patch tuesday

  1. CVE-2026-45599: Windows UPnP Device Host RCE (Use-After-Free) Patched June 9, 2026

    Microsoft disclosed CVE-2026-45599 on June 9, 2026, as a high-severity Windows UPnP Device Host remote code execution vulnerability in Universal Plug and Play’s upnp.dll, with an 8.1 CVSS score and patches released through the June Patch Tuesday security updates. The bug is not the loudest item...
  2. CVE-2026-45597: Windows UI Automation Manager Local EoP Fix (June 9, 2026)

    Microsoft’s June 9, 2026 security update identifies CVE-2026-45597 as a Windows UI Automation Manager elevation-of-privilege vulnerability in uiamanager.dll, a local Windows component tied to accessibility and cross-process interface automation. The immediate story is not a remote worm or a...
  3. CVE-2026-45595 Patch Tuesday: Windows Mark of the Web Bypass (Important)

    Microsoft patched CVE-2026-45595, a Windows Mark of the Web security feature bypass vulnerability rated Important, as part of the June 9, 2026 Patch Tuesday release for supported Windows systems. The bug matters less because it is glamorous than because it touches one of Windows’ quietest lines...
  4. CVE-2026-45604 Patch Tuesday: Windows Managed Installer Info Leak & App Control Trust

    Microsoft disclosed CVE-2026-45604 on June 9, 2026, as an Important-rated Windows Managed Installer information disclosure vulnerability in the Windows Application Identity subsystem, shipping it inside a very large June Patch Tuesday release that addressed roughly 200 Microsoft flaws. The bug...
  5. June 2026 Patch Tuesday: Prioritize RCE Risks Across Windows, Office, Azure

    Microsoft’s June 2026 Patch Tuesday, released on June 9, delivers security fixes for roughly 200 disclosed vulnerabilities across Windows, Office, Azure, Exchange Online, Microsoft Graph, SQL Server, and related services, including 32 bugs Microsoft rated critical and a Talos Snort ruleset...
  6. CVE-2026-45593: Windows SDK EoP—Why Build Systems Must Be Patched Fast

    Microsoft disclosed CVE-2026-45593 on June 9, 2026, as a Windows SDK elevation-of-privilege vulnerability in its Security Update Guide, placing a developer-facing component into the same Patch Tuesday risk conversation usually dominated by Windows kernel, browser, and server flaws. The important...
  7. CVE-2026-45592 WinINet EoP: Why the June Patch for Windows Must Be Priority

    Microsoft has published CVE-2026-45592 as a Windows Internet (wininet.dll) elevation-of-privilege vulnerability in the Security Update Guide on June 9, 2026, signaling that supported Windows systems should receive the applicable June security update even though public technical detail remains...
  8. Windows 10 KB5094127 (June 2026) ESU Update: Build 19045.7417 & Secure Boot

    Microsoft released Windows 10 KB5094127 on June 9, 2026, as the June Patch Tuesday cumulative update for Windows 10 22H2 systems covered by Extended Security Updates, raising eligible PCs to build 19045.7417 and adding File Explorer search fixes, Secure Boot certificate status reporting, and...
  9. CVE-2026-42835: High-Severity Microsoft Teams Android Info Disclosure Fix

    Microsoft disclosed CVE-2026-42835 on June 9, 2026, as a high-severity Microsoft Teams for Android information disclosure vulnerability that can let an authorized attacker disclose information over a network through an injection weakness in the app. The headline is not that Teams for Android...
  10. CVE-2026-42828: Windows ProjFS Elevation of Privilege—June 2026 Patch Guide

    Microsoft has disclosed CVE-2026-42828, an elevation-of-privilege vulnerability in the Windows Projected File System, as part of its June 2026 security guidance for Windows systems, with the practical risk centered on local attackers who already have some access and are trying to turn that...
  11. CVE-2026-40371: Patch Tuesday EoP Risk in Microsoft Dynamics 365 On-Prem

    On June 9, 2026, Microsoft disclosed CVE-2026-40371, an Important-rated elevation-of-privilege vulnerability in Microsoft Dynamics 365 on-premises, as part of its June Patch Tuesday security release for Windows, server, cloud, developer, and business-application products. The bug is not the...
  12. CVE-2026-49161: Microsoft PC Manager Security Feature Bypass (Patch Tuesday)

    Microsoft disclosed CVE-2026-49161 on June 9, 2026, as an Important-rated security feature bypass vulnerability in Microsoft PC Manager, part of the company’s June Patch Tuesday release, which also covered roughly 200 Microsoft vulnerabilities across Windows, Office, Exchange, developer tools...
  13. CVE-2026-48578 Secure Boot Bypass: Patch Tuesday Fix for Windows (June 2026)

    Microsoft published CVE-2026-48578 on June 9, 2026, describing an Important-rated Windows Secure Boot security feature bypass that can let a highly privileged local attacker defeat Secure Boot protections across supported Windows client and server releases. The short version is simple enough for...
  14. CVE-2026-48575 Secure Boot Bypass: June 2026 Fix for Windows Local High-Priv Flaw

    Microsoft disclosed CVE-2026-48575 on June 9, 2026, as an Important Windows Secure Boot security feature bypass affecting supported Windows client and server releases, with official fixes issued through security updates and no public disclosure or exploitation reported at publication time. The...
  15. CVE-2026-48570 Secure Boot Bypass: Patch Guidance for Windows Clients & Servers

    Microsoft disclosed CVE-2026-48570 on June 9, 2026, as an Important-rated Windows Secure Boot security feature bypass affecting supported Windows client and server releases, with official fixes available and Microsoft saying exploitation is less likely and not publicly disclosed or observed in...
  16. CVE-2026-48568 Secure Boot Bypass: June 2026 Patch Tuesday Update Guide

    Microsoft disclosed CVE-2026-48568 on June 9, 2026, as an Important-rated Windows Secure Boot security feature bypass that can be exploited locally by an authorized attacker and is addressed through June Patch Tuesday updates across supported Windows client and server releases. The advisory is...
  17. CVE-2026-48566 DWM Info Disclosure: June Patch Tuesday Update Guidance

    Microsoft published CVE-2026-48566 on June 9, 2026, as an Important-rated Windows DWM Core Library information disclosure vulnerability, addressed in the June Patch Tuesday updates for supported Windows client and server systems through the normal cumulative update channel. The bug is not the...
  18. CVE-2026-48563 Critical RDP Client RCE: Patch June 2026 Before Exploits

    Microsoft disclosed CVE-2026-48563 on June 9, 2026, as a Critical remote code execution vulnerability in the Windows Remote Desktop Client, part of a June Patch Tuesday release that also included multiple other Remote Desktop Client flaws across supported Windows releases. The headline is not...
  19. June 2026 Patch Tuesday for Windows 11: KB5094126, KB5093998, KB5095051

    Microsoft released the June 2026 Patch Tuesday updates for Windows 11 on June 9, shipping KB5094126 for versions 25H2 and 24H2, KB5093998 for version 23H2, and KB5095051 for Arm-only version 26H1 PCs, with security fixes and several gradually rolling features. The headline is not that Patch...
  20. CVE-2026-47652 Hyper-V RCE: Microsoft Confirms Patch Need (June 9, 2026)

    Microsoft’s June 9, 2026 Security Update Guide entry for CVE-2026-47652 identifies a Windows Hyper-V remote code execution vulnerability in Microsoft’s virtualization stack, with the vendor’s own advisory serving as the authoritative confirmation that the flaw exists and has been assigned a...