Microsoft has released its largest-ever monthly security update, fixing around 200 vulnerabilities across Windows, Office, Exchange and Azure. Several of these flaws were already being used in real-world attacks before the fix was available.
- What it is: The June 2026 Patch Tuesday update, released 10 June, addresses roughly 200 vulnerabilities, including 33 rated Critical.
- Who is affected: All businesses running Windows 11, Windows Server, Microsoft Office, Exchange Server and related Microsoft products.
- The risk: At least one flaw is confirmed under active attack, including a Windows Defender privilege-escalation issue and a Common Log File System driver flaw that can give an attacker full control of a device.
- What to do: Make sure Windows Update has applied the June 2026 updates on all computers and servers. Restart devices to complete installation, as some patches do not take effect until a reboot.
Businesses should confirm these updates have rolled out across all devices, not just the machines in daily use. OzComm clients on our managed update service are already covered; contact us if you would like us to confirm your patch status.
Sources: BleepingComputer, Qualys.