Blog

Microsoft Patch Tuesday – June 2026

13 min. read
10/06/2026
By Esben Dochy
Patch Tuesday
Microsoft Patch Tuesday

⚡ TL;DR | Go Straight to the June 2026 Patch Tuesday Audit Report

Patch Tuesday is once again upon us. As always, our team has put together the monthly Patch Tuesday Report to help you manage your update progress. The audit report gives you a quick and clear overview of your Windows machines and their patching status. The June 2026 edition of Patch Tuesday brings us 229 fixes, with 33 rated as critical. We’ve listed the most important changes below.

Windows HTTP.sys Remote Code Execution Vulnerability

CVE-2026-47291 is the one to patch first this month. HTTP.sys is the kernel-mode driver that sits underneath IIS and a long list of other Windows services, so a flaw here reaches a lot further than a single application. With a CVSS score of 9.8, this is an unauthenticated remote code execution bug that an attacker can trigger over the network without any privileges and without any user interaction.

In practice that means a specially crafted request sent to a vulnerable, internet-facing Windows web server could let an attacker run code in the context of the kernel. The combination of network reach, no authentication, and no clicks required is exactly the profile that tends to get weaponized quickly, and it gives this one real wormable potential. If you run any public-facing IIS or HTTP.sys-backed service, treat this as your top priority.

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2026-44803 and CVE-2026-44812 are two critical remote code execution flaws in the Windows Graphics Component, both rated 7.8 and both assessed by Microsoft as more likely to be exploited. They share the same shape: an attacker crafts a malicious file or image, and code runs the moment the target opens it.

Exploitation is local and requires user interaction, so these rely on the usual delivery methods, a phishing attachment, a download, or a booby-trapped document, rather than a direct network hit. The graphics-rendering stack is a perennial favorite for attackers precisely because rendering an image is something users do without a second thought, which makes prompt patching the only reliable defense here.

Microsoft SharePoint Server Spoofing Vulnerability

CVE-2026-47634 and CVE-2026-45481 are two spoofing vulnerabilities in on-premises Microsoft SharePoint Server, each rated 7.3 and flagged as more likely to be exploited. Both are network-accessible and require only low privileges plus some user interaction to pull off.

Spoofing flaws in SharePoint can be used to misrepresent content or identity within the platform, setting up convincing phishing or social-engineering follow-ups against users who trust what they see in their own SharePoint environment. On-prem SharePoint has taken more than its share of attention from attackers over the past year, so anyone still running it should get these in quickly.

Run the Patch Tuesday June 2026 Audit

To help manage your update progress, we’ve created the Patch Tuesday Audit that checks if the assets in your network are on the latest patch updates. The report has been color-coded to see which machines are up-to-date and which ones still need to be updated. As always, system administrators are urged to update their environment as soon as possible to ensure all endpoints are secured.

The Lansweeper Patch Tuesday report is automatically added to your Lansweeper Site. Lansweeper Sites is included in all our licenses without any additional cost and allows you to federate all your installations into one single view so all you need to do is look at one report, automatically added every patch Tuesday!

Patch Tuesday June 2026 CVE Codes & Titles

CVETitle
CVE-2025-10263ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel]
CVE-2026-10722cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
CVE-2026-10879DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders
CVE-2026-11463USCiLab Cereal Shared Pointer type confusion
CVE-2026-26142Nuance PowerScribe Remote Code Execution Vulnerability
CVE-2026-27145Inefficient candidate hostname parsing in crypto/x509
CVE-2026-32193Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability
CVE-2026-33113Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-33828Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability
CVE-2026-34335Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-37460Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CVE-2026-40371Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
CVE-2026-40376Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-40404Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-40409Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-40930LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body
CVE-2026-41092Microsoft Kinect Elevation of Privilege Vulnerability
CVE-2026-41098Azure Stack Edge Spoofing Vulnerability
CVE-2026-41108Windows DNS Client Elevation of Privilege Vulnerability
CVE-2026-42504Quadratic complexity in WordDecoder.DecodeHeader in mime
CVE-2026-42507Arbitrary inputs are included in errors without any escaping in net/textproto
CVE-2026-42828Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-42829Windows Administrator Protection Secure Feature Bypass Vulnerability
CVE-2026-42835Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2026-42836Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-42837Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-42902Microsoft PowerToys Elevation of Privilege Vulnerability
CVE-2026-42903Windows Kerberos Denial of Service Vulnerability
CVE-2026-42904Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-42905Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42906Windows Shell Information Disclosure Vulnerability
CVE-2026-42907Windows Shell Information Disclosure Vulnerability
CVE-2026-42908Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-42909Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42910Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability
CVE-2026-42911Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-42912Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-42913Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42914Windows Kerberos Denial of Service Vulnerability
CVE-2026-42915Windows TCP/IP Denial of Service Vulnerability
CVE-2026-42916NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-42968Windows Telephony Server Information Disclosure Vulnerability
CVE-2026-42969Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42970Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42971Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42972Windows Hyper-V Information Disclosure Vulnerability
CVE-2026-42973Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42974Windows Performance Monitor Remote Code Execution Vulnerability
CVE-2026-42977Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42978Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42979Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42980NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-42981Windows Performance Monitor Remote Code Execution Vulnerability
CVE-2026-42983Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42984Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-42985Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42986Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-42987Windows Deployment Services (WDS) Remote Code Execution
CVE-2026-42989Winlogon Elevation of Privilege Vulnerability
CVE-2026-42991Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42992Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42993Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-43958Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service
CVE-2026-44799Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-44801Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-44802Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44803Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-44804Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44805Windows Network Controller (NC) Host Agent Denial of Service Vulnerability
CVE-2026-44807Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44808Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44809Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-44810Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2026-44811Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44812Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-44813Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44814Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-44815DHCP Client Service Remote Code Execution Vulnerability
CVE-2026-44817Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-44818Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-44819Microsoft Office Remote Code Execution Vulnerability
CVE-2026-44820Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-44821Microsoft Office Information Disclosure Vulnerability
CVE-2026-44822Microsoft Excel Information Disclosure Vulnerability
CVE-2026-44823Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-44824Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45453Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45454Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2026-45455Microsoft Excel Information Disclosure Vulnerability
CVE-2026-45456Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-45457Microsoft Word Remote Code Execution Vulnerability
CVE-2026-45458Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-45459Microsoft Excel Security Feature Bypass Vulnerability
CVE-2026-45460Microsoft Office Information Disclosure Vulnerability
CVE-2026-45461Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45462Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45463Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45464Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45465Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45466Microsoft Word Information Disclosure Vulnerability
CVE-2026-45467Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45468Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45469Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-45471Microsoft Word Remote Code Execution Vulnerability
CVE-2026-45472Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45474Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45475Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45476Microsoft Azure Network Adapter Elevation of Privilege Vulnerability
CVE-2026-45479Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45481Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-45482Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability
CVE-2026-45483Microsoft Office Project Server Spoofing Vulnerability
CVE-2026-45484Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2026-45485Microsoft Office Information Disclosure Vulnerability
CVE-2026-45486Microsoft Word Remote Code Execution Vulnerability
CVE-2026-45487Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
CVE-2026-45490.NET SDK Elevation of Privilege Vulnerability
CVE-2026-45491.NET Tampering Vulnerability
CVE-2026-45500Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-45501Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-45502Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2026-45503Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2026-45504Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-45583Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2026-45586Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
CVE-2026-45588Secure Boot Security Feature Bypass Vulnerability
CVE-2026-45591ASP.NET Core Denial of Service Vulnerability
CVE-2026-45592Windows Internet (wininet.dll) Elevation of Privilege Vulnerability
CVE-2026-45593Windows SDK Elevation of Privilege Vulnerability
CVE-2026-45594Windows Application Identity (AppID) Information Disclosure Vulnerability
CVE-2026-45595Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2026-45596Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45597Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability
CVE-2026-45598Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45599Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-45600Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-45601Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45602Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
CVE-2026-45603Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45604Windows Managed Installer Information Disclosure Vulnerability
CVE-2026-45605Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2026-45606Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability
CVE-2026-45607Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-45608Windows DHCP Client Information Disclosure Vulnerability
CVE-2026-45634Windows DHCP Client Information Disclosure Vulnerability
CVE-2026-45635Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-45636Windows NTFS Remote Code Execution Vulnerability
CVE-2026-45637Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-45638Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45639Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-45640Windows Bluetooth Port Driver Elevation of Privilege Vulnerability
CVE-2026-45641Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-45642Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability
CVE-2026-45643Microsoft Word Remote Code Execution Vulnerability
CVE-2026-45644Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability
CVE-2026-45645Microsoft Office Remote Code Execution Vulnerability
CVE-2026-45647Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
CVE-2026-45648Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-45649Office for Android Spoofing Vulnerability
CVE-2026-45650Microsoft Bing Search Spoofing Vulnerability
CVE-2026-45653Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-45654Secure Boot Security Feature Bypass Vulnerability
CVE-2026-45655Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-45656UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-45657Windows Kernel Remote Code Execution Vulnerability
CVE-2026-45658Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-46250MIPS: Work around LLVM bug when gp is used as global register variable
CVE-2026-46272coresight: tmc-etr: Fix race condition between sysfs and perf mode
CVE-2026-46273ibmveth: Disable GSO for packets with small MSS
CVE-2026-47281Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-47284Visual Studio Code Information Disclosure Vulnerability
CVE-2026-47287Visual Studio Code Tampering Vulnerability
CVE-2026-47288Windows Kerberos Key Distribution Center (KDC) Remote Code Execution
CVE-2026-47289Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-47291HTTP.sys Remote Code Execution Vulnerability
CVE-2026-47292Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability
CVE-2026-47293Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVE-2026-47298Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-47631Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-47634Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47635Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-47636Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47637Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47638Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47639Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47640Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47641Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-47643Azure Stack Edge Remote Code Execution Vulnerability
CVE-2026-47648Windows Storage Elevation of Privilege Vulnerability
CVE-2026-47652Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-47653Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-47654Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-47656Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2026-48560Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-48562Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-48563Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-48565Windows Narrator Braille Elevation of Privilege Vulnerability
CVE-2026-48566Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-48568Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48569Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-48570Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48573Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48574Windows Media Remote Code Execution Vulnerability
CVE-2026-48575Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48576Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48578Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48583Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-49160HTTP.sys Denial of Service Vulnerability
CVE-2026-49161Microsoft PC Manager Security Feature Bypass Vulnerability
CVE-2026-49975Apache HTTP Server: mod_http2 denial of service
CVE-2026-50031ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages.
CVE-2026-50219libexpat before 2.8.2 lacks handler call depth tracking, leading to a use-after-free
CVE-2026-50256xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch
CVE-2026-50257xorg-x11-server: use-after-free in misyncdestroyfence()
CVE-2026-50258xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels
CVE-2026-50259xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing
CVE-2026-50260xorg-x11-server: use-after-free in freecounter()
CVE-2026-50261xorg-x11-server: use-after-free in syncchangecounter()
CVE-2026-50262xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes
CVE-2026-50263xorg-x11-server: use-after-free information disclosure in createsaverwindow()
CVE-2026-50265Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292
CVE-2026-50292In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
CVE-2026-50507Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-50508Windows NTLM Spoofing Vulnerability
CVE-2026-50511Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2026-50512Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2026-7774tarfile.data_filter path traversal bypass allows writing outside the extraction directory
CVE-2026-8643pip can extract console_scripts and gui_scripts outside installation directory
CVE-2026-8863UEFI Secure Boot Security Feature Bypass Vulnerability

Ready to get started?

Explore the full platform, free for 14 days.
No credit card required.

Need help evaluating?
Get guidance on pricing at scale and enterprise requirements.
Talk to sales
Clear pricing as you grow
Transparent plans that scale with your environment.
View plans & pricing