Microsoft released its monthly Windows security update today, Tuesday 9 June 2026. This month's update carries extra urgency due to a critical security deadline on 26 June 2026 — just 17 days away.
Since 2011, Windows computers have used a specific Secure Boot certificate to verify that software loaded at startup is legitimate and has not been tampered with. Those certificates are expiring on 26 June 2026. Microsoft is replacing them with updated 2023 versions, and today's Patch Tuesday is the final scheduled opportunity to deploy the replacement before the deadline.
Key facts for businesses:
- All Windows 10 and Windows 11 PCs must receive this update before 26 June 2026.
- After that date, any device that has not been updated will lose the ability to receive boot-level security protections — leaving it vulnerable to a class of malware that loads before Windows itself starts.
- In most managed business environments, Windows Update handles this automatically. IT administrators should verify no devices have been missed and restart any devices with pending updates.
- This month's update also addresses a Windows Kernel Elevation of Privilege vulnerability (CVE-2026-33841) and an actively exploited Exchange Server vulnerability (CVE-2026-42897).
What to do:
- If your Windows devices update automatically, check that updates have completed and no restarts are pending.
- If your business has an IT provider managing updates, confirm with them that deployment is underway this week — the 26 June deadline leaves no room to defer.
- Devices that have not installed this update by 26 June will enter a degraded security state with no simple remediation path.
We recommend treating this as a priority action for this week. Sources: Microsoft Security Update Guide, Patch Tuesday June 2026 Analysis.