Web_Logo
Remote Support
Microsoft Windows: Record June Patch Tuesday — 206 Vulnerabilities Fixed
Home » Microsoft Updates  »  Microsoft Windows: Record June Patch Tuesday — 206 Vulnerabilities Fixed

Microsoft Windows: Record June Patch Tuesday — 206 Vulnerabilities Fixed

Microsoft has released its June 2026 Patch Tuesday security updates — the largest in the program's 23-year history — fixing 206 vulnerabilities across Windows, Office, Exchange Server, and Azure. Three of the flaws are zero-days, meaning they were publicly known or actively exploited before a patch existed.

Key vulnerabilities patched this month:

  • CVE-2026-49160 (HTTP.sys Denial of Service): A remotely exploitable flaw in Windows web server components that can be used to take systems offline through specially crafted network requests.
  • CVE-2026-45586 (Windows Privilege Escalation): Allows a local attacker to gain full SYSTEM-level access on a Windows machine. This was publicly disclosed before the patch was released.
  • CVE-2026-50507 (BitLocker Bypass): An attacker with physical access to a device can bypass BitLocker drive encryption protection.

Additional critical patches cover Windows DNS, Hyper-V, Remote Desktop, Kerberos, Exchange Server, and Microsoft Office. In total, 33 vulnerabilities are rated Critical and 55 involve remote code execution.

Businesses running Windows or Office should confirm that Windows Update has applied this month's patches across all devices. If your organisation uses an IT provider for patch management, contact them to confirm June patching is complete.

Sources: Bleeping Computer | Microsoft Security Update Guide