Patch Tuesday 2026
The latest Patch Tuesday 2026 coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-45638: Windows WinSock AFD Driver Local Privilege Escalation Flaw Patched
Microsoft patched a critical local privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) on June 9, 2026, as part of its monthly Patch Tuesday updates....
Patch Now: CVE-2026-45635 UPnP RCE Exploited in the Wild
Microsoft’s June 2026 Patch Tuesday delivered a critical fix for CVE-2026-45635, an Important-rated remote code execution (RCE) vulnerability in the Windows Universal Plug and Play (UPnP) Device...
DHCP Server CVE-2026-45602: Unauthenticated attackers can hijack network traffic with a CVSS 9.1 flaw in June 2026 Patch Tuesday.
Microsoft dropped a critical security patch on June 9, 2026, addressing a severe vulnerability in the Windows Dynamic Host Configuration Protocol (DHCP) Server. Tracked as CVE-2026-45602, this...
CVE-2026-45600: Microsoft Patches Important Windows Kernel Privilege Escalation Flaw in June 2026 Patch Tuesday
Microsoft’s June 2026 security update, released on the 9th as part of its regular Patch Tuesday cycle, addresses a local privilege escalation vulnerability tracked as CVE-2026-45600. The flaw,...
CVE-2026-45504: Apply June Exchange Patch Now to Block Privilege Escalation
Microsoft disclosed CVE-2026-45504—an elevation-of-privilege vulnerability in Microsoft Exchange Server—as part of its June 9, 2026 Patch Tuesday release. The vulnerability carries an Important...
Patch Now: Critical CVE-2026-45598 AFD.sys Bug Gives Hackers SYSTEM Access
Microsoft's June 2026 Patch Tuesday has arrived with a crucial fix for CVE-2026-45598, an Important-rated elevation-of-privilege vulnerability residing in the Windows Ancillary Function Driver for...
Microsoft Exchange Spoofing Flaw CVE-2026-45501: Patch Now to Block Phishing Attacks
Microsoft's June 2026 Patch Tuesday rollout includes a crucial fix for an Important-rated spoofing vulnerability in on-premises Exchange Server. Tracked as CVE-2026-45501, this security flaw could...
Windows UPnP Device Host RCE (CVE-2026-45599) Patched in June 2026 Update
Microsoft has pushed out a security update for a high-severity remote code execution vulnerability in the Windows UPnP Device Host service. Tracked as CVE-2026-45599, the flaw carries an 8.1 CVSS...
Patch Tuesday Fix: CVE-2026-45597 Gives SYSTEM Access via UI Automation Bug
Microsoft's June 9, 2026 security update addresses a significant local elevation-of-privilege vulnerability tracked as CVE-2026-45597. The flaw resides in the Windows UI Automation Manager,...
June 2026 Patch Tuesday: Windows MotW Bypass CVE-2026-45595 Gets Fix
Microsoft has released a security update to address CVE-2026-45595, a Windows Mark of the Web (MotW) security feature bypass vulnerability, as part of the June 9, 2026 Patch Tuesday. The flaw, rated...
CVE-2026-45604: Microsoft Patches Windows Managed Installer Information Disclosure Bug
Microsoft rolled out its June 2026 Patch Tuesday updates, addressing 49 vulnerabilities across the Windows ecosystem. Among them, CVE-2026-45604 stands out for its targeted impact on the Managed...
200 RCE bugs in June Patch Tuesday—patch Windows, Office, Azure now
Microsoft dropped its June 2026 Patch Tuesday release on June 9, packing fixes for roughly 200 disclosed vulnerabilities spanning Windows, Office, Azure, Exchange Online, Microsoft Graph, SQL Server,...