patch tuesday

  1. CVE-2026-42915: Windows TCP/IP Medium DoS Bug (Patch June 2026)

    Microsoft disclosed CVE-2026-42915 on June 9, 2026, as a medium-severity Windows TCP/IP denial-of-service vulnerability affecting Windows 10, Windows 11, Windows Server 2022, and Windows Server 2025, with exploitation requiring an authorized attacker on an adjacent network. The bug is not the...
  2. CVE-2026-42914: Patch Microsoft Kerberos DoS (Important) Before It Disrupts Identity

    Microsoft disclosed CVE-2026-42914 on June 9, 2026, as an Important-rated Windows Kerberos denial-of-service vulnerability affecting supported Windows client and server releases, with official fixes available through June security updates and no public disclosure or active exploitation reported...
  3. CVE-2026-42913: Patch RDP Client RCE Risk in Windows 11 & Server

    Microsoft disclosed CVE-2026-42913 on June 9, 2026, as a high-severity Remote Desktop Client remote code execution flaw affecting Windows 11, Windows Server 2022, and Windows Server 2025, with exploitation requiring a user to interact with a malicious RDP target. The bug is not the loudest item...
  4. CVE-2026-42980: Microsoft NT Kernel Local EoP Patch Priority (7.8, Exploitation More Likely)

    Microsoft published CVE-2026-42980 on June 9, 2026 as an NT OS Kernel elevation-of-privilege vulnerability affecting supported Windows client and server releases, rating it Important with a CVSS 3.1 base score of 7.8 and marking exploitation as more likely. That combination is the story: not a...
  5. CVE-2026-42908: Windows RDP Out-of-Bounds Info Disclosure (Patch Now)

    Microsoft disclosed CVE-2026-42908 on June 9, 2026, as a Windows Remote Desktop Protocol information disclosure vulnerability caused by an out-of-bounds read that could allow an unauthenticated attacker to disclose information over a network on affected Windows systems. The bug is not the...
  6. CVE-2026-42907: Why a Windows Shell Info Disclosure Patch Timing Matters

    Microsoft disclosed CVE-2026-42907 on June 9, 2026, as a Windows Shell information disclosure vulnerability affecting supported Windows client and server releases, with public listings placing it at medium severity and tying remediation to the June Patch Tuesday security updates. The headline is...
  7. CVE-2026-42904: Windows TCP/IP Heap Overflow Could Grant SYSTEM Privileges

    Microsoft disclosed CVE-2026-42904 on June 9, 2026, as an Important Windows TCP/IP elevation-of-privilege vulnerability caused by a heap-based buffer overflow that can let an unauthenticated attacker with adjacent-network access gain SYSTEM privileges on affected Windows clients and servers. The...
  8. CVE-2026-42903 Kerberos DoS: Patch Tuesday Guidance for Windows Domains

    CVE-2026-42903 is a Microsoft-disclosed Windows Kerberos denial-of-service vulnerability published on June 9, 2026, as part of the June Patch Tuesday cycle, affecting supported Windows client and server releases, including domain-controller-capable Windows Server versions where Kerberos...
  9. CVE-2026-50507 BitLocker Bypass: Why Physical Access Can Expose Encrypted Data

    Microsoft published CVE-2026-50507 on June 9, 2026, as a Windows BitLocker security feature bypass vulnerability that could let an attacker with physical access bypass BitLocker Device Encryption and access encrypted data on an affected Windows device. The dry phrasing hides the uncomfortable...
  10. CVE-2026-49160 HTTP.sys DoS: Patch Tuesday Urgency for Windows Web Stack

    Microsoft disclosed CVE-2026-49160 on June 9, 2026, as a Windows HTTP.sys denial-of-service vulnerability addressed in the June Patch Tuesday updates, with public disclosure already recorded but no confirmed active exploitation at release time. The bug matters less because it promises dramatic...
  11. CVE-2026-42910: Hotpatch Monitoring Service Privilege Escalation Risk on Windows

    Microsoft disclosed CVE-2026-42910 on June 9, 2026, as a Windows Hotpatch Monitoring Service elevation-of-privilege vulnerability in the Security Update Guide, directing administrators to treat the flaw as a patched Windows security issue rather than a speculative advisory. The interesting part...
  12. Windows 11 June 2026 Patch Tuesday KB5094126: Low Latency Profile Rollout Explained

    Microsoft released Windows 11’s June 2026 Patch Tuesday update on June 9, 2026, bringing KB5094126 to Windows 11 versions 25H2 and 24H2 with OS builds 26200.8655 and 26100.8655, including a new Low Latency Profile meant to make Start, Search, Action Center, and app launches feel faster. The...
  13. CVE-2026-45653 Kernel EoP: Patch Tuesday Guidance for Windows Admins

    Microsoft’s June 9, 2026 security update lists CVE-2026-45653 as an Important Windows Kernel elevation-of-privilege vulnerability, one of several kernel-class fixes in a record-sized Patch Tuesday release affecting Windows client and server systems. The important word is not merely kernel; it is...
  14. CVE-2026-45608: Windows DHCP Client Info Disclosure—Patch Tuesday Priorities

    Microsoft has listed CVE-2026-45608 as a Windows DHCP Client information disclosure vulnerability in the Microsoft Security Response Center update guide on June 9, 2026, placing a familiar but easily underestimated networking component back into the Patch Tuesday risk conversation. The important...
  15. CVE-2026-45637: Patch Tuesday DWM EoP—Why “Local” Still Demands Urgent Updates

    CVE-2026-45637 is an Important-rated Microsoft DWM Core Library elevation-of-privilege vulnerability patched in Microsoft’s June 9, 2026 Patch Tuesday release, affecting Windows systems through the Desktop Window Manager component and carrying a reported CVSS base score of 7.8. It is not the...
  16. CVE-2026-45638: Windows WinSock Driver Local Privilege Escalation (Patch Tuesday)

    Microsoft disclosed CVE-2026-45638 on June 9, 2026, as a Windows Ancillary Function Driver for WinSock elevation-of-privilege vulnerability affecting Windows systems, with the practical risk that an attacker who already has local authorized access could potentially gain higher privileges. That...
  17. CVE-2026-45635: Windows UPnP Device Host RCE—Patch Tuesday Priorities

    Microsoft disclosed CVE-2026-45635 on June 9, 2026 as an Important-rated Windows UPnP Device Host remote code execution vulnerability affecting the Universal Plug and Play stack, with public listings placing it in the June 2026 Patch Tuesday batch and assigning it a high CVSS score of 8.1. The...
  18. CVE-2026-45602: Patch Windows DHCP Server Tampering (CVSS 9.1) ASAP

    Microsoft released CVE-2026-45602 on June 9, 2026, as a Windows Dynamic Host Configuration Protocol Server tampering vulnerability affecting supported Windows client and server releases, with an official fix available and no public disclosure or active exploitation reported at publication. The...
  19. CVE-2026-45600: Important Windows Kernel Driver LPE—Patch June 2026 Now

    Microsoft disclosed CVE-2026-45600 on June 9, 2026, as an Important-rated Windows Kernel-Mode Driver elevation-of-privilege vulnerability in its June Patch Tuesday release, affecting Windows systems through a local privilege-escalation path rather than a remote, unauthenticated network attack...
  20. CVE-2026-45504: Urgent Microsoft Exchange EoP Patch Tuesday Guidance

    CVE-2026-45504 is a Microsoft Exchange Server elevation-of-privilege vulnerability disclosed in Microsoft’s June 9, 2026 Patch Tuesday release, rated Important, and listed among a cluster of Exchange Server fixes that administrators should treat as operationally urgent despite sparse public...