June 2026 Patch Tuesday
Microsoft's June 2026 security release came out on Tuesday, June 9, 2026. Below: the updates for each Windows version, the holes that were already under attack, and the rest of the release.
Microsoft data read Last revised by Microsoft Sep 28, 2026
Windows 11 and Windows 10
| Update | Applies to | Build after update | CVEs |
|---|---|---|---|
| KB5095051Security Update | Windows 11 Version 26H1 | 28000.2269 | 112 |
| KB5094126Security Update | Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 | 26100.8655, 26200.8655 | 106 |
| KB5093998Security Update | Windows 11 Version 22H2, Windows 11 Version 23H2 | 22631.7219 | 102 |
| KB5094127Security Update | Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server, version 2004 | 19044.7417, 19045.7417 | 94 |
| KB5094123Security Update | Windows 10 Version 1809, Windows Server 2019 | 17763.8880 | 89 |
| KB5094122Security Update | Windows 10 Version 1607, Windows Server 2016 | 14393.9234 | 76 |
| KB5089549Security Update | Windows 11 Version 24H2, Windows 11 Version 25H2 | 26100.8457, 26200.8457 | 1 |
| KB5089466Security Hotpatch Update | Windows 11 Version 24H2, Windows 11 Version 25H2 | 26100.8390, 26200.8390 | 1 |
| KB5089548Security Update | Windows 11 Version 26H1 | 28000.2113 | 1 |
Publicly known before the fix
| CVE | Type | CVSS | Severity |
|---|---|---|---|
| CVE-2026-45586Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-50656Microsoft Defender Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-49160HTTP.sys Denial of Service Vulnerability | Denial of Service | 7.5 | Important |
| CVE-2026-50507Windows BitLocker Security Feature Bypass Vulnerability | Security Feature Bypass | 6.8 | Important |
Critical fixes with the highest scores
| CVE | Type | CVSS | Severity |
|---|---|---|---|
| CVE-2026-45480Azure Active Directory Elevation of Privilege Vulnerability | Elevation of Privilege | 10.0 | Critical |
| CVE-2026-48567Azure HorizonDB Elevation of Privilege Vulnerability | Elevation of Privilege | 10.0 | Critical |
| CVE-2026-47647Dynamics 365 Elevation of Privilege Vulnerability | Elevation of Privilege | 9.9 | Critical |
| CVE-2026-48584Microsoft Azure Synapse Elevation of Privilege Vulnerability | Elevation of Privilege | 9.9 | Critical |
| CVE-2026-26142Nuance PowerScribe Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical |
| CVE-2026-44815DHCP Client Service Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical |
| CVE-2026-45657Windows Kernel Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical |
| CVE-2026-47291HTTP.sys Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical |
| CVE-2026-54130M365 Copilot Information Disclosure Vulnerability | Information Disclosure | 9.8 | Critical |
| CVE-2026-48582Microsoft Exchange Online Elevation of Privilege Vulnerability | Elevation of Privilege | 9.6 | Critical |
| CVE-2026-47646Dynamics 365 Customer Voice Spoofing Vulnerability | Spoofing | 9.3 | Critical |
| CVE-2026-48579Microsoft Exchange Online Information Disclosure Vulnerability | Information Disclosure | 9.1 | Critical |
Servers and other products
| Update | Applies to | CVEs |
|---|---|---|
| KB5094125Security Update | Windows Server 2025 | 108 |
| KB5094128Security Update | Windows Server 2022 | 105 |
| KB5094041Monthly Rollup | Windows Server 2012 R2 | 65 |
| KB5094042Monthly Rollup | Windows Server 2012 | 62 |
| KB5002874Security Update | Microsoft SharePoint Server 2019 | 30 |
| KB5002873Security Update | Microsoft SharePoint Server Subscription Edition | 30 |
| KB5002880Security Update | Microsoft SharePoint Enterprise Server 2016 | 29 |
| KB5002878Security Update | Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition) | 9 |
| KB5002881Security Update | Microsoft SharePoint Enterprise Server 2016 | 8 |
| KB5002876Security Update | Microsoft SharePoint Server 2019 | 8 |
| KB5002875Security Update | Office Online Server | 7 |
| KB5002877Security Update | Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition) | 7 |
| KB5103214Security Update | Microsoft Exchange Server 2019 Cumulative Update 14 | 7 |
| KB5103212Security Update | Microsoft Exchange Server Subscription Edition RTM | 7 |
| KB5103213Security Update | Microsoft Exchange Server 2019 Cumulative Update 15 | 7 |
| KB5103215Security Update | Microsoft Exchange Server 2016 Cumulative Update 23 | 7 |
| KB5002879Security Update | Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition) | 3 |
| KB5097148Security Update | .NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows, ASP.NET Core 10.0 | 3 |
| KB5097149Security Update | .NET 8.0, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows and 1 more | 3 |
| KB5097150Security Update | .NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows, ASP.NET Core 9.0 | 3 |
| KB5094006IE Cumulative | Windows Server 2012 R2 | 1 |
| KB5002852Security Update | Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition) | 1 |
| KB5087539Security Update | Windows Server 2025 | 1 |
| KB5087423Security Hotpatch Update | Windows Server 2025 | 1 |
Questions and experiences
Ask about this page: members and our editors answer. Reading is open; writing needs a free account.
0 comments
…