June 2026 Patch Tuesday: 200 CVEs, Three Public Disclosures, and a New Record

Microsoft's June 2026 Patch Tuesday, released June 9, is the largest single release in the program's history: 200 vulnerabilities, surpassing the previous record of 167. Of those, 33 are rated Critical — 28 remote code execution, four elevation of privilege, and one information disclosure. Microsoft reported no known in-the-wild exploitation at release, but three vulnerabilities were publicly disclosed before patches shipped.

A note on that 200 number: depending on which vendor roundup you read this week, the count is 198, 200, 206, or 208. Everyone counts differently — some include Edge/Chromium, some include flaws fixed earlier in the month, some don't. Keep that in mind any time your compliance story leans on a press headline instead of what's actually installed on your devices.

The Three Publicly Disclosed Vulnerabilities

CVE-2026-50507 — Windows BitLocker Security Feature Bypass (Important). An attacker with physical or local access can bypass BitLocker full-disk encryption. For most organizations BitLocker is the last-line control for lost or stolen hardware, and frequently a hard compliance requirement. If you're shipping field laptops, patch before they leave the building — and audit your BitLocker-protected inventory now, not after an incident.

CVE-2026-49160 — HTTP.sys Denial of Service (Important). A flaw in the HTTP/2 stack inside HTTP.sys, which underpins IIS and a long tail of Windows networking services. Public disclosure plus internet-facing attack surface is a bad combination; prioritize any public-facing web server.

CVE-2026-45586 — Windows CTFMON Elevation of Privilege (Important). A publicly disclosed path from a standard user context to SYSTEM via the Collaborative Translation Framework. EoP bugs like this are rarely the headline, but they're the second stage of nearly every real intrusion chain. Review your SYSTEM-escalation detections while the patch rolls out.

Where the Critical RCEs Cluster

Remote Desktop Client took the most concentrated hit: 11 CVEs in one cycle, including Critical-rated CVE-2026-44801, CVE-2026-44799, CVE-2026-42992, and CVE-2026-42985. RDP client bugs invert the usual threat model — the risk is your admins and users connecting out to a malicious or compromised server.

Hyper-V shipped three Critical RCEs — CVE-2026-47652, CVE-2026-45641, and CVE-2026-45607 — each capable of guest-to-host escape with code execution on the host. If you run multi-tenant or security-boundary-sensitive virtualization, these go to the front of the queue.

Office has multiple Critical client-side RCEs across Outlook, Word, and Office core, including CVE-2026-45458 and CVE-2026-45456, plus type-confusion and use-after-free variants. Preview-pane-adjacent Outlook bugs deserve the standard skepticism: assume user interaction requirements are optimistic.

Identity and core services round out the Critical list — Active Directory, Kerberos KDC, Windows Deployment Services, DHCP Client, and a Windows Cryptographic Services improper-authentication flaw (CVE-2026-44810) that allows local privilege elevation.

The Browser Sidebar

Separately from the Patch Tuesday count, roughly 360 Edge/Chromium vulnerabilities were patched this month — an order of magnitude above the historical norm. The volume is high enough that Microsoft has stopped enumerating Chromium CVEs in the Security Update Guide entirely. If your vulnerability reporting depends on SUG enumeration for browser coverage, that pipeline just changed underneath you.

What to Do This Week

  1. Deploy the June cumulative updates (KB5094126 for Windows 11, KB5094127 for Windows 10) through your normal ring progression — but compress the soak time for internet-facing servers affected by CVE-2026-49160.
  2. Prioritize CVE-2026-50507 on any BitLocker-protected device that travels.
  3. Patch Hyper-V hosts ahead of general workstation rollout if guests cross trust boundaries.
  4. Verify, don't assume. Last month's release reported no active exploitation at publication — and several of those CVEs landed on CISA KEV within days. The window between "patched per the console" and "actually installed and effective on every device" is exactly where you get hurt.

That last point is the one we'd underline. A record-size Patch Tuesday means record-size opportunity for deployment gaps: devices that report success but never rebooted, machines outside the management plane, update rings that stalled without anyone noticing. Intune will tell you what it sent. Independent, device-level verification tells you what actually happened — and with 200 CVEs in flight, the difference between those two numbers is your real exposure.

See Patchblox in Action

Unlock the Full Potential of Microsoft Endpoint Management

Request a Demo