Microsoft’s June 2026 Patch Tuesday delivered a record-setting security release, with reports citing 206 to 208 CVEs addressed across Windows, Office, Azure, SQL Server, and other products, including 32 critical issues. Among the most urgent were multiple Remote Desktop Client remote code execution flaws—CVE-2026-42985, CVE-2026-47289, CVE-2026-44801, CVE-2026-44799, and CVE-2026-48563—that could let an attacker run code on a victim system if the user connected to a malicious Remote Desktop Server or accepted a specially crafted RDP certificate. Microsoft rated CVE-2026-42985 as more likely to be exploited, while the others were assessed as less likely at publication; several of the bugs were credited to Kyeongmin Kim of KAIST Hacking Lab.
Microsoft also disclosed CVE-2026-47291, a critical HTTP.sys remote code execution vulnerability with a CVSS 9.8 score that can be exploited remotely without authentication or user interaction by sending a specially crafted packet to a server using the Windows HTTP Protocol Stack. Microsoft said systems using the default MaxRequestBytes setting are not affected, but warned that servers with higher values may be vulnerable and advised administrators to set the registry value to a safe level and restart the HTTP service or host until patches are applied. Cisco Talos published Snort coverage for many of the newly disclosed flaws, while separate reporting also highlighted one actively exploited zero-day in Microsoft Defender and additional high-risk issues in Hyper-V, DHCP Client, Secure Boot, and UEFI components.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Microsoft's Security Response Center published an advisory page for CVE-2026-3195 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.
Microsoft's Security Response Center published an advisory page for CVE-2026-49760 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.
Microsoft's Security Response Center published an advisory page for CVE-2026-11824 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.
Microsoft's Security Response Center published an advisory page for CVE-2025-49697 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.
Microsoft's Security Response Center published an advisory page for CVE-2025-49673 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.
Microsoft's Security Response Center published an advisory page for CVE-2025-48824 in its Update Guide. The existing timeline does not already include this specific vulnerability disclosure.
Following Microsoft's June 2026 Patch Tuesday disclosures, Cisco Talos published Snort coverage for many of the newly disclosed vulnerabilities. Talos specifically highlighted CVE-2026-42985, CVE-2026-47291, CVE-2026-44803, and CVE-2026-44812 as prominent issues and advised users to update to the latest rulesets.
On 2026-06-09, Microsoft received and published CVE-2026-45607, an out-of-bounds read vulnerability in Windows Hyper-V that could allow local code execution. The entry referenced Microsoft's Security Response Center update guide and classified the issue as high severity.
On 2026-06-09, Microsoft disclosed CVE-2026-47291, a critical Windows HTTP.sys remote code execution vulnerability that is network-exploitable without authentication or user interaction. Microsoft said exploitation was more likely, released a fix, and advised administrators to set MaxRequestBytes to a safe value and restart the HTTP service or system as a mitigation before patching.
On 2026-06-09, Microsoft disclosed several critical Remote Desktop Client remote code execution vulnerabilities, including CVE-2026-42985, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, and CVE-2026-48563. Microsoft said fixes were available for these issues and stated they were not publicly disclosed or exploited at publication, while rating CVE-2026-42985 as more likely to be exploited.
On 2026-06-09, Microsoft released its June 2026 Patch Tuesday updates, addressing a record-breaking set of vulnerabilities across its product portfolio. Sources describe the release as fixing 206 Microsoft vulnerabilities, while another report counts 208 Microsoft CVEs and 571 total when Chromium and bundled third-party components are included.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
22 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcemalware.news
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.