-10895 | CVE-2026-11001 | CVE-2026-11107 | CVE-2026-11217 |
| CVE-2026-10897 | CVE-2026-11002 | CVE-2026-11109 | CVE-2026-11218 |
| CVE-2026-10898 | CVE-2026-11003 | CVE-2026-11110 | CVE-2026-11219 |
| CVE-2026-10899 | CVE-2026-11004 | CVE-2026-11111 | CVE-2026-11220 |
| CVE-2026-10900 | CVE-2026-11005 | CVE-2026-11112 | CVE-2026-11221 |
| CVE-2026-10901 | CVE-2026-11006 | CVE-2026-11113 | CVE-2026-11222 |
| CVE-2026-10902 | CVE-2026-11008 | CVE-2026-11114 | CVE-2026-11223 |
| CVE-2026-10903 | CVE-2026-11009 | CVE-2026-11115 | CVE-2026-11224 |
| CVE-2026-10904 | CVE-2026-11011 | CVE-2026-11116 | CVE-2026-11225 |
| CVE-2026-10905 | CVE-2026-11013 | CVE-2026-11117 | CVE-2026-11227 |
| CVE-2026-10906 | CVE-2026-11014 | CVE-2026-11118 | CVE-2026-11228 |
| CVE-2026-10907 | CVE-2026-11015 | CVE-2026-11120 | CVE-2026-11229 |
| CVE-2026-10908 | CVE-2026-11016 | CVE-2026-11121 | CVE-2026-11230 |
| CVE-2026-10909 | CVE-2026-11017 | CVE-2026-11122 | CVE-2026-11231 |
| CVE-2026-10910 | CVE-2026-11018 | CVE-2026-11123 | CVE-2026-11232 |
| CVE-2026-10911 | CVE-2026-11020 | CVE-2026-11124 | CVE-2026-11233 |
| CVE-2026-10912 | CVE-2026-11021 | CVE-2026-11125 | CVE-2026-11234 |
| CVE-2026-10913 | CVE-2026-11022 | CVE-2026-11126 | CVE-2026-11235 |
| CVE-2026-10914 | CVE-2026-11023 | CVE-2026-11128 | CVE-2026-11236 |
| CVE-2026-10916 | CVE-2026-11024 | CVE-2026-11129 | CVE-2026-11237 |
| CVE-2026-10917 | CVE-2026-11025 | CVE-2026-11130 | CVE-2026-11238 |
| CVE-2026-10918 | CVE-2026-11026 | CVE-2026-11132 | CVE-2026-11239 |
| CVE-2026-10919 | CVE-2026-11027 | CVE-2026-11133 | CVE-2026-11240 |
| CVE-2026-10920 | CVE-2026-11028 | CVE-2026-11134 | CVE-2026-11241 |
| CVE-2026-10921 | CVE-2026-11030 | CVE-2026-11135 | CVE-2026-11242 |
| CVE-2026-10922 | CVE-2026-11031 | CVE-2026-11136 | CVE-2026-11243 |
| CVE-2026-10924 | CVE-2026-11032 | CVE-2026-11137 | CVE-2026-11244 |
| CVE-2026-10925 | CVE-2026-11033 | CVE-2026-11138 | CVE-2026-11245 |
| CVE-2026-10926 | CVE-2026-11036 | CVE-2026-11139 | CVE-2026-11246 |
| CVE-2026-10927 | CVE-2026-11037 | CVE-2026-11140 | CVE-2026-11248 |
| CVE-2026-10928 | CVE-2026-11038 | CVE-2026-11141 | CVE-2026-11249 |
| CVE-2026-10930 | CVE-2026-11039 | CVE-2026-11142 | CVE-2026-11250 |
| CVE-2026-10931 | CVE-2026-11040 | CVE-2026-11143 | CVE-2026-11251 |
| CVE-2026-10932 | CVE-2026-11041 | CVE-2026-11144 | CVE-2026-11252 |
| CVE-2026-10933 | CVE-2026-11042 | CVE-2026-11146 | CVE-2026-11253 |
| CVE-2026-10935 | CVE-2026-11043 | CVE-2026-11147 | CVE-2026-11254 |
| CVE-2026-10936 | CVE-2026-11044 | CVE-2026-11149 | CVE-2026-11255 |
| CVE-2026-10937 | CVE-2026-11046 | CVE-2026-11150 | CVE-2026-11256 |
| CVE-2026-10938 | CVE-2026-11047 | CVE-2026-11151 | CVE-2026-11257 |
| CVE-2026-10939 | CVE-2026-11048 | CVE-2026-11152 | CVE-2026-11258 |
| CVE-2026-10940 | CVE-2026-11049 | CVE-2026-11153 | CVE-2026-11259 |
| CVE-2026-10941 | CVE-2026-11050 | CVE-2026-11154 | CVE-2026-11260 |
| CVE-2026-10942 | CVE-2026-11051 | CVE-2026-11155 | CVE-2026-11261 |
| CVE-2026-10943 | CVE-2026-11052 | CVE-2026-11156 | CVE-2026-11262 |
| CVE-2026-10945 | CVE-2026-11053 | CVE-2026-11157 | CVE-2026-11264 |
| CVE-2026-10946 | CVE-2026-11054 | CVE-2026-11158 | CVE-2026-11265 |
| CVE-2026-10947 | CVE-2026-11055 | CVE-2026-11159 | CVE-2026-11266 |
| CVE-2026-10948 | CVE-2026-11056 | CVE-2026-11160 | CVE-2026-11267 |
| CVE-2026-10949 | CVE-2026-11057 | CVE-2026-11161 | CVE-2026-11268 |
| CVE-2026-10954 | CVE-2026-11058 | CVE-2026-11162 | CVE-2026-11269 |
| CVE-2026-10955 | CVE-2026-11059 | CVE-2026-11164 | CVE-2026-11271 |
| CVE-2026-10956 | CVE-2026-11060 | CVE-2026-11166 | CVE-2026-11273 |
| CVE-2026-10957 | CVE-2026-11061 | CVE-2026-11168 | CVE-2026-11275 |
| CVE-2026-10960 | CVE-2026-11062 | CVE-2026-11169 | CVE-2026-11276 |
| CVE-2026-10962 | CVE-2026-11063 | CVE-2026-11170 | CVE-2026-11279 |
| CVE-2026-10963 | CVE-2026-11066 | CVE-2026-11171 | CVE-2026-11281 |
| CVE-2026-10964 | CVE-2026-11067 | CVE-2026-11173 | CVE-2026-11282 |
| CVE-2026-10965 | CVE-2026-11068 | CVE-2026-11174 | CVE-2026-11283 |
| CVE-2026-10966 | CVE-2026-11069 | CVE-2026-11176 | CVE-2026-11284 |
| CVE-2026-10968 | CVE-2026-11070 | CVE-2026-11177 | CVE-2026-11286 |
| CVE-2026-10969 | CVE-2026-11071 | CVE-2026-11179 | CVE-2026-11288 |
| CVE-2026-10970 | CVE-2026-11073 | CVE-2026-11180 | CVE-2026-11289 |
| CVE-2026-10971 | CVE-2026-11074 | CVE-2026-11181 | CVE-2026-11292 |
| CVE-2026-10972 | CVE-2026-11075 | CVE-2026-11182 | CVE-2026-11293 |
| CVE-2026-10973 | CVE-2026-11076 | CVE-2026-11184 | CVE-2026-11294 |
| CVE-2026-10974 | CVE-2026-11078 | CVE-2026-11185 | CVE-2026-11296 |
| CVE-2026-10975 | CVE-2026-11079 | CVE-2026-11186 | CVE-2026-11299 |
| CVE-2026-10976 | CVE-2026-11081 | CVE-2026-11187 | CVE-2026-11300 |
| CVE-2026-10977 | CVE-2026-11083 | CVE-2026-11189 | CVE-2026-11301 |
| CVE-2026-10978 | CVE-2026-11084 | CVE-2026-11190 | CVE-2026-11303 |
| CVE-2026-10979 | CVE-2026-11085 | CVE-2026-11191 | CVE-2026-11304 |
| CVE-2026-10980 | CVE-2026-11086 | CVE-2026-11192 | CVE-2026-11305 |
| CVE-2026-10981 | CVE-2026-11087 | CVE-2026-11193 | CVE-2026-11306 |
| CVE-2026-10982 | CVE-2026-11088 | CVE-2026-11194 | CVE-2026-11307 |
| CVE-2026-10983 | CVE-2026-11089 | CVE-2026-11195 | CVE-2026-11308 |
| CVE-2026-10985 | CVE-2026-11090 | CVE-2026-11196 | CVE-2026-11309 |
| CVE-2026-10986 | CVE-2026-11091 | CVE-2026-11197 | CVE-2026-20942 |
| CVE-2026-10987 | CVE-2026-11092 | CVE-2026-11198 | CVE-2026-32208 |
| CVE-2026-10988 | CVE-2026-11093 | CVE-2026-11199 | CVE-2026-45488 |
| CVE-2026-10989 | CVE-2026-11094 | CVE-2026-11200 |
|
There are also two Windows-related advisories, to which we afford the dignity of names and severity / impact information. Please note that as mentioned above, that client-only CVE-2026-10263 is sporting a rather high CVSS Base score of 9.3.
| CVE-2026-8863 | UEFI Secure Boot Security Feature Bypass Vulnerability | Security Feature Bypass | Important |
| CVE-2025-10263 | ARM CVE-2025-10263: Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] | Elevation of Privilege | Critical |
Meanwhile, there are 23 CVEs from Adobe. Seven of these affect ColdFusion 2025 Update 8 and earlier as well as ColdFusion 2023 Update 19 and earlier, and are collectively addressed in APSB26-64. The rest affect Acrobat Reader 26.001.21411 and earlier, 26.001.21411 and earlier, Win: 24.001.30362 and earlier (Windows), and 24.001.30360 and earlier (Mac); they are collectively addressed in APSB26-64. Unusually, a majority of this month’s CVEs come with a Critical severity rating; for that reason, we’re taking the time to mark those troubling items in red.
ForColdFusion
| CVE-2026-47928 | Improper Input Validation (CWE-20) |
| CVE-2026-47929 | Incorrect Authorization (CWE-863) |
| CVE-2026-47930 | Improper Input Validation (CWE-20) |
| CVE-2026-47931 | Improper Input Validation (CWE-20) |
| CVE-2026-47932 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
| CVE-2026-48293 | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) |
| CVE-2026-47933 | Cross-site Scripting (Stored XSS) (CWE-79) |
For Reader
| CVE-2026-47911 | Out-of-bounds Write (CWE-787) |
| CVE-2026-47912 | Use After Free (CWE-416) |
| CVE-2026-47913 | Use After Free (CWE-416) |
| CVE-2026-47914 | Use After Free (CWE-416) |
| CVE-2026-47915 | Use After Free (CWE-416) |
| CVE-2026-47916 | Use After Free (CWE-416) |
| CVE-2026-47917 | Use After Free (CWE-416) |
| CVE-2026-47918 | Use After Free (CWE-416) |
| CVE-2026-47919 | Use After Free (CWE-416) |
| CVE-2026-47920 | Use After Free (CWE-416) |
| CVE-2026-47921 | Use After Free (CWE-416) |
| CVE-2026-47922 | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-47923 | Out-of-bounds Read (CWE-125) |
| CVE-2026-47924 | Use After Free (CWE-416) |
| CVE-2026-47925 | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-47926 | Out-of-bounds Read (CWE-125) |
Microsoft also issued the usual servicing stack updates this month (ADV990001).
Appendix E: Affected Windows Server versions
This is a table of 113 CVEs in the June release affecting Windows Server versions 2012 through 2025. The table differentiates among major versions of the platform but doesn’t go into deeper detail (eg., Server Core). An “x” indicates that the CVE does not apply to that version. Several Windows CVEs are affect only the client, and those CVEs are omitted from the table entirely. We also include the Important-severity, Windows-touching advisory from CERT/CC, since the Server versions it affects are known, for a grand total of 114. That advisory is indicated in this chart in blue. The Critical-severity patch from Arm Limited is not known to affect any versions of the server.
We remind readers that May was the final month of support for Server 2023 r2, and so that column is out of the table going forward.
Administrators are encouraged to use this appendix as a starting point to ascertain their specific exposure, as each reader’s situation, especially as it concerns products out of mainstream support, will vary. For specific Knowledge Base numbers, please consult Microsoft.
| CVE | S-12 | 12r2 | S-16 | S-19 | S-22 | S-25 |
| CVE-2020-17103 | × | × | × | ■ | × | ■ |
| CVE-2026-8863 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-33828 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-34335 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-40404 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-40409 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-41092 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-41108 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42828 | × | × | × | ■ | ■ | ■ |
| CVE-2026-42836 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42837 | × | × | × | ■ | ■ | ■ |
| CVE-2026-42903 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42904 | × | × | × | × | ■ | ■ |
| CVE-2026-42905 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42906 | × | × | × | × | ■ | ■ |
| CVE-2026-42907 | × | × | × | ■ | ■ | ■ |
| CVE-2026-42908 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42909 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42910 | × | × | × | × | × | ■ |
| CVE-2026-42911 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42912 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42913 | × | × | × | × | ■ | ■ |
| CVE-2026-42914 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42915 | × | × | × | × | ■ | ■ |
| CVE-2026-42916 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42968 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42969 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-42970 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42971 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-42972 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42973 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-42974 | × | × | × | × | ■ | ■ |
| CVE-2026-42977 | × | × | × | ■ | ■ | ■ |
| CVE-2026-42978 | × | × | × | ■ | ■ | ■ |
| CVE-2026-42979 | × | × | × | ■ | ■ | ■ |
| CVE-2026-42980 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42981 | × | × | × | × | ■ | ■ |
| CVE-2026-42983 | × | × | × | ■ | ■ | ■ |
| CVE-2026-42984 | × | × | × | ■ | ■ | ■ |
| CVE-2026-42985 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42986 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42987 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42989 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-42991 | × | × | × | ■ | ■ | ■ |
| CVE-2026-42992 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-42993 | × | × | × | × | ■ | ■ |
| CVE-2026-44799 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-44801 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-44802 | × | × | × | ■ | ■ | ■ |
| CVE-2026-44803 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-44805 | × | × | × | ■ | ■ | ■ |
| CVE-2026-44809 | × | × | × | × | × | ■ |
| CVE-2026-44810 | × | × | × | × | ■ | ■ |
| CVE-2026-44812 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-44815 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45487 | × | × | × | × | ■ | ■ |
| CVE-2026-45585 | × | × | × | × | × | ■ |
| CVE-2026-45586 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45588 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45592 | × | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45593 | × | × | × | ■ | ■ | ■ |
| CVE-2026-45594 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-45595 | × | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45596 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45597 | × | × | × | × | ■ | ■ |
| CVE-2026-45598 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45599 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45600 | × | × | × | × | × | ■ |
| CVE-2026-45601 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45602 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45603 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45604 | × | × | × | × | × | ■ |
| CVE-2026-45605 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-45606 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45607 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-45608 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45634 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45635 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45636 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45637 | × | × | × | ■ | ■ | ■ |
| CVE-2026-45638 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45639 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45640 | × | × | × | × | ■ | ■ |
| CVE-2026-45641 | × | × | × | × | ■ | ■ |
| CVE-2026-45642 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45648 | × | × | × | × | ■ | ■ |
| CVE-2026-45653 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45654 | × | × | × | × | × | ■ |
| CVE-2026-45655 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45656 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-45657 | × | × | × | × | ■ | ■ |
| CVE-2026-45658 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-47288 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-47289 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-47291 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-47648 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-47652 | × | × | × | × | ■ | ■ |
| CVE-2026-47653 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-47654 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-47656 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-48563 | × | × | × | ■ | ■ | ■ |
| CVE-2026-48566 | × | × | × | × | × | ■ |
| CVE-2026-48568 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-48570 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-48573 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-48574 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-48575 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-48576 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-48578 | ■ | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-48583 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-49160 | × | × | ■ | ■ | ■ | ■ |
| CVE-2026-50507 | × | ■ | ■ | ■ | ■ | ■ |
| CVE-2026-50508 | ■ | ■ | ■ | × | ■ | × |
Appendix F: Common Weakness Enumeration
As mentioned above, Microsoft now (almost always!) states which CWEs affect the CVEs they address. This month, we looked at which CWEs were most heavily represented in the dataset and compared them to last month’s inaugural numbers. The June dataset of 209 CVEs gave us 208 CWEs to examine; 24 CVEs had two CVEs, and one had three CWEs. There were 44 unique CWEs, which is just about average for the CWE project so far. Once again CWE-416, Use After Free, leads the pack, appearing in just over 20 percent of all cases. The rest of the field remains is fairly diffuse, with only four other CWEs appearing more than five percent of the time. We did note one especially forehead-smack item this time around: Visual Studio Code Elevation of Privilege Vulnerability, CVE-2026-47281, not only is the only CVE to sport three different CWE findings this time, one of those findings is CWE-798, Use of Hard-Coded Credentials. Sigh.
| CWE | Count | CWE Name |
| 416 | 42 | Use After Free |
| 122 | 24 | Heap-based Buffer Overflow |
| 79 | 20 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| 125 | 19 | Out-of-bounds Read |
| 362 | 14 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
| 200 | 10 | Exposure of Sensitive Information to an Unauthorized Actor |
| 693 | 9 | Protection Mechanism Failure |
| 190 | 8 | Integer Overflow or Wraparound |
| 284 | 7 | Improper Access Control |
| 20 | 6 | Improper Input Validation |
| 59 | 5 | Improper Link Resolution Before File Access ('Link Following') |
| 285 | 5 | Improper Authorization |
| 843 | 5 | Access of Resource Using Incompatible Type ('Type Confusion') |
| 191 | 4 | Integer Underflow (Wrap or Wraparound) |
| 822 | 4 | Untrusted Pointer Dereference |
| 22 | 3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| 74 | 3 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') |
| 77 | 3 | Improper Neutralization of Special Elements used in a Command ('Command Injection') |
| 121 | 3 | Stack-based Buffer Overflow |
| 197 | 3 | Numeric Truncation Error |
| 306 | 3 | Missing Authentication for Critical Function |
| 502 | 3 | Deserialization of Untrusted Data |
| 918 | 3 | Server-Side Request Forgery (SSRF) |
| 23 | 2 | Relative Path Traversal |
| 94 | 2 | Improper Control of Generation of Code ('Code Injection') |
| 126 | 2 | Buffer Over-read |
| 367 | 2 | Time-of-check Time-of-use (TOCTOU) Race Condition |
| 400 | 2 | Uncontrolled Resource Consumption |
| 426 | 2 | Untrusted Search Path |
| 1329 | 2 | Reliance on Component That is Not Updateable |
| 73 | 1 | External Control of File Name or Path |
| 131 | 1 | Incorrect Calculation of Buffer Size |
| 269 | 1 | Improper Privilege Management |
| 280 | 1 | Improper Handling of Insufficient Permissions or Privileges |
| 287 | 1 | Improper Authentication |
| 290 | 1 | Authentication Bypass by Spoofing |
| 451 | 1 | User Interface (UI) Misrepresentation of Critical Information |
| 476 | 1 | NULL Pointer Dereference |
| 501 | 1 | Trust Boundary Violation |
| 787 | 1 | Out-of-bounds Write |
| 798 | 1 | Use of Hard-coded Credentials |
| 829 | 1 | Inclusion of Functionality from Untrusted Control Sphere |
| 862 | 1 | Missing Authorization |
| 908 | 1 | Use of Uninitialized Resource |
