Patch Tuesday 2026
The latest Patch Tuesday 2026 coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-42980: Patch Critical NT Kernel EoP Bug Now (CVSS 7.8)
Microsoft dropped its June 2026 Patch Tuesday updates on June 9, addressing a total of 67 vulnerabilities across the Windows ecosystem. Among them, CVE-2026-42980 stands out as a local...
Microsoft Patches Critical RDP Info Disclosure Bug CVE-2026-42908 Now
Microsoft patched a critical information disclosure bug in Windows Remote Desktop Services as part of its June 2026 security updates. CVE-2026-42908, an out-of-bounds read vulnerability, allows an...
Windows Shell Memory Leak Patch: Why June 2026's Medium Bug Is Critical
Microsoft's June 2026 Patch Tuesday touched down on the 9th, and tucked inside the usual monthly cavalcade of fixes was CVE-2026-42907, a medium-severity information disclosure vulnerability in the...
Windows TCP/IP Zero-Click Flaw Lets Attackers Gain SYSTEM Access
Microsoft’s June 2026 Patch Tuesday batch fixes a critical Windows networking flaw—CVE-2026-42904—that lets unauthenticated attackers escalate privileges to SYSTEM, the highest possible level...
CVE-2026-42903: Critical Kerberos Denial-of-Service Flaw Patched – Update Windows Domain Controllers Immediately
Microsoft has released a security update that patches CVE-2026-42903, a denial-of-service vulnerability in the Kerberos authentication protocol, as part of the June 2026 Patch Tuesday cycle. The...
CVE-2026-50507: Microsoft Reveals BitLocker Bypass That Lets Attackers With Physical Access Decrypt Drives
Microsoft published CVE-2026-50507 on June 9, 2026, as part of its monthly Patch Tuesday release. The vulnerability is classified as a Windows BitLocker security feature bypass, allowing an attacker...
CVE-2026-49160: Critical HTTP.sys DoS Flaw Patched in June 2026 Patch Tuesday – Update Now
Microsoft rolled out its June 2026 Patch Tuesday updates with a critical fix for a denial-of-service vulnerability in Windows HTTP Protocol Stack (HTTP.sys), tracked as CVE-2026-49160. The flaw,...
Microsoft Hotpatch Service Bug Lets Attackers Gain SYSTEM Privileges
June’s Patch Tuesday brought a new privilege escalation bug that server administrators need to prioritize: CVE-2026-42910, a hole in the Windows Hotpatch Monitoring Service. Microsoft disclosed the...
CVE-2026-45653: Microsoft Patches Important Windows Kernel Elevation-of-Privilege Flaw in June 2026 Patch Tuesday
Microsoft’s June 9, 2026 security update addresses CVE-2026-45653, a Windows kernel elevation-of-privilege vulnerability that could allow an attacker to gain SYSTEM-level access on a compromised...
CVE-2026-45608: Microsoft Patches Windows DHCP Client Information Disclosure Flaw – June 2026 Patch Tuesday
Microsoft's June 2026 Patch Tuesday release, published on June 9, contained a fix for CVE-2026-45608, an information disclosure vulnerability in the Windows DHCP Client service. The bug, listed in...
June 2026 Patch Tuesday: Fix This DWM Bug That Turns Low-Level Access Into SYSTEM Control
Microsoft’s June 9, 2026 Patch Tuesday rollout plugged CVE-2026-45637, an Important-rated elevation-of-privilege (EoP) vulnerability inside the Desktop Window Manager (DWM) core library. Assigned a...
CVE-2026-45638: Windows WinSock AFD Driver Local Privilege Escalation Flaw Patched
Microsoft patched a critical local privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) on June 9, 2026, as part of its monthly Patch Tuesday updates....