Skip to main content
QUIETLYTIC
Advisory

Microsoft Patch Tuesday June 2026: 1285 Vulnerabilities Fixed

Microsoft's June 9, 2026 Patch Tuesday fixed 1285 vulnerabilities (81 critical, 295 important) — none are currently listed as actively exploited, per CISA…

Microsoft Patch Tuesday June 2026: 1285 Vulnerabilities Fixed — Advisory research covering CVE-2026-45480, CVE-2026-48567, CVE-2026-47647, CVE-2026-48584, CVE-2026-52913, CVE-2026-52919, CVE-2026-52922, CVE-2026-52931, CVE-2026-52934, CVE-2026-52944, CVE-2026-52947, CVE-2026-52989, CVE-2026-52991, CVE-2026-52993, CVE-2026-53000, CVE-2026-53002, CVE-2026-53009, CVE-2026-53010, CVE-2026-53017, CVE-2026-53018, CVE-2026-53025, CVE-2026-53036, CVE-2026-53052, CVE-2026-53053, CVE-2026-53062, CVE-2026-53075, CVE-2026-53077, CVE-2026-53086, CVE-2026-53130, CVE-2026-53309, CVE-2026-26142, CVE-2026-44815, CVE-2026-45657, CVE-2026-47291, CVE-2026-53043, CVE-2026-53045, CVE-2026-53049, CVE-2026-54130, CVE-2026-48582, CVE-2025-10263, CVE-2026-47646, CVE-2026-34182, CVE-2026-48579, CVE-2026-32193, CVE-2026-32208, CVE-2026-42985, CVE-2026-45648, CVE-2026-47289, CVE-2026-47645, CVE-2026-44810, CVE-2026-45456, CVE-2026-45458, CVE-2026-45461, CVE-2026-45463, CVE-2026-45472, CVE-2026-45474, CVE-2026-45607, CVE-2026-45641, CVE-2026-47635, CVE-2026-45476, CVE-2026-47652, CVE-2026-42987, CVE-2026-56123, CVE-2026-33828, CVE-2026-44803, CVE-2026-44812, CVE-2026-48574, CVE-2026-32174, CVE-2026-45497, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-47633, CVE-2026-47654, CVE-2026-48563, CVE-2026-47288, CVE-2026-42824, CVE-2026-42895, CVE-2026-47644, CVE-2026-47655, CVE-2026-45460, CVE-2026-47643, CVE-2026-42904, CVE-2026-47281, CVE-2026-44631, CVE-2026-12087, CVE-2026-53176, CVE-2026-45602, CVE-2026-45447, CVE-2026-48715, CVE-2026-6893, CVE-2026-9698, CVE-2026-40371, CVE-2026-45484, CVE-2026-45504, CVE-2026-47653, CVE-2026-10879, CVE-2026-29167, CVE-2026-13325, CVE-2026-41098, CVE-2026-45482, CVE-2026-52911, CVE-2026-50521, CVE-2026-49759, CVE-2026-57235, CVE-2026-57236, CVE-2026-44822, CVE-2026-11816, CVE-2026-42055, CVE-2026-46331, CVE-2026-55200, CVE-2026-7383, CVE-2026-42835, CVE-2026-42974, CVE-2026-42981, CVE-2026-45503, CVE-2026-45599, CVE-2026-45635, CVE-2026-47631, CVE-2026-45644, CVE-2026-47298, CVE-2026-45588, CVE-2026-45654, CVE-2026-47656, CVE-2026-48568, CVE-2026-48570, CVE-2026-48573, CVE-2026-48575, CVE-2026-48576, CVE-2026-48578, CVE-2026-11332, CVE-2026-11822, CVE-2026-11824, CVE-2026-12505, CVE-2026-43958, CVE-2026-46243, CVE-2026-46274, CVE-2026-46324, CVE-2026-50256, CVE-2026-50258, CVE-2026-50259, CVE-2026-50261, CVE-2026-52908, CVE-2026-52909, CVE-2026-52910, CVE-2026-52912, CVE-2026-52923, CVE-2026-52926, CVE-2026-52935, CVE-2026-52943
Severity
Critical
Confidence
High
Status
Active

Full CVE Roster

All 150 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search — 1 flagged as actively exploited (KEV).

CVE ID Title CVSS Severity KEV
CVE-2026-45480 Azure Active Directory Elevation of Privilege Vulnerability 10.0 critical
CVE-2026-48567 Azure HorizonDB Elevation of Privilege Vulnerability 10.0 critical
CVE-2026-47647 Dynamics 365 Elevation of Privilege Vulnerability 9.9 critical
CVE-2026-48584 Microsoft Azure Synapse Elevation of Privilege Vulnerability 9.9 critical
CVE-2026-52913 batman-adv: v: stop OGMv2 on disabled interface 9.8 critical
CVE-2026-52919 batman-adv: fix tp_meter counter underflow during shutdown 9.8 critical
CVE-2026-52922 batman-adv: dat: handle forward allocation error 9.8 critical
CVE-2026-52931 batman-adv: tp_meter: avoid use of uninit sender vars 9.8 critical
CVE-2026-52934 batman-adv: tvlv: reject oversized TVLV packets 9.8 critical
CVE-2026-52944 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE 9.8 critical
CVE-2026-52947 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove 9.8 critical
CVE-2026-52989 nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers 9.8 critical
CVE-2026-52991 sched/psi: fix race between file release and pressure write 9.8 critical
CVE-2026-52993 tipc: fix double-free in tipc_buf_append() 9.8 critical
CVE-2026-53000 netfilter: nat: use kfree_rcu to release ops 9.8 critical
CVE-2026-53002 netfilter: conntrack: remove sprintf usage 9.8 critical
CVE-2026-53009 ice: fix double-free of tx_buf skb 9.8 critical
CVE-2026-53010 ksmbd: fix use-after-free in smb2_open during durable reconnect 9.8 critical
CVE-2026-53017 f2fs: fix data loss caused by incorrect use of nat_entry flag 9.8 critical
CVE-2026-53018 f2fs: avoid reading already updated pages during GC 9.8 critical
CVE-2026-53025 greybus: raw: fix use-after-free on cdev close 9.8 critical
CVE-2026-53036 bpf, arm64: Fix off-by-one in check_imm signed range check 9.8 critical
CVE-2026-53052 ASoC: qcom: qdsp6: topology: check widget type before accessing data 9.8 critical
CVE-2026-53053 iommu/amd: Fix clone_alias() to use the original device's devid 9.8 critical
CVE-2026-53062 dm cache policy smq: fix missing locks in invalidating cache blocks 9.8 critical
CVE-2026-53075 ppp: require CAP_NET_ADMIN in target netns for unattached ioctls 9.8 critical
CVE-2026-53077 net/rds: Restrict use of RDS/IB to the initial network namespace 9.8 critical
CVE-2026-53086 net: bcmgenet: fix racing timeout handler 9.8 critical
CVE-2026-53130 fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START 9.8 critical
CVE-2026-53309 ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison 9.8 critical
CVE-2026-26142 Nuance PowerScribe Remote Code Execution Vulnerability 9.8 critical
CVE-2026-44815 DHCP Client Service Remote Code Execution Vulnerability 9.8 critical
CVE-2026-45657 Windows Kernel Remote Code Execution Vulnerability 9.8 critical
CVE-2026-47291 HTTP.sys Remote Code Execution Vulnerability 9.8 critical
CVE-2026-53043 ocfs2/dlm: validate qr_numregions in dlm_match_regions() 9.8 critical
CVE-2026-53045 memory: tegra124-emc: Fix dll_change check 9.8 critical
CVE-2026-53049 gfs2: add some missing log locking 9.8 critical
CVE-2026-54130 M365 Copilot Information Disclosure Vulnerability 9.8 critical
CVE-2026-48582 Microsoft Exchange Online Elevation of Privilege Vulnerability 9.6 critical
CVE-2025-10263 ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] 9.3 critical
CVE-2026-47646 Dynamics 365 Customer Voice Spoofing Vulnerability 9.3 critical
CVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged Messages 9.1 critical
CVE-2026-48579 Microsoft Exchange Online Information Disclosure Vulnerability 9.1 critical
CVE-2026-32193 Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability 8.8 critical
CVE-2026-32208 Microsoft Entra ID Spoofing Vulnerability 8.8 critical
CVE-2026-42985 Remote Desktop Client Remote Code Execution Vulnerability 8.8 critical
CVE-2026-45648 Windows Active Directory Domain Services Remote Code Execution Vulnerability 8.8 critical
CVE-2026-47289 Remote Desktop Client Remote Code Execution Vulnerability 8.8 critical
CVE-2026-47645 Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability 8.8 critical
CVE-2026-44810 Microsoft Cryptographic Services Elevation of Privilege Vulnerability 8.4 critical
CVE-2026-45456 Microsoft Outlook and Word Remote Code Execution Vulnerability 8.4 critical
CVE-2026-45458 Microsoft Outlook and Word Remote Code Execution Vulnerability 8.4 critical
CVE-2026-45461 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-45463 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-45472 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-45474 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-45607 Windows Hyper-V Remote Code Execution Vulnerability 8.4 critical
CVE-2026-45641 Windows Hyper-V Remote Code Execution Vulnerability 8.4 critical
CVE-2026-47635 Microsoft Outlook and Word Remote Code Execution Vulnerability 8.4 critical
CVE-2026-45476 Microsoft Azure Network Adapter Elevation of Privilege Vulnerability 8.2 critical
CVE-2026-47652 Windows Hyper-V Remote Code Execution Vulnerability 8.2 critical
CVE-2026-42987 Windows Deployment Services (WDS) Remote Code Execution 8.1 critical
CVE-2026-56123 socat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser 8.1 critical
CVE-2026-33828 Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability 7.8 critical
CVE-2026-44803 Windows Graphics Component Remote Code Execution Vulnerability 7.8 critical
CVE-2026-44812 Windows Graphics Component Remote Code Execution Vulnerability 7.8 critical
CVE-2026-48574 Windows Media Remote Code Execution Vulnerability 7.8 critical
CVE-2026-32174 Azure Bot Service Elevation of Privilege Vulnerability 7.7 critical
CVE-2026-45497 Microsoft M365 Copilot Remote Code Execution Vulnerability 7.7 critical
CVE-2026-42992 Remote Desktop Client Remote Code Execution Vulnerability 7.5 critical
CVE-2026-44799 Remote Desktop Client Remote Code Execution Vulnerability 7.5 critical
CVE-2026-44801 Remote Desktop Client Remote Code Execution Vulnerability 7.5 critical
CVE-2026-47633 Microsoft Cost Management Information Disclosure Vulnerability 7.5 critical
CVE-2026-47654 Remote Desktop Client Remote Code Execution Vulnerability 7.5 critical
CVE-2026-48563 Remote Desktop Client Remote Code Execution Vulnerability 7.5 critical
CVE-2026-47288 Windows Kerberos Key Distribution Center (KDC) Remote Code Execution 7.1 critical
CVE-2026-42824 M365 Copilot Information Disclosure Vulnerability 6.5 critical
CVE-2026-42895 Microsoft Copilot Tampering Vulnerability 6.5 critical
CVE-2026-47644 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability 6.5 critical
CVE-2026-47655 Microsoft Graph Information Disclosure Vulnerability 6.5 critical
CVE-2026-45460 Microsoft Office Information Disclosure Vulnerability 4.7 critical
CVE-2026-47643 Azure Stack Edge Remote Code Execution Vulnerability 9.8 high
CVE-2026-42904 Windows TCP/IP Elevation of Privilege Vulnerability 9.6 high
CVE-2026-47281 Visual Studio Code Elevation of Privilege Vulnerability 9.6 high
CVE-2026-44631 Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow 9.4 high
CVE-2026-12087 Socket versions before 2.041 for Perl have an out-of-bounds heap read 9.1 high
CVE-2026-53176 IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN 9.1 high
CVE-2026-45602 Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability 9.1 high
CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Function 8.8 high
CVE-2026-48715 radvdump's Route Information Option Parser has a Stack Buffer Overflow 8.8 high
CVE-2026-6893 Dracut: dracut: root code execution via dhcp options command injection 8.8 high
CVE-2026-9698 DBI versions before 1.648 for Perl saved errors in a limited-sized buffer 8.8 high
CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability 8.8 high
CVE-2026-45484 Microsoft SharePoint Elevation of Privilege Vulnerability 8.8 high
CVE-2026-45504 Microsoft Exchange Server Elevation of Privilege Vulnerability 8.8 high
CVE-2026-47653 Remote Desktop Client Remote Code Execution Vulnerability 8.8 high
CVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders 8.6 high
CVE-2026-29167 Apache HTTP Server: mod_ldap per-dir use-after-free 8.6 high
CVE-2026-13325 Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces 8.5 high
CVE-2026-41098 Azure Stack Edge Spoofing Vulnerability 8.4 high
CVE-2026-45482 Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability 8.4 high
CVE-2026-52911 ksmbd: scope conn->binding slowpath to bound sessions only 8.4 high
CVE-2026-50521 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 8.3 high
CVE-2026-49759 Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash 8.2 high
CVE-2026-57235 Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` 8.2 high
CVE-2026-57236 Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception 8.2 high
CVE-2026-44822 Microsoft Excel Information Disclosure Vulnerability 8.2 high
CVE-2026-11816 Path Traversal in keras-team/keras 8.1 high
CVE-2026-42055 NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability 8.1 high
CVE-2026-46331 net/sched: fix pedit partial COW leading to page cache corruption 8.1 high Yes
CVE-2026-55200 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c 8.1 high
CVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion 8.1 high
CVE-2026-42835 Microsoft Teams for Android Information Disclosure Vulnerability 8.1 high
CVE-2026-42974 Windows Performance Monitor Remote Code Execution Vulnerability 8.1 high
CVE-2026-42981 Windows Performance Monitor Remote Code Execution Vulnerability 8.1 high
CVE-2026-45503 Microsoft Exchange Server Information Disclosure Vulnerability 8.1 high
CVE-2026-45599 Windows UPnP Device Host Remote Code Execution Vulnerability 8.1 high
CVE-2026-45635 Windows UPnP Device Host Remote Code Execution Vulnerability 8.1 high
CVE-2026-47631 Microsoft Exchange Server Spoofing Vulnerability 8.1 high
CVE-2026-45644 Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability 8.0 high
CVE-2026-47298 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.0 high
CVE-2026-45588 Secure Boot Security Feature Bypass Vulnerability 7.9 high
CVE-2026-45654 Secure Boot Security Feature Bypass Vulnerability 7.9 high
CVE-2026-47656 Windows Boot Manager Security Feature Bypass Vulnerability 7.9 high
CVE-2026-48568 Secure Boot Security Feature Bypass Vulnerability 7.9 high
CVE-2026-48570 Secure Boot Security Feature Bypass Vulnerability 7.9 high
CVE-2026-48573 Secure Boot Security Feature Bypass Vulnerability 7.9 high
CVE-2026-48575 Secure Boot Security Feature Bypass Vulnerability 7.9 high
CVE-2026-48576 Secure Boot Security Feature Bypass Vulnerability 7.9 high
CVE-2026-48578 Secure Boot Security Feature Bypass Vulnerability 7.9 high
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution 7.8 high
CVE-2026-11822 SQLite before 3.53.2 Memory Corruption in FTS5 Extension 7.8 high
CVE-2026-11824 SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate 7.8 high
CVE-2026-12505 Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall 7.8 high
CVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service 7.8 high
CVE-2026-46243 smb: client: reject userspace cifs.spnego descriptions 7.8 high
CVE-2026-46274 io-wq: check that the predecessor is hashed in io_wq_remove_pending() 7.8 high
CVE-2026-46324 netfilter: nf_tables: use list_del_rcu for netlink hooks 7.8 high
CVE-2026-50256 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch 7.8 high
CVE-2026-50258 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels 7.8 high
CVE-2026-50259 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing 7.8 high
CVE-2026-50261 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter() 7.8 high
CVE-2026-52908 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible 7.8 high
CVE-2026-52909 ip6_vti: set netns_immutable on the fallback device. 7.8 high
CVE-2026-52910 bpf: Free reuseport cBPF prog after RCU grace period. 7.8 high
CVE-2026-52912 netfilter: nf_queue: hold bridge skb->dev while queued 7.8 high
CVE-2026-52923 ipc: limit next_id allocation to the valid ID range 7.8 high
CVE-2026-52926 batman-adv: clear current gateway during teardown 7.8 high
CVE-2026-52935 xfrm: espintcp: do not reuse an in-progress partial send 7.8 high
CVE-2026-52943 net: skbuff: fix missing zerocopy reference in pskb_carve helpers 7.8 high

Microsoft’s June 9, 2026 Patch Tuesday release covers 1285 CVEs: 81 rated critical, 295 rated important, and 334 rated moderate. Of these, none are currently listed as actively exploited.

Severity Breakdown

Severity Count
Critical 81
Important 295
Moderate 334
Actively exploited (CISA KEV) 0

Highest-Severity Vulnerabilities

Top 20 of 1285 total, by CVSS/severity:

CVE Title CVSS
CVE-2026-45480 Azure Active Directory Elevation of Privilege Vulnerability 10.0
CVE-2026-48567 Azure HorizonDB Elevation of Privilege Vulnerability 10.0
CVE-2026-47647 Dynamics 365 Elevation of Privilege Vulnerability 9.9
CVE-2026-48584 Microsoft Azure Synapse Elevation of Privilege Vulnerability 9.9
CVE-2026-52913 batman-adv: v: stop OGMv2 on disabled interface 9.8
CVE-2026-52919 batman-adv: fix tp_meter counter underflow during shutdown 9.8
CVE-2026-52922 batman-adv: dat: handle forward allocation error 9.8
CVE-2026-52931 batman-adv: tp_meter: avoid use of uninit sender vars 9.8
CVE-2026-52934 batman-adv: tvlv: reject oversized TVLV packets 9.8
CVE-2026-52944 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE 9.8
CVE-2026-52947 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove 9.8
CVE-2026-52989 nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers 9.8
CVE-2026-52991 sched/psi: fix race between file release and pressure write 9.8
CVE-2026-52993 tipc: fix double-free in tipc_buf_append() 9.8
CVE-2026-53000 netfilter: nat: use kfree_rcu to release ops 9.8
CVE-2026-53002 netfilter: conntrack: remove sprintf usage 9.8
CVE-2026-53009 ice: fix double-free of tx_buf skb 9.8
CVE-2026-53010 ksmbd: fix use-after-free in smb2_open during durable reconnect 9.8
CVE-2026-53017 f2fs: fix data loss caused by incorrect use of nat_entry flag 9.8
CVE-2026-53018 f2fs: avoid reading already updated pages during GC 9.8

CVSS scores are sourced directly from Microsoft’s CVRF data as of June 9, 2026; exploitation status is cross-checked against CISA’s KEV catalog. Later re-scoring by NVD can shift a CVE’s score after this report was generated.

Why This Matters

No vulnerabilities in this release are yet listed in CISA’s Known Exploited Vulnerabilities catalog, but that can change quickly once a patch is public and attackers reverse-engineer it. Organizations should prioritize the critical- and important-rated CVEs above, especially any with public proof-of-concept exploits.

Frequently Asked Questions

How many vulnerabilities did Microsoft patch in June 2026? 1285 CVEs, per Microsoft’s June 9, 2026 Patch Tuesday release.

Were any June 2026 Patch Tuesday vulnerabilities actively exploited? Not as of June 9, 2026, per CISA’s Known Exploited Vulnerabilities (KEV) catalog — this can change as exploitation is discovered after release.


Data sourced from Microsoft Security Response Center (MSRC) CVRF v3.0 and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated June 9, 2026. See more vulnerability research.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 Microsoft Security Response Center (MSRC)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Cross-referenced intelligence


Analyst tools