Microsoft’s June 2026 Patch Tuesday Fixes Critical Windows RCE Vulnerabilities

Microsoft fixes 208 vulnerabilities while introducing Windows 11 performance, security, and user experience enhancements.

Windows update hero image

Key Takeaways:

  • 208 vulnerabilities patched, including an actively exploited Microsoft Defender privilege-escalation flaw.
  • Microsoft has fixed multiple critical RCE bugs this month.
  • Windows 11 gets performance improvements, shared audio, and more.

Microsoft has released the June 2026 Patch Tuesday updates for Windows 11 versions 25H2, 24H2, and 26H1. This month, the company has fixed over 200 vulnerabilities in Windows, Office, Microsoft Edge, Azure, Exchange Server, Hyper-V, Microsoft Defender, and other components.

On the quality and experiences update front, this update improves Secure Boot by adding more reliable device-targeting data to Windows quality updates. It also fixes a bug that could result in Stop errors HYPERVISOR_ERROR (0x20001) and KMODE_EXCEPTION_NOT_HANDLED (0x1E) after installing KB5089573 on some devices. This problem occurred during system restarts, virtual machine operations, or when running certain gaming apps.

208 vulnerabilities fixed with the June 2026 Patch Tuesday updates

As pointed out by the Zero Day Initiative, Microsoft has fixed 208 new security flaws this month. Specifically, 38 of them are deemed “Critical,” and the rest are rated as “Important” in severity. Let’s take a look at the most important vulnerabilities Microsoft fixed this month:

  • CVE-2026-41091: This is a Microsoft Defender elevation-of-privilege vulnerability that has already been exploited in the wild. It could allow an authorized attacker to elevate privileges locally.
  • CVE-2026-50507: This is a security feature bypass bug in Windows BitLocker with a CVSS score of 6.8. An attacker with physical access to the vulnerable system could bypass the BitLocker Device Encryption feature and gain access to the encrypted data.
  • CVE-2026-45586: This is a Windows Collaborative Translation Framework (CTFMON) elevation-of-privilege vulnerability with a CVSS score of 7.8. It could be abused by an authorized attacker to elevate privileges locally and gain SYSTEM access.
  • CVE-2026-45657: This is a Windows kernel remote code execution (RCE) vulnerability that enables unauthenticated hackers to run malicious code with system-level privileges without any user interaction. This bug could be exploited by sending malicious network packets to a vulnerable Windows machine.
  • CVE-2026-47291: This Windows HTTP.sys remote code execution vulnerability carries a CVSS score of 9.8. This flaw could also be triggered without any user interaction, and it’s most likely to be exploited by attackers.
  • CVE-2026-44815: This is a Windows DHCP Client remote code execution vulnerability with a CVSS score of 9.8. It could allow an unauthenticated attacker to remotely compromise a vulnerable system without any user interaction.
  • CVE-2026-49160: This is an HTTP.sys denial of service vulnerability with a CVSS score of 7.5. It’s a denial-of-service flaw in HTTP/2 handling that could let an unauthenticated remote attacker disrupt affected Windows machines.

You can find below the full list of security patches Microsoft released this month:

ProductImpactMax SeverityArticleDownloadDetails
Microsoft PC ManagerElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2026-50511
Windows 10 Version 22H2 for x64-based SystemsElevation of PrivilegeImportant5094127Security UpdateCVE-2026-45603
Windows Server 2016 (Server Core installation)Elevation of PrivilegeImportant5094122Security UpdateCVE-2026-45638
.NET 8.0 installed on Mac OSDenial of ServiceImportant5097149Security UpdateCVE-2026-45591
.NET 8.0 installed on LinuxDenial of ServiceImportant5097149Security UpdateCVE-2026-45591
.NET 8.0 installed on WindowsDenial of ServiceImportant5097149Security UpdateCVE-2026-45591
ASP.NET Core 8.0Denial of ServiceImportant5097149Security UpdateCVE-2026-45591
.NET 10.0 installed on LinuxDenial of ServiceImportant5097148Security UpdateCVE-2026-45591
ASP.NET Core 10.0Denial of ServiceImportant5097148Security UpdateCVE-2026-45591
Windows Server 2025Remote Code ExecutionImportant5094125Security UpdateCVE-2026-42993
Windows 11 Version 24H2 for x64-based SystemsRemote Code ExecutionImportant5094126Security UpdateCVE-2026-42993
Windows 11 Version 24H2 for ARM64-based SystemsRemote Code ExecutionImportant5094126Security UpdateCVE-2026-42993
Windows 11 Version 23H2 for x64-based SystemsRemote Code ExecutionImportant5093998Security UpdateCVE-2026-42993
Microsoft PowerPoint for AndroidRemote Code ExecutionCriticalCVE-2026-44812
Microsoft Excel for AndroidRemote Code ExecutionCriticalCVE-2026-44812
Windows Server 2012 R2 (Server Core installation)Remote Code ExecutionCritical5094041Monthly RollupCVE-2026-44812
Windows Server 2012 R2Remote Code ExecutionCritical5094041Monthly RollupCVE-2026-44812
Windows Server 2012 (Server Core installation)Remote Code ExecutionCritical5094042Monthly RollupCVE-2026-44812
Windows Server 2012Remote Code ExecutionCritical5094042Monthly RollupCVE-2026-44812
Windows Server 2016Remote Code ExecutionCritical5094122Security UpdateCVE-2026-44812
Windows 10 Version 1607 for x64-based SystemsRemote Code ExecutionCritical5094122Security UpdateCVE-2026-44812
Windows 10 Version 1607 for 32-bit SystemsRemote Code ExecutionCritical5094122Security UpdateCVE-2026-44812
Windows 11 Version 26H1 for ARM64-based SystemsRemote Code ExecutionCritical5095051Security UpdateCVE-2026-44812
Windows 11 version 26H1 for x64-based SystemsRemote Code ExecutionCritical5095051Security UpdateCVE-2026-44812
Windows 11 Version 23H2 for ARM64-based SystemsRemote Code ExecutionCritical5093998Security UpdateCVE-2026-44803
Windows 11 Version 25H2 for x64-based SystemsRemote Code ExecutionCritical5094126Security UpdateCVE-2026-44803
Windows 11 Version 25H2 for ARM64-based SystemsRemote Code ExecutionCritical5094126Security UpdateCVE-2026-44803
Windows Server 2025 (Server Core installation)Remote Code ExecutionCritical5094125Security UpdateCVE-2026-44803
Windows 10 Version 22H2 for 32-bit SystemsRemote Code ExecutionCritical5094127Security UpdateCVE-2026-44803
Windows 10 Version 22H2 for ARM64-based SystemsElevation of PrivilegeImportant5094127Security UpdateCVE-2026-42991
Windows Server 2022 (Server Core installation)Remote Code ExecutionImportant5094128Security UpdateCVE-2026-42981
Windows Server 2022Remote Code ExecutionImportant5094128Security UpdateCVE-2026-42981
Windows 11 Version 26H1 for x64-based Systems – extraElevation of PrivilegeImportant5095051Security UpdateCVE-2026-42984
Windows 10 Version 21H2 for x64-based SystemsInformation DisclosureImportant5094127Security UpdateCVE-2026-42971
Windows 10 Version 21H2 for ARM64-based SystemsInformation DisclosureImportant5094127Security UpdateCVE-2026-42971
Windows 10 Version 21H2 for 32-bit SystemsInformation DisclosureImportant5094127Security UpdateCVE-2026-42971
Windows 10 Version 1809 for x64-based SystemsElevation of PrivilegeImportant5094123Security UpdateCVE-2026-42911
Windows 10 Version 1809 for 32-bit SystemsElevation of PrivilegeImportant5094123Security UpdateCVE-2026-42911
Windows Server 2019 (Server Core installation)Elevation of PrivilegeImportant5094123Security UpdateCVE-2026-42905
Windows Server 2019Elevation of PrivilegeImportant5094123Security UpdateCVE-2026-42905
Microsoft 365 Apps for Enterprise for 64-bit SystemsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2026-44819
Microsoft 365 Apps for Enterprise for 32-bit SystemsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2026-44819
Microsoft Office 2019 for 64-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2026-44819
Microsoft Office 2019 for 32-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2026-44819
Microsoft Live Share Canvas SDKElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2026-45644
Microsoft Word for AndroidRemote Code ExecutionCriticalCVE-2026-44803
Remote Desktop client for Windows DesktopRemote Code ExecutionImportantRelease NotesSecurity UpdateCVE-2026-42909
Microsoft Office 365 for MacRemote Code ExecutionImportantCVE-2026-45645
Microsoft Office LTSC for Mac 2024Remote Code ExecutionImportantCVE-2026-45643
Microsoft Office LTSC 2024 for 64-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2026-45643
Microsoft Office LTSC 2024 for 32-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2026-45643
Windows App Client for Windows DesktopInformation DisclosureImportant{“type”:5,”hyperlink”:”https://learn.microsoft.com/en-us/windows-app/whats-new?toc=admins%2Ftoc.json&tabs=windows”,”tooltip”:”Open \”https://learn.microsoft.com/en-us/windows-app/whats-new?toc=admins%2Ftoc.json&tabs=windows\””}Security UpdateCVE-2026-42908
Visual Studio CodeSecurity Feature BypassImportantRelease NotesSecurity UpdateCVE-2026-48569
Windows Narrator BrailleElevation of PrivilegeImportantCVE-2026-48565
Microsoft SharePoint Server Subscription EditionSpoofingImportant5002873Security UpdateCVE-2026-48562
Microsoft SharePoint Server 2019SpoofingImportant5002874Security UpdateCVE-2026-48562
Microsoft SharePoint Enterprise Server 2016SpoofingImportant5002880Security UpdateCVE-2026-48562
Microsoft Exchange Server 2019 Cumulative Update 14SpoofingImportant5094142Security UpdateCVE-2026-47631
Microsoft Exchange Server 2016 Cumulative Update 23SpoofingImportant5094144Security UpdateCVE-2026-47631
Microsoft Office LTSC 2021 for 64-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2026-44819
Microsoft Office LTSC for Mac 2021Remote Code ExecutionImportantCVE-2026-44819
Azure Stack EdgeRemote Code ExecutionImportantRelease NotesSecurity UpdateCVE-2026-47643
Microsoft Word 2016 (64-bit edition)Remote Code ExecutionImportant5002879Security UpdateCVE-2026-45471
Microsoft Word 2016 (32-bit edition)Remote Code ExecutionImportant5002879Security UpdateCVE-2026-45471
Microsoft Office LTSC 2021 for 32-bit editionsRemote Code ExecutionImportantClick to RunSecurity UpdateCVE-2026-45471
Windows Server 2025Security Feature BypassImportant5094126Security UpdateCVE-2026-50507
Microsoft Defender for Endpoint for MacElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2026-45647
Azure Kubernetes ServiceRemote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-32193
Windows Server 2025 (Server Core installation)Security Feature BypassImportant5094126Security UpdateCVE-2026-50507
.NET 10.0 installed on Mac OSDenial of ServiceImportant5097148Security UpdateCVE-2026-45591
.NET 10.0 installed on WindowsDenial of ServiceImportant5097148Security UpdateCVE-2026-45591
Microsoft Visual Studio 2026 version 18.6Denial of ServiceImportantRelease NotesSecurity UpdateCVE-2026-45591
Windows 11 Version 26H1 for ARM64-based SystemsInformation DisclosureImportant5089548Security UpdateCVE-2026-48566
Windows 11 version 26H1 for x64-based SystemsInformation DisclosureImportant5089548Security UpdateCVE-2026-48566
Windows Server 2025Information DisclosureImportant5087539Security UpdateCVE-2026-48566
Windows Server 2025Information DisclosureImportant5087423Security Hotpatch UpdateCVE-2026-48566
Windows 11 Version 24H2 for x64-based SystemsInformation DisclosureImportant5089549Security UpdateCVE-2026-48566
Windows 11 Version 24H2 for x64-based SystemsInformation DisclosureImportant5089466Security Hotpatch UpdateCVE-2026-48566
Windows 11 Version 24H2 for ARM64-based SystemsInformation DisclosureImportant5089549Security UpdateCVE-2026-48566
Windows 11 Version 24H2 for ARM64-based SystemsInformation DisclosureImportant5089466Security Hotpatch UpdateCVE-2026-48566
Microsoft Exchange Server Subscription Edition RTMRemote Code ExecutionImportant5094139Security UpdateCVE-2026-45583
Microsoft Exchange Server 2019 Cumulative Update 15Remote Code ExecutionImportant5094140Security UpdateCVE-2026-45583
Microsoft SharePoint Server 2019Remote Code ExecutionImportant5002876Security UpdateCVE-2026-44819
Microsoft SharePoint Enterprise Server 2016Remote Code ExecutionImportant5002881Security UpdateCVE-2026-44819
Microsoft Excel 2016 (64-bit edition)Remote Code ExecutionImportant5002877Security UpdateCVE-2026-44818
Microsoft Excel 2016 (32-bit edition)Remote Code ExecutionImportant5002877Security UpdateCVE-2026-44818
Windows Server 2012 R2 (Server Core installation)Elevation of PrivilegeImportant5094006IE CumulativeCVE-2026-45592
Windows Server 2012 R2Elevation of PrivilegeImportant5094006IE CumulativeCVE-2026-45592
ASP.NET Core 9.0Denial of ServiceImportant5097150Security UpdateCVE-2026-45591
.NET 9.0 installed on WindowsDenial of ServiceImportant5097150Security UpdateCVE-2026-45591
.NET 9.0 installed on LinuxDenial of ServiceImportant5097150Security UpdateCVE-2026-45591
.NET 9.0 installed on Mac OSDenial of ServiceImportant5097150Security UpdateCVE-2026-45591
Microsoft Visual Studio Code CoPilot Chat ExtensionSecurity Feature BypassImportantRelease NotesSecurity UpdateCVE-2026-45482
Linux kernel – Microsoft MANA Network DriverElevation of PrivilegeCriticalRelease NotesSecurity UpdateCVE-2026-45476
Microsoft Office 2016 (64-bit edition)Remote Code ExecutionCritical5002878Security UpdateCVE-2026-45463
Microsoft Office 2016 (32-bit edition)Remote Code ExecutionCritical5002878Security UpdateCVE-2026-45463
Microsoft Office for AndroidRemote Code ExecutionCriticalCVE-2026-45463
Office Online ServerInformation DisclosureImportant5002875Security UpdateCVE-2026-45455
Microsoft Teams for AndroidInformation DisclosureImportantRelease NotesSecurity UpdateCVE-2026-42835
Microsoft Dynamics 365 (on-premises) version 9.1Elevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2026-40371
PowerScribe One version 2023.1 SP3 Patch 6Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
PowerScribe One version 2023.1 SP2 Patch 11Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe One version 2019.10Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe One version 2019.9Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe One version 2019.8Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe One version 2019.7Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe One version 2019.6Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe One version 2019.5Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe One version 2019.4Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe 360 version 4.0.4Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe 360 version 4.0.3Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe 360 version 4.0.2Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe 360 version 4.0.1Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe 360 4.0Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe One version 2019.3Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe One version 2019.2Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe One version 2019.1Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe 360 version 4.0.9Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe 360 version 4.0.8Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe 360 version 4.0.7Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe 360 version 4.0.6Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Nuance PowerScribe 360 version 4.0.5Remote Code ExecutionCriticalRelease NotesSecurity UpdateCVE-2026-26142
Windows 11 Version 22H2 for x64-based SystemsSpoofingImportant5093998Security UpdateCVE-2026-50508
Windows 11 Version 22H2 for ARM64-based SystemsSpoofingImportant5093998Security UpdateCVE-2026-50508
Windows Server, version 2004 (Server Core installation)SpoofingImportant5094127Security UpdateCVE-2026-50508
Windows 11 Version 25H2 for x64-based SystemsInformation DisclosureImportant5089549Security UpdateCVE-2026-48566
Windows 11 Version 25H2 for x64-based SystemsInformation DisclosureImportant5089466Security Hotpatch UpdateCVE-2026-48566
Windows 11 Version 25H2 for ARM64-based SystemsInformation DisclosureImportant5089549Security UpdateCVE-2026-48566
Windows 11 Version 25H2 for ARM64-based SystemsInformation DisclosureImportant5089466Security Hotpatch UpdateCVE-2026-48566
Windows Server 2025 (Server Core installation)Information DisclosureImportant5087539Security UpdateCVE-2026-48566
Windows Server 2025 (Server Core installation)Information DisclosureImportant5087423Security Hotpatch UpdateCVE-2026-48566
Visual Studio Code – MSSQL ExtensionElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2026-47292
Microsoft Bing Search for AndroidSpoofingImportantRelease NotesSecurity UpdateCVE-2026-45650
Microsoft Office 2016 (64-bit edition)Remote Code ExecutionImportant5002852Security UpdateCVE-2026-45645
Microsoft Office 2016 (32-bit edition)Remote Code ExecutionImportant5002852Security UpdateCVE-2026-45645
.NET 8.0TamperingImportant5097149Security UpdateCVE-2026-45491
Microsoft PowerToysElevation of PrivilegeImportantRelease NotesSecurity UpdateCVE-2026-42902

Quality and experience updates

For Windows 11 versions 25H2 and 24H2, the KB5094126 patch brings several new features, including Shared audio, multi-app camera support, as well as enhancements for magnifier, Windows Search and performance. The Shared Audio feature lets two users with Bluetooth LE audio accessories listen to the same audio together. Users can enable this feature through the Quick Settings panel from the taskbar.

Microsoft has introduced a new “Low Latency Profile” to speed up app launches and core shell experiences, including the Start menu, Search, and Action Center. This update also lets multiple Windows apps access the users’ camera stream at the same time.

Windows Update testing and best practices

Organizations looking to deploy this month’s patches should conduct thorough testing before deploying them widely on production systems. That said, applying the patches widely shouldn’t be delayed longer than necessary, as hackers start to work out how to weaponize newly reported vulnerabilities.

A best practice is to make sure you have backed up systems before applying updates. Every month, users experience issues with Windows updates that lead to systems not booting, application and hardware compatibility issues, or even data loss in extreme cases.

There are backup tools built into Windows and Windows Server that you can use to restore systems in the event a patch causes a problem. The backup features in Windows can be used to restore an entire system or files and folders on a granular basis.