Microsoft released its monthly security updates on 10 June 2026, fixing 206 vulnerabilities across Windows, Office, Exchange Server, and other products. Six of these were zero-day vulnerabilities, with one confirmed to be actively exploited in attacks before a patch was available.
- 206 vulnerabilities patched in total, including 33 rated Critical
- 6 zero-days disclosed, with 1 actively exploited in the wild before the patch was released
- Critical areas affected: Windows DNS, NTFS, Hyper-V, BitLocker, Bluetooth, Exchange Server, and Microsoft Copilot
- 28 of the 33 Critical vulnerabilities are remote code execution (RCE) flaws — meaning an attacker could run malicious code on your systems without requiring any user interaction
- Exchange Server received dedicated security updates released alongside the main Patch Tuesday bundle
- Microsoft 365 Copilot and Exchange Online also received fixes for an RCE flaw and a critical information disclosure flaw, patched on the cloud side — no end-user action required for those
If your business runs Windows PCs or servers, these updates should be applied as soon as possible — particularly for any internet-facing systems. Businesses on managed IT services will have these updates rolled out through their normal patching cycle. If you manage your own IT, we recommend applying the June 2026 updates without delay.
Sources: Microsoft Security Update Guide | BleepingComputer | Qualys