Microsoft June 2026 Patch Tuesday Fixes 198 Flaws, Including 3 Zero-Days
Key Takeaways Microsoft released its June 2026 Patch Tuesday updates, addressing a total of 198 vulnerabilities. Three zero-day vulnerabilities, including a BitLocker bypass and an HTTP.sys...
Key Takeaways
- Microsoft released its June 2026 Patch Tuesday updates, addressing a total of 198 vulnerabilities.
- Three zero-day vulnerabilities, including a BitLocker bypass and an HTTP.sys denial-of-service flaw, were actively exploited or publicly known prior to the patch release.
- The update cycle includes 54 Remote Code Execution (RCE) vulnerabilities, with critical patches for Remote Desktop Client, Windows Hyper-V, and Microsoft Office.
- Elevation of Privilege (EoP) vulnerabilities were the most common type, with 63 flaws, many affecting core Windows components.
- Immediate patching is strongly recommended for all organizations due to the active exploitation of zero-days and the severity of other critical flaws.
Microsoft Addresses 198 Vulnerabilities, Including Three Zero-Days, in June 2026 Patch Tuesday
Microsoft has issued its comprehensive security updates for June 2026, on June 9, 2026, rectifying a substantial 198 vulnerabilities across its extensive product portfolio. This month’s Patch Tuesday stands out not only for the sheer volume of fixes but also for the critical inclusion of three zero-day vulnerabilities that were either actively exploited in the wild or publicly disclosed before official patches became available.
Table Of Content
Organizations are strongly advised to prioritize the immediate deployment of these updates, as every identified CVE in this release necessitates customer action to mitigate potential risks effectively.
Breakdown of Vulnerability Types
The 198 vulnerabilities patched in June 2026 are categorized as follows:
- Elevation of Privilege: 63
- Remote Code Execution: 54
- Spoofing: 27
- Information Disclosure: 26
- Security Feature Bypass: 18
- Denial of Service: 7
- Tampering: 3
- Total: 198
Three Zero-Days Patched
Three vulnerabilities confirmed to be known to attackers before the patch release are addressed in this cycle, highlighting persistent areas of concern for enterprise security.
- CVE-2026-50507: Windows BitLocker Security Feature Bypass – This “Important” rated flaw could enable an attacker with physical or local access to circumvent BitLocker’s full-disk encryption. This bypass undermines a crucial defense mechanism for data protection on lost or stolen devices, making it a significant concern for data integrity.
- CVE-2026-49160: HTTP.sys Denial of Service – Also rated “Important,” this vulnerability affects the HTTP/2 stack within HTTP.sys. Given that HTTP.sys underpins IIS and other critical Windows networking services, a maliciously crafted request stream could render exposed web servers inoperable. This makes it a high-priority fix for any internet-facing infrastructure.
- CVE-2026-45586: Unspecified Zero-Day – The third zero-day vulnerability underscores a consistent pattern in attacker focus: bypassing encryption, disrupting services, and compromising boot integrity.
Critical RCE Vulnerabilities Addressed
Beyond the actively exploited zero-days, this Patch Tuesday addresses 54 Remote Code Execution (RCE) vulnerabilities, with several rated as Critical due to their potential for severe impact.
The Remote Desktop Client received a significant cluster of 11 RCE patches, including Critical-rated flaws such as CVE-2026-44801, CVE-2026-44799, CVE-2026-42992, and CVE-2026-42985. These vulnerabilities could allow attackers to execute arbitrary code on affected systems.
Windows Hyper-V is also heavily impacted by Critical RCE vulnerabilities, including CVE-2026-47652, CVE-2026-45641, and CVE-2026-45607. These flaws are particularly dangerous as they could enable virtual machine guest escape, allowing attackers to execute code on the host system.
Other notable Critical RCE vulnerabilities include:
- CVE-2026-47291 – HTTP.sys Remote Code Execution
- CVE-2026-47288 – Windows Kerberos KDC RCE, a critical patch for Active Directory environments.
- CVE-2026-45648 – Active Directory Domain Services RCE
- CVE-2026-32193 – Azure Kubernetes Service (AKS) RCE
- CVE-2026-26142 – Nuance PowerScribe RCE, critical for healthcare environments.
Microsoft Office also received several Critical RCE patches, including CVE-2026-45458 and CVE-2026-45456 for Outlook and Word, and CVE-2026-45474 and CVE-2026-45472. These vulnerabilities can be exploited through malicious document delivery, posing a significant threat to end-users.
Elevation of Privilege and Security Feature Bypass
With 63 vulnerabilities, Elevation of Privilege (EoP) flaws represent the largest category in this patch cycle. Key components affected include the Windows DWM Core Library (11 EoP CVEs), Windows Ancillary Function Driver for WinSock (7 CVEs), Windows Push Notifications (4 CVEs), and the Windows Kernel (CVE-2026-48583, CVE-2026-45653). The Critical-rated Microsoft Cryptographic Services EoP (CVE-2026-44810) is particularly critical, as it targets a fundamental security subsystem. These EoP flaws are frequently leveraged in multi-stage attacks to escalate privileges to SYSTEM-level control after initial access.
Windows Secure Boot also received 8 Security Feature Bypass patches this month, indicating a continued focus by attackers on undermining the integrity of the pre-OS boot process.
What You Should Do
Given the presence of three actively exploited zero-day vulnerabilities and numerous Critical RCEs, security teams must prioritize and expedite the deployment of this month’s updates.
- Immediate Patching: Apply all available security updates without delay.
- Prioritize Critical Systems: Focus patching efforts on systems running BitLocker, HTTP.sys, Remote Desktop, and Hyper-V hosts due to the severity of the vulnerabilities affecting them.
- Implement Network Segmentation: Where immediate patching is not feasible, implement network segmentation to isolate vulnerable systems and reduce potential attack surfaces.
- Restrict RDP Exposure: Limit Remote Desktop Protocol (RDP) exposure to only necessary endpoints and implement strong authentication mechanisms.
- User Awareness Training: Educate users about the dangers of malicious documents and phishing attempts, especially concerning Microsoft Office vulnerabilities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.