Microsoft released its largest Patch Tuesday update to date, fixing 206 vulnerabilities across Windows, Office, Azure, Exchange, SharePoint, SQL Server, Visual Studio, Copilot-related offerings, and other products. Multiple reports said the release included three publicly disclosed zero-days, while Microsoft separately noted an earlier out-of-band fix for the actively exploited Microsoft Defender flaw CVE-2026-41091. Publicly disclosed issues in the June bundle included CVE-2026-50507, a BitLocker security feature bypass that could expose encrypted data with physical access and available proof-of-concept code, and CVE-2026-45586, a Windows CTFMON elevation-of-privilege flaw that could let a low-privileged local attacker gain SYSTEM access. JPCERT/CC also warned that Microsoft disclosed active exploitation of CVE-2026-42897, a spoofing flaw in Microsoft Exchange Server.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
100 events from the most recent confirmed update back to the earliest known activity.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53209. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-9697. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53242. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-52930. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53247. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53176. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53154. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53217. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-52923. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-52922. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53160. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-52915. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-52934. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53270. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-52924. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-9675. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53133. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-52943. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53230. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-52947. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53186. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53266. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53177. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53143. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53239. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53148. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53228. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-52916. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53213. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-52913. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53196. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53146. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53214. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53225. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-55200. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53254. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12442. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-11647. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12028. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-50521. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-13035. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-13031. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-13026. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-13038. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-13036. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-13029. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12087. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-4367. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-13027. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-53689. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-43973. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-9698. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12455. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12447. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12441. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12457. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12445. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12454. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12465. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12459. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12439. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12462. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12464. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12446. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12440. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12466. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12443. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-42895. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-47645. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-48582. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-32208. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-32174. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-48584. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-47646. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-42766. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-48856. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-48860. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-49759. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-7383. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-42767. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-34180. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-48858. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-9076. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-47647. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-54130. The CVE is not present in the existing timeline, making this a new disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12451. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12452. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12458. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-12453. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-48855. The CVE is not present in the existing timeline, making this a distinct disclosure event.
Microsoft published an MSRC vulnerability advisory for CVE-2026-50656. The existing timeline does not already include this CVE, making it a distinct disclosure event.
JPCERT/CC said Microsoft had disclosed active exploitation of CVE-2026-42897, a spoofing vulnerability in Microsoft Exchange Server, and noted the flaw had been publicly announced on May 14. The advisory urged users to apply Microsoft's June 2026 security updates.
New CVE entries were published for CVE-2026-45641 in Windows Hyper-V, CVE-2026-47298 in SharePoint Server, CVE-2026-45503 in Exchange Server, and CVE-2026-45602 in Windows DHCP Server. The entries described high-severity vulnerabilities and referenced Microsoft's Security Response Center guidance.
Microsoft released Windows 10 cumulative update KB5094127 for Enterprise LTSC and Extended Security Updates customers, advancing systems to build 19045.7417 and LTSC 2021 to 19044.7417. The update incorporated June 2026 Patch Tuesday fixes and added Secure Boot monitoring and File Explorer search improvements.
Microsoft released Windows 11 cumulative updates KB5094126 for versions 25H2/24H2 and KB5093998 for version 23H2 as part of Patch Tuesday. The mandatory updates included security fixes plus reliability and feature improvements, and Microsoft said it was not aware of new known issues.
Microsoft disclosed multiple Remote Desktop Client remote code execution vulnerabilities, including CVE-2026-42909, CVE-2026-42913, CVE-2026-42992, CVE-2026-47653, and CVE-2026-47654. The flaws generally required a victim to connect to an attacker-controlled RDP server, and Microsoft said fixes were available.
Microsoft disclosed CVE-2026-45586, an Important elevation-of-privilege flaw in the Windows Collaborative Translation Framework that could let a low-privileged local attacker gain SYSTEM privileges. Microsoft said the issue was publicly disclosed, not actively exploited, and fixed.
Microsoft disclosed CVE-2026-50507, an Important Windows BitLocker security feature bypass vulnerability requiring physical access. Microsoft said the flaw was publicly disclosed, proof-of-concept code was available, exploitation was considered more likely, and a fix was released.
Microsoft published its June 2026 Patch Tuesday advisories and updates, addressing a record 206 vulnerabilities across products and services. Multiple sources describe the release as Microsoft's largest monthly patch set on record.
Microsoft disclosed CVE-2026-48567, a critical Azure HorizonDB elevation-of-privilege vulnerability with a CVSS score of 10.0. Microsoft said the cloud service issue had already been fully mitigated and required no customer action.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.