Claude is having a major outage. Status board · Discuss Claude

Patch Tuesday: June 2026

Each month's Microsoft security updates: what to patch first, the Critical fixes, and what CISA says attackers are exploiting.

How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.

Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)

June 2026 Patch Tuesday: Microsoft fixed 201 vulnerabilities, 32 of them Critical. None was known to be exploited on the day. Released Tue 9 Jun 2026.

  • 201vulnerabilities fixed
  • 32Critical
  • 0exploited before the fix
  • 3publicly disclosed
  • 0now on CISA KEV

By type: 66 elevation of privilege, 54 remote code execution, 27 spoofing, 26 information disclosure, 18 security feature bypass, 7 denial of service, 3 tampering.

Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.

Patch these first

Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.

CVEWhatSeverityCVSSWhy first
CVE-2026-45586Windows Collaborative Translation Framework (CTFMON) Elevation of PrivilegeImportant7.8Publicly disclosed
CVE-2026-49160HTTP.sys Denial of ServiceImportant7.5Publicly disclosed
CVE-2026-50507Windows BitLocker Security Feature BypassImportant6.8Publicly disclosed

Critical (32)

Microsoft’s top rating: usually code execution with little or no user action.

CVEWhatImpactCVSS
CVE-2026-26142Nuance PowerScribe Remote Code ExecutionRemote Code Execution9.8
CVE-2026-44815DHCP Client Service Remote Code ExecutionRemote Code Execution9.8
CVE-2026-45657Windows Kernel Remote Code ExecutionRemote Code Execution9.8
CVE-2026-47291HTTP.sys Remote Code ExecutionRemote Code Execution9.8
CVE-2026-32193Azure Kubernetes Service (AKS) Remote Code ExecutionRemote Code Execution8.8
CVE-2026-42985Remote Desktop Client Remote Code ExecutionRemote Code Execution8.8
CVE-2026-45648Windows Active Directory Domain Services Remote Code ExecutionRemote Code Execution8.8
CVE-2026-47289Remote Desktop Client Remote Code ExecutionRemote Code Execution8.8
CVE-2026-44810Microsoft Cryptographic Services Elevation of PrivilegeElevation of Privilege8.4
CVE-2026-45456Microsoft Outlook and Word Remote Code ExecutionRemote Code Execution8.4
CVE-2026-45458Microsoft Outlook and Word Remote Code ExecutionRemote Code Execution8.4
CVE-2026-45461Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2026-45463Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2026-45472Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2026-45474Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2026-45607Windows Hyper-V Remote Code ExecutionRemote Code Execution8.4
CVE-2026-45641Windows Hyper-V Remote Code ExecutionRemote Code Execution8.4
CVE-2026-47635Microsoft Outlook and Word Remote Code ExecutionRemote Code Execution8.4
CVE-2026-45476Microsoft Azure Network Adapter Elevation of PrivilegeElevation of Privilege8.2
CVE-2026-47652Windows Hyper-V Remote Code ExecutionRemote Code Execution8.2
CVE-2026-42987Windows Deployment Services (WDS) Remote Code ExecutionRemote Code Execution8.1
CVE-2026-33828Windows Device Health Attestation (DHA) Elevation of PrivilegeElevation of Privilege7.8
CVE-2026-44803Windows Graphics Component Remote Code ExecutionRemote Code Execution7.8
CVE-2026-44812Windows Graphics Component Remote Code ExecutionRemote Code Execution7.8
CVE-2026-48574Windows Media Remote Code ExecutionRemote Code Execution7.8
CVE-2026-42992Remote Desktop Client Remote Code ExecutionRemote Code Execution7.5
CVE-2026-44799Remote Desktop Client Remote Code ExecutionRemote Code Execution7.5
CVE-2026-44801Remote Desktop Client Remote Code ExecutionRemote Code Execution7.5
CVE-2026-47654Remote Desktop Client Remote Code ExecutionRemote Code Execution7.5
CVE-2026-48563Remote Desktop Client Remote Code ExecutionRemote Code Execution7.5
CVE-2026-47288Windows Kerberos Key Distribution Center (KDC) Remote Code ExecutionRemote Code Execution7.1
CVE-2026-45460Microsoft Office Information DisclosureInformation Disclosure4.7

Added to CISA KEV in June 2026 (23)

Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.

CVEVendor and productWhatAddedFederal deadlineRansomware
CVE-2026-48558SimpleHelp SimpleHelpSimpleHelp Authentication Bypass29 Jun2 Jul 2026
CVE-2026-12569PTC Windchill and FlexPLMImproper Input Validation25 Jun28 Jun 2026Known
CVE-2026-20230Cisco Unified Communications ManagerServer-Side Request Forgery (SSRF)25 Jun28 Jun 2026
CVE-2025-67038Lantronix EDS5000Code Injection23 Jun26 Jun 2026
CVE-2026-34908Ubiquiti UniFi OSImproper Access Control23 Jun26 Jun 2026
CVE-2026-34909Ubiquiti UniFi OSPath Traversal23 Jun26 Jun 2026
CVE-2026-34910Ubiquiti UniFi OSImproper Input Validation23 Jun26 Jun 2026
CVE-2026-20253Splunk EnterpriseMissing Authentication for Critical Function18 Jun21 Jun 2026
CVE-2026-48907Widget Factory Joomla Content Editor Widget Factory Joomla Content Editor Improper Access Control16 Jun19 Jun 2026
CVE-2026-20262Cisco Catalyst SD-WAN ManagerDirectory or Path Traversal15 Jun29 Jun 2026
CVE-2026-54420LiteSpeed cPanel PluginUNIX Symbolic Link (Symlink) Following15 Jun18 Jun 2026
CVE-2026-35273Oracle PeopleSoft Enterprise PeopleToolsOracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function12 Jun15 Jun 2026Known
CVE-2026-10520Ivanti SentryOS Command Injection11 Jun14 Jun 2026
CVE-2026-11645Google Chromium V8Out-of-Bounds Read and Write9 Jun23 Jun 2026
CVE-2026-20245Cisco Catalyst SD-WAN ManagerImproper Encoding or Escaping of Output9 Jun23 Jun 2026
CVE-2026-7473Arista Extensible Operating SystemIncomplete Comparison with Missing Factors9 Jun23 Jun 2026
CVE-2026-42271BerriAI LiteLLMCommand Injection8 Jun22 Jun 2026
CVE-2026-50751Check Point Security GatewayImproper Authentication8 Jun11 Jun 2026Known
CVE-2026-28318SolarWinds Serv-UUncontrolled Resource Consumption5 Jun19 Jun 2026
CVE-2026-45247Mirasvit Mirasvit Full Page Cache WarmerMirasvit Full Page Cache Warmer Deserialization of Untrusted Data3 Jun6 Jun 2026
CVE-2022-0492Linux KernelImproper Authentication2 Jun5 Jun 2026
CVE-2025-48595Android FrameworkInteger Overflow2 Jun5 Jun 2026
CVE-2024-21182Oracle WebLogic ServerUnspecified1 Jun4 Jun 2026

All 201 fixes

Show the full list, with a filter
CVEProductWhatSeverityCVSS
CVE-2026-26142Nuance PowerScribeNuance PowerScribe Remote Code ExecutionCritical9.8
CVE-2026-44815Windows DHCP ClientDHCP Client Service Remote Code ExecutionCritical9.8
CVE-2026-45657Windows KernelWindows Kernel Remote Code ExecutionCritical9.8
CVE-2026-47291Windows HTTP.sysHTTP.sys Remote Code ExecutionCritical9.8
CVE-2026-32193Microsoft Azure Kubernetes ServiceAzure Kubernetes Service (AKS) Remote Code ExecutionCritical8.8
CVE-2026-42985Remote Desktop ClientRemote Desktop Client Remote Code ExecutionCritical8.8
CVE-2026-45648Active Directory Domain ServicesWindows Active Directory Domain Services Remote Code ExecutionCritical8.8
CVE-2026-47289Remote Desktop ClientRemote Desktop Client Remote Code ExecutionCritical8.8
CVE-2026-44810Windows Cryptographic ServicesMicrosoft Cryptographic Services Elevation of PrivilegeCritical8.4
CVE-2026-45456Microsoft OfficeMicrosoft Outlook and Word Remote Code ExecutionCritical8.4
CVE-2026-45458Microsoft OfficeMicrosoft Outlook and Word Remote Code ExecutionCritical8.4
CVE-2026-45461Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2026-45463Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2026-45472Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2026-45474Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2026-45607Windows Hyper-VWindows Hyper-V Remote Code ExecutionCritical8.4
CVE-2026-45641Role: Windows Hyper-VWindows Hyper-V Remote Code ExecutionCritical8.4
CVE-2026-47635Microsoft OfficeMicrosoft Outlook and Word Remote Code ExecutionCritical8.4
CVE-2026-45476Linux MANA DriverMicrosoft Azure Network Adapter Elevation of PrivilegeCritical8.2
CVE-2026-47652Windows Hyper-VWindows Hyper-V Remote Code ExecutionCritical8.2
CVE-2026-42987Windows Deployment ServicesWindows Deployment Services (WDS) Remote Code ExecutionCritical8.1
CVE-2026-33828Microsoft Azure Attestation service and Device Health Attestation ServiceWindows Device Health Attestation (DHA) Elevation of PrivilegeCritical7.8
CVE-2026-44803Windows Win32K – GRFXWindows Graphics Component Remote Code ExecutionCritical7.8
CVE-2026-44812Windows Win32K – GRFXWindows Graphics Component Remote Code ExecutionCritical7.8
CVE-2026-48574Windows MediaWindows Media Remote Code ExecutionCritical7.8
CVE-2026-42992Remote Desktop ClientRemote Desktop Client Remote Code ExecutionCritical7.5
CVE-2026-44799Remote Desktop ClientRemote Desktop Client Remote Code ExecutionCritical7.5
CVE-2026-44801Remote Desktop ClientRemote Desktop Client Remote Code ExecutionCritical7.5
CVE-2026-47654Remote Desktop ClientRemote Desktop Client Remote Code ExecutionCritical7.5
CVE-2026-48563Remote Desktop ClientRemote Desktop Client Remote Code ExecutionCritical7.5
CVE-2026-47288Windows KerberosWindows Kerberos Key Distribution Center (KDC) Remote Code ExecutionCritical7.1
CVE-2026-45460Microsoft OfficeMicrosoft Office Information DisclosureCritical4.7
CVE-2026-47643Azure Stack EdgeAzure Stack Edge Remote Code ExecutionImportant9.8
CVE-2026-42904Windows TCP/IPWindows TCP/IP Elevation of PrivilegeImportant9.6
CVE-2026-47281Visual Studio CodeVisual Studio Code Elevation of PrivilegeImportant9.6
CVE-2026-45602Windows DHCP ServerWindows Dynamic Host Configuration Protocol (DHCP) TamperingImportant9.1
CVE-2026-40371Microsoft Dynamics 365 (on-premises)Microsoft Dynamics 365 (on-premises) Elevation of PrivilegeImportant8.8
CVE-2026-45484Microsoft Office SharePointMicrosoft SharePoint Elevation of PrivilegeImportant8.8
CVE-2026-45504Microsoft Exchange ServerMicrosoft Exchange Server Elevation of PrivilegeImportant8.8
CVE-2026-47653Remote Desktop ClientRemote Desktop Client Remote Code ExecutionImportant8.8
CVE-2026-41098Azure Stack EdgeAzure Stack Edge SpoofingImportant8.4
CVE-2026-45482GitHub Copilot and Visual Studio CodeMicrosoft Visual Studio Code CoPilot Chat Security Feature BypassImportant8.4
CVE-2026-44822Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant8.2
CVE-2026-42835Microsoft Teams for AndroidMicrosoft Teams for Android Information DisclosureImportant8.1
CVE-2026-42974Windows Performance MonitorWindows Performance Monitor Remote Code ExecutionImportant8.1
CVE-2026-42981Windows Performance MonitorWindows Performance Monitor Remote Code ExecutionImportant8.1
CVE-2026-45503Microsoft Exchange ServerMicrosoft Exchange Server Information DisclosureImportant8.1
CVE-2026-45599Universal Plug and Play (upnp.dll)Windows UPnP Device Host Remote Code ExecutionImportant8.1
CVE-2026-45635Universal Plug and Play (upnp.dll)Windows UPnP Device Host Remote Code ExecutionImportant8.1
CVE-2026-47631Microsoft Exchange ServerMicrosoft Exchange Server SpoofingImportant8.1
CVE-2026-45644Microsoft Live Share Canvas SDKMicrosoft Live Share Canvas SDK Elevation of PrivilegeImportant8.0
CVE-2026-47298Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionImportant8.0
CVE-2026-45588Windows Secure BootSecure Boot Security Feature BypassImportant7.9
CVE-2026-45654Windows Secure BootSecure Boot Security Feature BypassImportant7.9
CVE-2026-47656Windows Boot ManagerWindows Boot Manager Security Feature BypassImportant7.9
CVE-2026-48568Windows Secure BootSecure Boot Security Feature BypassImportant7.9
CVE-2026-48570Windows Secure BootSecure Boot Security Feature BypassImportant7.9
CVE-2026-48573Windows Secure BootSecure Boot Security Feature BypassImportant7.9
CVE-2026-48575Windows Secure BootSecure Boot Security Feature BypassImportant7.9
CVE-2026-48576Windows Secure BootSecure Boot Security Feature BypassImportant7.9
CVE-2026-48578Windows Secure BootSecure Boot Security Feature BypassImportant7.9
CVE-2026-40404Windows Universal Disk Format File System Driver (UDFS)Windows Universal Disk Format File System Driver (UDFS) Elevation of PrivilegeImportant7.8
CVE-2026-40409Windows Universal Disk Format File System Driver (UDFS)Windows Universal Disk Format File System Driver (UDFS) Elevation of PrivilegeImportant7.8
CVE-2026-41092Microsoft KinectMicrosoft Kinect Elevation of PrivilegeImportant7.8
CVE-2026-42828Windows Projected File System Filter DriverWindows Projected File System Elevation of PrivilegeImportant7.8
CVE-2026-42829Windows Administrator ProtectionWindows Administrator Protection Secure Feature BypassImportant7.8
CVE-2026-42837Windows Projected File System Filter DriverWindows Projected File System Elevation of PrivilegeImportant7.8
CVE-2026-42902Microsoft PowerToysMicrosoft PowerToys Elevation of PrivilegeImportant7.8
CVE-2026-42905Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-42910Windows Hotpatch Monitoring ServiceWindows Hotpatch Monitoring Service Elevation of PrivilegeImportant7.8
CVE-2026-42916Windows NT OS KernelNT OS Kernel Elevation of PrivilegeImportant7.8
CVE-2026-42977Windows Push NotificationsWindows Push Notifications Elevation of PrivilegeImportant7.8
CVE-2026-42978Windows Push NotificationsWindows Push Notifications Elevation of PrivilegeImportant7.8
CVE-2026-42979Windows Push NotificationsWindows Push Notifications Elevation of PrivilegeImportant7.8
CVE-2026-42980Windows NT OS KernelNT OS Kernel Elevation of PrivilegeImportant7.8
CVE-2026-42983Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-42986Microsoft Graphics ComponentMicrosoft Graphics Component Elevation of PrivilegeImportant7.8
CVE-2026-42989WinlogonWinlogon Elevation of PrivilegeImportant7.8
CVE-2026-42991Windows Push NotificationsWindows Push Notifications Elevation of PrivilegeImportant7.8
CVE-2026-44802Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-44804Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-44807Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-44808Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-44809Windows Common Log File System DriverWindows Common Log File System Driver Elevation of PrivilegeImportant7.8
CVE-2026-44811Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-44813Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-44817Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-44819Microsoft OfficeMicrosoft Office Remote Code ExecutionImportant7.8
CVE-2026-44820Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-44823Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-44824Microsoft OfficeMicrosoft Office Remote Code ExecutionImportant7.8
CVE-2026-45457Microsoft Office WordMicrosoft Word Remote Code ExecutionImportant7.8
CVE-2026-45469Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-45471Microsoft Office WordMicrosoft Word Remote Code ExecutionImportant7.8
CVE-2026-45475Microsoft OfficeMicrosoft Office Remote Code ExecutionImportant7.8
CVE-2026-45486Microsoft Office WordMicrosoft Word Remote Code ExecutionImportant7.8
CVE-2026-45487Windows Program Compatibility Assistant ServiceWindows Program Compatibility Assistant Service Elevation of PrivilegeImportant7.8
CVE-2026-45490.NET.NET SDK Elevation of PrivilegeImportant7.8
CVE-2026-45586Windows Collaborative Translation FrameworkWindows Collaborative Translation Framework (CTFMON) Elevation of PrivilegeImportant7.8
CVE-2026-45592Windows Internet (wininet.dll)Windows Internet (wininet.dll) Elevation of PrivilegeImportant7.8
CVE-2026-45593Windows SDKWindows SDK Elevation of PrivilegeImportant7.8
CVE-2026-45600Windows Kernel-Mode DriversWindows Kernel-Mode Driver Elevation of PrivilegeImportant7.8
CVE-2026-45605Windows Bluetooth ServiceWindows Bluetooth Service Elevation of PrivilegeImportant7.8
CVE-2026-45636Windows NTFSWindows NTFS Remote Code ExecutionImportant7.8
CVE-2026-45637Windows DWM Core LibraryMicrosoft DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-45638Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2026-45643Microsoft Office WordMicrosoft Word Remote Code ExecutionImportant7.8
CVE-2026-45645Microsoft OfficeMicrosoft Office Remote Code ExecutionImportant7.8
CVE-2026-45656Windows UEFIUEFI Secure Boot Security Feature BypassImportant7.8
CVE-2026-45658Windows BitLockerWindows BitLocker Security Feature BypassImportant7.8
CVE-2026-47292Visual Studio CodeVisual Studio Code MSSQL Extension Remote Code ExecutionImportant7.8
CVE-2026-48565Windows Narrator BrailleWindows Narrator Braille Elevation of PrivilegeImportant7.8
CVE-2026-48583Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2026-49161Window PC ManagerMicrosoft PC Manager Security Feature BypassImportant7.8
CVE-2026-50511Window PC ManagerMicrosoft PC Manager Elevation of PrivilegeImportant7.8
CVE-2026-50512Window PC ManagerMicrosoft PC Manager Elevation of PrivilegeImportant7.8
CVE-2026-40376Visual Studio CodeVisual Studio Code Elevation of PrivilegeImportant7.5
CVE-2026-42908Windows RDPWindows Remote Desktop Protocol (RDP) Information DisclosureImportant7.5
CVE-2026-42909Remote Desktop ClientRemote Desktop Client Remote Code ExecutionImportant7.5
CVE-2026-42913Remote Desktop ClientRemote Desktop Client Remote Code ExecutionImportant7.5
CVE-2026-42993Remote Desktop ClientRemote Desktop Client Remote Code ExecutionImportant7.5
CVE-2026-45583Microsoft Exchange ServerMicrosoft Exchange Server Remote Code ExecutionImportant7.5
CVE-2026-45591ASP.NET CoreASP.NET Core Denial of ServiceImportant7.5
CVE-2026-45639Windows RDPWindows Remote Desktop Protocol (RDP) Information DisclosureImportant7.5
CVE-2026-49160HTTP/2HTTP.sys Denial of ServiceImportant7.5
CVE-2026-45481Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant7.3
CVE-2026-47634Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant7.3
CVE-2026-45649Office for AndroidOffice for Android SpoofingImportant7.1
CVE-2026-48569Visual Studio CodeVisual Studio Code Security Feature BypassImportant7.1
CVE-2026-34335Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-41108Windows DNSWindows DNS Client Elevation of PrivilegeImportant7.0
CVE-2026-42836Function Discovery Service (fdwsd.dll)Windows Function Discovery Service (fdwsd.dll) Elevation of PrivilegeImportant7.0
CVE-2026-42911Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-42912Windows Telephony ServiceWindows Telephony Service Elevation of PrivilegeImportant7.0
CVE-2026-42984Windows KernelWindows Kernel Elevation of PrivilegeImportant7.0
CVE-2026-44818Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.0
CVE-2026-45596Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-45597UI Automation Manager (uiamanager.dll)Windows UI Automation Manager (uiamanager.dll) Elevation of PrivilegeImportant7.0
CVE-2026-45598Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-45601Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-45603Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-45640Windows Bluetooth Port DriverWindows Bluetooth Port Driver Elevation of PrivilegeImportant7.0
CVE-2026-45653Windows KernelWindows Kernel Elevation of PrivilegeImportant7.0
CVE-2026-47293Microsoft Office Click-To-RunMicrosoft Office Click-To-Run Elevation of PrivilegeImportant7.0
CVE-2026-47648Windows StorageWindows Storage Elevation of PrivilegeImportant7.0
CVE-2026-45608Windows DHCP ClientWindows DHCP Client Information DisclosureImportant6.8
CVE-2026-50507Windows BitLockerWindows BitLocker Security Feature BypassImportant6.8
CVE-2026-42903Windows KerberosWindows Kerberos Denial of ServiceImportant6.5
CVE-2026-42907Windows ShellWindows Shell Information DisclosureImportant6.5
CVE-2026-45454Microsoft Office SharePointMicrosoft SharePoint Remote Code ExecutionImportant6.5
CVE-2026-45501Microsoft Exchange ServerMicrosoft Exchange Server SpoofingImportant6.5
CVE-2026-47284Visual Studio CodeVisual Studio Code Information DisclosureImportant6.5
CVE-2026-47287Visual Studio CodeVisual Studio Code TamperingImportant6.5
CVE-2026-50508Windows NTLMWindows NTLM SpoofingImportant6.5
CVE-2026-50519GitHub Copilot and Visual Studio CodeMicrosoft Visual Studio Code CoPilot Chat Security Feature BypassImportant6.5
CVE-2026-45491.NET.NET TamperingImportant6.2
CVE-2026-45500Microsoft Exchange ServerMicrosoft Exchange Server SpoofingImportant6.1
CVE-2026-42906Windows ShellWindows Shell Information DisclosureImportant5.5
CVE-2026-42915Windows VMSwitchMicrosoft Windows VMSwitch Denial of ServiceImportant5.5
CVE-2026-42968Windows Telephony ServiceWindows Telephony Server Information DisclosureImportant5.5
CVE-2026-42969Windows Push NotificationsWindows Push Notification Information DisclosureImportant5.5
CVE-2026-42970Windows Push NotificationsWindows Push Notification Information DisclosureImportant5.5
CVE-2026-42971Windows Push NotificationsWindows Push Notification Information DisclosureImportant5.5
CVE-2026-42972Role: Windows Hyper-VWindows Hyper-V Information DisclosureImportant5.5
CVE-2026-42973Windows Push NotificationsWindows Push Notification Information DisclosureImportant5.5
CVE-2026-44805Windows Network Controller (NC) Host AgentWindows Network Controller (NC) Host Agent Denial of ServiceImportant5.5
CVE-2026-44814Windows DWM Core LibraryWindows DWM Core Library Information DisclosureImportant5.5
CVE-2026-44821Microsoft OfficeMicrosoft Office Information DisclosureImportant5.5
CVE-2026-45594Windows Application Identity (AppID) SubsystemWindows Application Identity (AppID) Information DisclosureImportant5.5
CVE-2026-45604Windows Application Identity (AppID) SubsystemWindows Managed Installer Information DisclosureImportant5.5
CVE-2026-45606Microsoft UxTheme Library (uxtheme.dll)Microsoft UxTheme Library (uxtheme.dll) Denial of ServiceImportant5.5
CVE-2026-45634Windows DHCP ServerWindows DHCP Client Information DisclosureImportant5.5
CVE-2026-45647Microsoft Defender for EndpointMicrosoft Defender for Endpoint for Mac Elevation of PrivilegeImportant5.5
CVE-2026-48566Windows DWM Core LibraryWindows DWM Core Library Information DisclosureImportant5.5
CVE-2026-33113Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant5.4
CVE-2026-45453Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant5.4
CVE-2026-45464Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant5.4
CVE-2026-45465Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant5.4
CVE-2026-45595Windows Mark of the Web (MOTW)Windows Mark of the Web Security Feature BypassImportant5.4
CVE-2026-47636Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant5.4
CVE-2026-47639Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant5.4
CVE-2026-48560Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant5.4
CVE-2026-42914Windows KerberosWindows Kerberos Denial of ServiceImportant5.3
CVE-2026-45655Windows BitLockerWindows BitLocker Security Feature BypassImportant5.3
CVE-2026-45502Microsoft Exchange ServerMicrosoft Exchange Server Information DisclosureImportant5.0
CVE-2026-45462Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant4.6
CVE-2026-45467Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant4.6
CVE-2026-45468Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant4.6
CVE-2026-45479Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant4.6
CVE-2026-45483Microsoft Office ProjectMicrosoft Office Project Server SpoofingImportant4.6
CVE-2026-47637Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant4.6
CVE-2026-47638Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant4.6
CVE-2026-47640Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant4.6
CVE-2026-47641Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant4.6
CVE-2026-48562Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant4.6
CVE-2026-45650Microsoft BingMicrosoft Bing Search SpoofingImportant4.3
CVE-2026-45642Microsoft Azure Attestation service and Device Health Attestation ServiceMicrosoft Azure Attestation service and Device Health Attestation Service SpoofingImportant3.9
CVE-2026-45455Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant3.3
CVE-2026-45459Microsoft Office ExcelMicrosoft Excel Security Feature BypassImportant3.3
CVE-2026-45466Microsoft Office WordMicrosoft Word Information DisclosureImportant3.3
CVE-2026-45485Microsoft OfficeMicrosoft Office Information DisclosureImportant3.3

Published later in the month (19)

Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.

DateCVEWhatSeverityAction
18 JunCVE-2026-45480Azure Active Directory Elevation of PrivilegeCriticalFixed by Microsoft
4 JunCVE-2026-48567Azure HorizonDB Elevation of PrivilegeCriticalFixed by Microsoft
18 JunCVE-2026-47647Dynamics 365 Elevation of PrivilegeCriticalFixed by Microsoft
18 JunCVE-2026-48584Microsoft Azure Synapse Elevation of PrivilegeCriticalFixed by Microsoft
18 JunCVE-2026-54130M365 Copilot Information DisclosureCriticalFixed by Microsoft
18 JunCVE-2026-48582Microsoft Exchange Online Elevation of PrivilegeCriticalFixed by Microsoft
18 JunCVE-2026-47646Dynamics 365 Customer Voice SpoofingCriticalFixed by Microsoft
4 JunCVE-2026-48579Microsoft Exchange Online Information DisclosureCriticalFixed by Microsoft
18 JunCVE-2026-32208Microsoft Entra ID SpoofingCriticalFixed by Microsoft
18 JunCVE-2026-47645Microsoft 365 Copilot's Business Chat Elevation of PrivilegeCriticalFixed by Microsoft
18 JunCVE-2026-32174Azure Bot Service Elevation of PrivilegeCriticalFixed by Microsoft
4 JunCVE-2026-45497Microsoft M365 Copilot Remote Code ExecutionCriticalFixed by Microsoft
18 JunCVE-2026-47633Microsoft Cost Management Information DisclosureCriticalFixed by Microsoft
4 JunCVE-2026-42824M365 Copilot Information DisclosureCriticalFixed by Microsoft
18 JunCVE-2026-42895Microsoft Copilot TamperingCriticalFixed by Microsoft
4 JunCVE-2026-47644Copilot Chat (Microsoft Edge) Information DisclosureCriticalFixed by Microsoft
4 JunCVE-2026-47655Microsoft Graph Information DisclosureCriticalFixed by Microsoft
26 JunCVE-2026-50521Microsoft Edge (Chromium-based) Remote Code ExecutionImportantUpdate
16 JunCVE-2026-50656Microsoft Defender Elevation of PrivilegeImportantUpdate

From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 2 weeks ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.

← All tools