Microsoft fixes 208 vulnerabilities while introducing Windows 11 performance, security, and user experience enhancements.
Key Takeaways:
Microsoft has released the June 2026 Patch Tuesday updates for Windows 11 versions 25H2, 24H2, and 26H1. This month, the company has fixed over 200 vulnerabilities in Windows, Office, Microsoft Edge, Azure, Exchange Server, Hyper-V, Microsoft Defender, and other components.
On the quality and experiences update front, this update improves Secure Boot by adding more reliable device-targeting data to Windows quality updates. It also fixes a bug that could result in Stop errors HYPERVISOR_ERROR (0x20001) and KMODE_EXCEPTION_NOT_HANDLED (0x1E) after installing KB5089573 on some devices. This problem occurred during system restarts, virtual machine operations, or when running certain gaming apps.
As pointed out by the Zero Day Initiative, Microsoft has fixed 208 new security flaws this month. Specifically, 38 of them are deemed “Critical,” and the rest are rated as “Important” in severity. Let’s take a look at the most important vulnerabilities Microsoft fixed this month:
You can find below the full list of security patches Microsoft released this month:
| Product | Impact | Max Severity | Article | Download | Details |
| Microsoft PC Manager | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2026-50511 |
| Windows 10 Version 22H2 for x64-based Systems | Elevation of Privilege | Important | 5094127 | Security Update | CVE-2026-45603 |
| Windows Server 2016 (Server Core installation) | Elevation of Privilege | Important | 5094122 | Security Update | CVE-2026-45638 |
| .NET 8.0 installed on Mac OS | Denial of Service | Important | 5097149 | Security Update | CVE-2026-45591 |
| .NET 8.0 installed on Linux | Denial of Service | Important | 5097149 | Security Update | CVE-2026-45591 |
| .NET 8.0 installed on Windows | Denial of Service | Important | 5097149 | Security Update | CVE-2026-45591 |
| ASP.NET Core 8.0 | Denial of Service | Important | 5097149 | Security Update | CVE-2026-45591 |
| .NET 10.0 installed on Linux | Denial of Service | Important | 5097148 | Security Update | CVE-2026-45591 |
| ASP.NET Core 10.0 | Denial of Service | Important | 5097148 | Security Update | CVE-2026-45591 |
| Windows Server 2025 | Remote Code Execution | Important | 5094125 | Security Update | CVE-2026-42993 |
| Windows 11 Version 24H2 for x64-based Systems | Remote Code Execution | Important | 5094126 | Security Update | CVE-2026-42993 |
| Windows 11 Version 24H2 for ARM64-based Systems | Remote Code Execution | Important | 5094126 | Security Update | CVE-2026-42993 |
| Windows 11 Version 23H2 for x64-based Systems | Remote Code Execution | Important | 5093998 | Security Update | CVE-2026-42993 |
| Microsoft PowerPoint for Android | Remote Code Execution | Critical | CVE-2026-44812 | ||
| Microsoft Excel for Android | Remote Code Execution | Critical | CVE-2026-44812 | ||
| Windows Server 2012 R2 (Server Core installation) | Remote Code Execution | Critical | 5094041 | Monthly Rollup | CVE-2026-44812 |
| Windows Server 2012 R2 | Remote Code Execution | Critical | 5094041 | Monthly Rollup | CVE-2026-44812 |
| Windows Server 2012 (Server Core installation) | Remote Code Execution | Critical | 5094042 | Monthly Rollup | CVE-2026-44812 |
| Windows Server 2012 | Remote Code Execution | Critical | 5094042 | Monthly Rollup | CVE-2026-44812 |
| Windows Server 2016 | Remote Code Execution | Critical | 5094122 | Security Update | CVE-2026-44812 |
| Windows 10 Version 1607 for x64-based Systems | Remote Code Execution | Critical | 5094122 | Security Update | CVE-2026-44812 |
| Windows 10 Version 1607 for 32-bit Systems | Remote Code Execution | Critical | 5094122 | Security Update | CVE-2026-44812 |
| Windows 11 Version 26H1 for ARM64-based Systems | Remote Code Execution | Critical | 5095051 | Security Update | CVE-2026-44812 |
| Windows 11 version 26H1 for x64-based Systems | Remote Code Execution | Critical | 5095051 | Security Update | CVE-2026-44812 |
| Windows 11 Version 23H2 for ARM64-based Systems | Remote Code Execution | Critical | 5093998 | Security Update | CVE-2026-44803 |
| Windows 11 Version 25H2 for x64-based Systems | Remote Code Execution | Critical | 5094126 | Security Update | CVE-2026-44803 |
| Windows 11 Version 25H2 for ARM64-based Systems | Remote Code Execution | Critical | 5094126 | Security Update | CVE-2026-44803 |
| Windows Server 2025 (Server Core installation) | Remote Code Execution | Critical | 5094125 | Security Update | CVE-2026-44803 |
| Windows 10 Version 22H2 for 32-bit Systems | Remote Code Execution | Critical | 5094127 | Security Update | CVE-2026-44803 |
| Windows 10 Version 22H2 for ARM64-based Systems | Elevation of Privilege | Important | 5094127 | Security Update | CVE-2026-42991 |
| Windows Server 2022 (Server Core installation) | Remote Code Execution | Important | 5094128 | Security Update | CVE-2026-42981 |
| Windows Server 2022 | Remote Code Execution | Important | 5094128 | Security Update | CVE-2026-42981 |
| Windows 11 Version 26H1 for x64-based Systems – extra | Elevation of Privilege | Important | 5095051 | Security Update | CVE-2026-42984 |
| Windows 10 Version 21H2 for x64-based Systems | Information Disclosure | Important | 5094127 | Security Update | CVE-2026-42971 |
| Windows 10 Version 21H2 for ARM64-based Systems | Information Disclosure | Important | 5094127 | Security Update | CVE-2026-42971 |
| Windows 10 Version 21H2 for 32-bit Systems | Information Disclosure | Important | 5094127 | Security Update | CVE-2026-42971 |
| Windows 10 Version 1809 for x64-based Systems | Elevation of Privilege | Important | 5094123 | Security Update | CVE-2026-42911 |
| Windows 10 Version 1809 for 32-bit Systems | Elevation of Privilege | Important | 5094123 | Security Update | CVE-2026-42911 |
| Windows Server 2019 (Server Core installation) | Elevation of Privilege | Important | 5094123 | Security Update | CVE-2026-42905 |
| Windows Server 2019 | Elevation of Privilege | Important | 5094123 | Security Update | CVE-2026-42905 |
| Microsoft 365 Apps for Enterprise for 64-bit Systems | Remote Code Execution | Important | Click to Run | Security Update | CVE-2026-44819 |
| Microsoft 365 Apps for Enterprise for 32-bit Systems | Remote Code Execution | Important | Click to Run | Security Update | CVE-2026-44819 |
| Microsoft Office 2019 for 64-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2026-44819 |
| Microsoft Office 2019 for 32-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2026-44819 |
| Microsoft Live Share Canvas SDK | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2026-45644 |
| Microsoft Word for Android | Remote Code Execution | Critical | CVE-2026-44803 | ||
| Remote Desktop client for Windows Desktop | Remote Code Execution | Important | Release Notes | Security Update | CVE-2026-42909 |
| Microsoft Office 365 for Mac | Remote Code Execution | Important | CVE-2026-45645 | ||
| Microsoft Office LTSC for Mac 2024 | Remote Code Execution | Important | CVE-2026-45643 | ||
| Microsoft Office LTSC 2024 for 64-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2026-45643 |
| Microsoft Office LTSC 2024 for 32-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2026-45643 |
| Windows App Client for Windows Desktop | Information Disclosure | Important | {“type”:5,”hyperlink”:”https://learn.microsoft.com/en-us/windows-app/whats-new?toc=admins%2Ftoc.json&tabs=windows”,”tooltip”:”Open \”https://learn.microsoft.com/en-us/windows-app/whats-new?toc=admins%2Ftoc.json&tabs=windows\””} | Security Update | CVE-2026-42908 |
| Visual Studio Code | Security Feature Bypass | Important | Release Notes | Security Update | CVE-2026-48569 |
| Windows Narrator Braille | Elevation of Privilege | Important | CVE-2026-48565 | ||
| Microsoft SharePoint Server Subscription Edition | Spoofing | Important | 5002873 | Security Update | CVE-2026-48562 |
| Microsoft SharePoint Server 2019 | Spoofing | Important | 5002874 | Security Update | CVE-2026-48562 |
| Microsoft SharePoint Enterprise Server 2016 | Spoofing | Important | 5002880 | Security Update | CVE-2026-48562 |
| Microsoft Exchange Server 2019 Cumulative Update 14 | Spoofing | Important | 5094142 | Security Update | CVE-2026-47631 |
| Microsoft Exchange Server 2016 Cumulative Update 23 | Spoofing | Important | 5094144 | Security Update | CVE-2026-47631 |
| Microsoft Office LTSC 2021 for 64-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2026-44819 |
| Microsoft Office LTSC for Mac 2021 | Remote Code Execution | Important | CVE-2026-44819 | ||
| Azure Stack Edge | Remote Code Execution | Important | Release Notes | Security Update | CVE-2026-47643 |
| Microsoft Word 2016 (64-bit edition) | Remote Code Execution | Important | 5002879 | Security Update | CVE-2026-45471 |
| Microsoft Word 2016 (32-bit edition) | Remote Code Execution | Important | 5002879 | Security Update | CVE-2026-45471 |
| Microsoft Office LTSC 2021 for 32-bit editions | Remote Code Execution | Important | Click to Run | Security Update | CVE-2026-45471 |
| Windows Server 2025 | Security Feature Bypass | Important | 5094126 | Security Update | CVE-2026-50507 |
| Microsoft Defender for Endpoint for Mac | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2026-45647 |
| Azure Kubernetes Service | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-32193 |
| Windows Server 2025 (Server Core installation) | Security Feature Bypass | Important | 5094126 | Security Update | CVE-2026-50507 |
| .NET 10.0 installed on Mac OS | Denial of Service | Important | 5097148 | Security Update | CVE-2026-45591 |
| .NET 10.0 installed on Windows | Denial of Service | Important | 5097148 | Security Update | CVE-2026-45591 |
| Microsoft Visual Studio 2026 version 18.6 | Denial of Service | Important | Release Notes | Security Update | CVE-2026-45591 |
| Windows 11 Version 26H1 for ARM64-based Systems | Information Disclosure | Important | 5089548 | Security Update | CVE-2026-48566 |
| Windows 11 version 26H1 for x64-based Systems | Information Disclosure | Important | 5089548 | Security Update | CVE-2026-48566 |
| Windows Server 2025 | Information Disclosure | Important | 5087539 | Security Update | CVE-2026-48566 |
| Windows Server 2025 | Information Disclosure | Important | 5087423 | Security Hotpatch Update | CVE-2026-48566 |
| Windows 11 Version 24H2 for x64-based Systems | Information Disclosure | Important | 5089549 | Security Update | CVE-2026-48566 |
| Windows 11 Version 24H2 for x64-based Systems | Information Disclosure | Important | 5089466 | Security Hotpatch Update | CVE-2026-48566 |
| Windows 11 Version 24H2 for ARM64-based Systems | Information Disclosure | Important | 5089549 | Security Update | CVE-2026-48566 |
| Windows 11 Version 24H2 for ARM64-based Systems | Information Disclosure | Important | 5089466 | Security Hotpatch Update | CVE-2026-48566 |
| Microsoft Exchange Server Subscription Edition RTM | Remote Code Execution | Important | 5094139 | Security Update | CVE-2026-45583 |
| Microsoft Exchange Server 2019 Cumulative Update 15 | Remote Code Execution | Important | 5094140 | Security Update | CVE-2026-45583 |
| Microsoft SharePoint Server 2019 | Remote Code Execution | Important | 5002876 | Security Update | CVE-2026-44819 |
| Microsoft SharePoint Enterprise Server 2016 | Remote Code Execution | Important | 5002881 | Security Update | CVE-2026-44819 |
| Microsoft Excel 2016 (64-bit edition) | Remote Code Execution | Important | 5002877 | Security Update | CVE-2026-44818 |
| Microsoft Excel 2016 (32-bit edition) | Remote Code Execution | Important | 5002877 | Security Update | CVE-2026-44818 |
| Windows Server 2012 R2 (Server Core installation) | Elevation of Privilege | Important | 5094006 | IE Cumulative | CVE-2026-45592 |
| Windows Server 2012 R2 | Elevation of Privilege | Important | 5094006 | IE Cumulative | CVE-2026-45592 |
| ASP.NET Core 9.0 | Denial of Service | Important | 5097150 | Security Update | CVE-2026-45591 |
| .NET 9.0 installed on Windows | Denial of Service | Important | 5097150 | Security Update | CVE-2026-45591 |
| .NET 9.0 installed on Linux | Denial of Service | Important | 5097150 | Security Update | CVE-2026-45591 |
| .NET 9.0 installed on Mac OS | Denial of Service | Important | 5097150 | Security Update | CVE-2026-45591 |
| Microsoft Visual Studio Code CoPilot Chat Extension | Security Feature Bypass | Important | Release Notes | Security Update | CVE-2026-45482 |
| Linux kernel – Microsoft MANA Network Driver | Elevation of Privilege | Critical | Release Notes | Security Update | CVE-2026-45476 |
| Microsoft Office 2016 (64-bit edition) | Remote Code Execution | Critical | 5002878 | Security Update | CVE-2026-45463 |
| Microsoft Office 2016 (32-bit edition) | Remote Code Execution | Critical | 5002878 | Security Update | CVE-2026-45463 |
| Microsoft Office for Android | Remote Code Execution | Critical | CVE-2026-45463 | ||
| Office Online Server | Information Disclosure | Important | 5002875 | Security Update | CVE-2026-45455 |
| Microsoft Teams for Android | Information Disclosure | Important | Release Notes | Security Update | CVE-2026-42835 |
| Microsoft Dynamics 365 (on-premises) version 9.1 | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2026-40371 |
| PowerScribe One version 2023.1 SP3 Patch 6 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| PowerScribe One version 2023.1 SP2 Patch 11 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe One version 2019.10 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe One version 2019.9 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe One version 2019.8 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe One version 2019.7 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe One version 2019.6 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe One version 2019.5 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe One version 2019.4 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe 360 version 4.0.4 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe 360 version 4.0.3 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe 360 version 4.0.2 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe 360 version 4.0.1 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe 360 4.0 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe One version 2019.3 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe One version 2019.2 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe One version 2019.1 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe 360 version 4.0.9 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe 360 version 4.0.8 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe 360 version 4.0.7 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe 360 version 4.0.6 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Nuance PowerScribe 360 version 4.0.5 | Remote Code Execution | Critical | Release Notes | Security Update | CVE-2026-26142 |
| Windows 11 Version 22H2 for x64-based Systems | Spoofing | Important | 5093998 | Security Update | CVE-2026-50508 |
| Windows 11 Version 22H2 for ARM64-based Systems | Spoofing | Important | 5093998 | Security Update | CVE-2026-50508 |
| Windows Server, version 2004 (Server Core installation) | Spoofing | Important | 5094127 | Security Update | CVE-2026-50508 |
| Windows 11 Version 25H2 for x64-based Systems | Information Disclosure | Important | 5089549 | Security Update | CVE-2026-48566 |
| Windows 11 Version 25H2 for x64-based Systems | Information Disclosure | Important | 5089466 | Security Hotpatch Update | CVE-2026-48566 |
| Windows 11 Version 25H2 for ARM64-based Systems | Information Disclosure | Important | 5089549 | Security Update | CVE-2026-48566 |
| Windows 11 Version 25H2 for ARM64-based Systems | Information Disclosure | Important | 5089466 | Security Hotpatch Update | CVE-2026-48566 |
| Windows Server 2025 (Server Core installation) | Information Disclosure | Important | 5087539 | Security Update | CVE-2026-48566 |
| Windows Server 2025 (Server Core installation) | Information Disclosure | Important | 5087423 | Security Hotpatch Update | CVE-2026-48566 |
| Visual Studio Code – MSSQL Extension | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2026-47292 |
| Microsoft Bing Search for Android | Spoofing | Important | Release Notes | Security Update | CVE-2026-45650 |
| Microsoft Office 2016 (64-bit edition) | Remote Code Execution | Important | 5002852 | Security Update | CVE-2026-45645 |
| Microsoft Office 2016 (32-bit edition) | Remote Code Execution | Important | 5002852 | Security Update | CVE-2026-45645 |
| .NET 8.0 | Tampering | Important | 5097149 | Security Update | CVE-2026-45491 |
| Microsoft PowerToys | Elevation of Privilege | Important | Release Notes | Security Update | CVE-2026-42902 |
For Windows 11 versions 25H2 and 24H2, the KB5094126 patch brings several new features, including Shared audio, multi-app camera support, as well as enhancements for magnifier, Windows Search and performance. The Shared Audio feature lets two users with Bluetooth LE audio accessories listen to the same audio together. Users can enable this feature through the Quick Settings panel from the taskbar.
Microsoft has introduced a new “Low Latency Profile” to speed up app launches and core shell experiences, including the Start menu, Search, and Action Center. This update also lets multiple Windows apps access the users’ camera stream at the same time.
Organizations looking to deploy this month’s patches should conduct thorough testing before deploying them widely on production systems. That said, applying the patches widely shouldn’t be delayed longer than necessary, as hackers start to work out how to weaponize newly reported vulnerabilities.
A best practice is to make sure you have backed up systems before applying updates. Every month, users experience issues with Windows updates that lead to systems not booting, application and hardware compatibility issues, or even data loss in extreme cases.
There are backup tools built into Windows and Windows Server that you can use to restore systems in the event a patch causes a problem. The backup features in Windows can be used to restore an entire system or files and folders on a granular basis.