Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Critical WordPress XSS2Shell Flaw Allows Remote Code Execution
August 7, 2026
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Home/CyberSecurity News/Microsoft June 2026 Patch Tuesday Fixes 198 Flaws, Including 3 Zero-Days
CyberSecurity News

Microsoft June 2026 Patch Tuesday Fixes 198 Flaws, Including 3 Zero-Days

Key Takeaways Microsoft released its June 2026 Patch Tuesday updates, addressing a total of 198 vulnerabilities. Three zero-day vulnerabilities, including a BitLocker bypass and an HTTP.sys...

Jennifer sherman
Jennifer sherman
June 9, 2026 4 Min Read
51 0

Key Takeaways

  • Microsoft released its June 2026 Patch Tuesday updates, addressing a total of 198 vulnerabilities.
  • Three zero-day vulnerabilities, including a BitLocker bypass and an HTTP.sys denial-of-service flaw, were actively exploited or publicly known prior to the patch release.
  • The update cycle includes 54 Remote Code Execution (RCE) vulnerabilities, with critical patches for Remote Desktop Client, Windows Hyper-V, and Microsoft Office.
  • Elevation of Privilege (EoP) vulnerabilities were the most common type, with 63 flaws, many affecting core Windows components.
  • Immediate patching is strongly recommended for all organizations due to the active exploitation of zero-days and the severity of other critical flaws.

Microsoft Addresses 198 Vulnerabilities, Including Three Zero-Days, in June 2026 Patch Tuesday

Microsoft has issued its comprehensive security updates for June 2026, on June 9, 2026, rectifying a substantial 198 vulnerabilities across its extensive product portfolio. This month’s Patch Tuesday stands out not only for the sheer volume of fixes but also for the critical inclusion of three zero-day vulnerabilities that were either actively exploited in the wild or publicly disclosed before official patches became available.

Table Of Content

  • Key Takeaways
  • Microsoft Addresses 198 Vulnerabilities, Including Three Zero-Days, in June 2026 Patch Tuesday
  • Breakdown of Vulnerability Types
  • Three Zero-Days Patched
  • Critical RCE Vulnerabilities Addressed
  • Elevation of Privilege and Security Feature Bypass
  • What You Should Do

Organizations are strongly advised to prioritize the immediate deployment of these updates, as every identified CVE in this release necessitates customer action to mitigate potential risks effectively.

Breakdown of Vulnerability Types

The 198 vulnerabilities patched in June 2026 are categorized as follows:

  • Elevation of Privilege: 63
  • Remote Code Execution: 54
  • Spoofing: 27
  • Information Disclosure: 26
  • Security Feature Bypass: 18
  • Denial of Service: 7
  • Tampering: 3
  • Total: 198

Three Zero-Days Patched

Three vulnerabilities confirmed to be known to attackers before the patch release are addressed in this cycle, highlighting persistent areas of concern for enterprise security.

  • CVE-2026-50507: Windows BitLocker Security Feature Bypass – This “Important” rated flaw could enable an attacker with physical or local access to circumvent BitLocker’s full-disk encryption. This bypass undermines a crucial defense mechanism for data protection on lost or stolen devices, making it a significant concern for data integrity.
  • CVE-2026-49160: HTTP.sys Denial of Service – Also rated “Important,” this vulnerability affects the HTTP/2 stack within HTTP.sys. Given that HTTP.sys underpins IIS and other critical Windows networking services, a maliciously crafted request stream could render exposed web servers inoperable. This makes it a high-priority fix for any internet-facing infrastructure.
  • CVE-2026-45586: Unspecified Zero-Day – The third zero-day vulnerability underscores a consistent pattern in attacker focus: bypassing encryption, disrupting services, and compromising boot integrity.

Critical RCE Vulnerabilities Addressed

Beyond the actively exploited zero-days, this Patch Tuesday addresses 54 Remote Code Execution (RCE) vulnerabilities, with several rated as Critical due to their potential for severe impact.

The Remote Desktop Client received a significant cluster of 11 RCE patches, including Critical-rated flaws such as CVE-2026-44801, CVE-2026-44799, CVE-2026-42992, and CVE-2026-42985. These vulnerabilities could allow attackers to execute arbitrary code on affected systems.

Windows Hyper-V is also heavily impacted by Critical RCE vulnerabilities, including CVE-2026-47652, CVE-2026-45641, and CVE-2026-45607. These flaws are particularly dangerous as they could enable virtual machine guest escape, allowing attackers to execute code on the host system.

Other notable Critical RCE vulnerabilities include:

  • CVE-2026-47291 – HTTP.sys Remote Code Execution
  • CVE-2026-47288 – Windows Kerberos KDC RCE, a critical patch for Active Directory environments.
  • CVE-2026-45648 – Active Directory Domain Services RCE
  • CVE-2026-32193 – Azure Kubernetes Service (AKS) RCE
  • CVE-2026-26142 – Nuance PowerScribe RCE, critical for healthcare environments.

Microsoft Office also received several Critical RCE patches, including CVE-2026-45458 and CVE-2026-45456 for Outlook and Word, and CVE-2026-45474 and CVE-2026-45472. These vulnerabilities can be exploited through malicious document delivery, posing a significant threat to end-users.

Elevation of Privilege and Security Feature Bypass

With 63 vulnerabilities, Elevation of Privilege (EoP) flaws represent the largest category in this patch cycle. Key components affected include the Windows DWM Core Library (11 EoP CVEs), Windows Ancillary Function Driver for WinSock (7 CVEs), Windows Push Notifications (4 CVEs), and the Windows Kernel (CVE-2026-48583, CVE-2026-45653). The Critical-rated Microsoft Cryptographic Services EoP (CVE-2026-44810) is particularly critical, as it targets a fundamental security subsystem. These EoP flaws are frequently leveraged in multi-stage attacks to escalate privileges to SYSTEM-level control after initial access.

Windows Secure Boot also received 8 Security Feature Bypass patches this month, indicating a continued focus by attackers on undermining the integrity of the pre-OS boot process.

What You Should Do

Given the presence of three actively exploited zero-day vulnerabilities and numerous Critical RCEs, security teams must prioritize and expedite the deployment of this month’s updates.

  • Immediate Patching: Apply all available security updates without delay.
  • Prioritize Critical Systems: Focus patching efforts on systems running BitLocker, HTTP.sys, Remote Desktop, and Hyper-V hosts due to the severity of the vulnerabilities affecting them.
  • Implement Network Segmentation: Where immediate patching is not feasible, implement network segmentation to isolate vulnerable systems and reduce potential attack surfaces.
  • Restrict RDP Exposure: Limit Remote Desktop Protocol (RDP) exposure to only necessary endpoints and implement strong authentication mechanisms.
  • User Awareness Training: Educate users about the dangers of malicious documents and phishing attempts, especially concerning Microsoft Office vulnerabilities.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerabilityzero-day

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Veeam Backup & Replication Vulnerability Allows RCE Attacks

Next Post

Browser-in-the-Browser Phishing Steals Microsoft 365 Logins

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
August 7, 2026
Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us