← All Posts
765Total Patches
50Critical
0Exploited in Wild
1CISA KEV

June 2026 Patch Tuesday: 765 Patches, 50 Critical, 0 Actively Exploited

By the Numbers

Microsoft's June 2026 Patch Tuesday addresses 765 vulnerabilities across Windows, Office, Azure, and browser components. Of these, 50 are rated Critical, 172 are rated Important, and none are currently being exploited in the wild. One vulnerability, CVE-2026-11645, appears in CISA's Known Exploited Vulnerabilities catalog. The Browser category dominates this release with 512 patches, the majority stemming from Chromium updates. Note: An additional 520 CVEs listed in Microsoft's documentation affect only Azure Linux packages and are excluded from the figures above, as they represent Linux distribution updates rather than Windows or Office patches.

Patches to Prioritize

CVE-2026-11645 | Chromium V8 Out of Bounds Memory Access | CISA KEV

This Chromium vulnerability affects Microsoft Edge and any other Chromium-based browsers. An attacker exploiting this flaw can achieve out of bounds memory access in the V8 JavaScript engine, potentially leading to remote code execution or information disclosure when a user visits a malicious webpage.

Attack vector: Network-based; requires user interaction (visiting a crafted website or clicking a malicious link). No authentication required.

Fix: Update Microsoft Edge to the latest version. The patch incorporates the upstream Chromium fix for the V8 engine. Organizations using managed browser deployments should push this update immediately given its CISA KEV status.

Critical Vulnerability Breakdown

CVE-2025-10263 | ARM Kernel TLBI Issue | CVSS 9.3

An ARM processor vulnerability where completion of affected memory accesses might not be guaranteed by completion of a Translation Lookaside Buffer Invalidate operation. This kernel-level flaw could allow privilege escalation on ARM-based Windows devices. Exploitation likelihood is rated less likely.

CVE-2026-26142 | Nuance PowerScribe Remote Code Execution | CVSS 9.8

A remote code execution vulnerability in Nuance PowerScribe. An attacker can execute arbitrary code on affected systems. With a CVSS of 9.8, this represents the highest-scoring vulnerability this month, though exploitation is rated less likely.

CVE-2026-32174 | Azure Bot Service Elevation of Privilege | CVSS 7.7

An elevation of privilege vulnerability in Azure Bot Service that could allow an authenticated attacker to gain elevated permissions within the service context.

CVE-2026-32193 | Azure Kubernetes Service Remote Code Execution | CVSS 8.8

A remote code execution vulnerability in AKS. An attacker with access to the cluster could execute arbitrary code, potentially compromising containerized workloads and cluster infrastructure.

CVE-2026-32208 | Microsoft Entra ID Spoofing | CVSS 8.8

A spoofing vulnerability in Microsoft Entra ID (formerly Azure Active Directory). An attacker could manipulate identity assertions, potentially bypassing authentication controls or impersonating legitimate users.

CVE-2026-33828 | Windows Device Health Attestation Elevation of Privilege | CVSS 7.8

A local elevation of privilege vulnerability in the Windows Device Health Attestation service. An attacker with local access could escalate from a standard user to elevated privileges.

CVE-2026-42824 | M365 Copilot Information Disclosure | CVSS 6.5

An information disclosure vulnerability in Microsoft 365 Copilot. An attacker could potentially access sensitive information processed by the AI assistant.

CVE-2026-42895 | Microsoft Copilot Tampering | CVSS 6.5

A tampering vulnerability in Microsoft Copilot that could allow an attacker to modify data or responses within the Copilot context.

By Product Family

Browser (512 patches)

The overwhelming majority of this month's patches address browser vulnerabilities, primarily through Chromium upstream updates affecting Microsoft Edge. CVE-2026-11645 is the standout issue here due to its CISA KEV listing. Organizations should ensure Edge auto-updates are functioning and verify deployment across managed endpoints.

Windows (86 patches)

Windows patches this month include CVE-2026-33828, an elevation of privilege issue in the Device Health Attestation service. The ARM-related CVE-2025-10263 also falls under Windows kernel patches for ARM64 devices. Standard Windows update procedures apply.

Office (64 patches)

Office receives 64 patches this cycle. While none are actively exploited, organizations should maintain regular patching cadence for Office applications given their exposure to user-delivered content.

SharePoint (21 patches)

SharePoint administrators should review this month's 21 patches. SharePoint's network-exposed nature makes it a common target, so timely patching is advisable.

Azure (9 patches)

Azure services see critical patches for Bot Service (CVE-2026-32174) and AKS (CVE-2026-32193). Azure customers should verify that automatic platform updates have applied, or manually update where self-managed deployments are in use.

Exchange (9 patches)

Exchange Server receives 9 patches. Given Exchange's history as a high-value target, administrators should prioritize testing and deployment.

.NET (11 patches)

.NET patches should be evaluated based on which runtime versions are deployed in production environments.

Defender (2 patches)

Microsoft Defender receives two patches. These typically deploy automatically through definition updates.

What to Patch First

  1. CVE-2026-11645 (Chromium/Edge): CISA KEV listing makes this the top priority despite no confirmed active exploitation against Microsoft products specifically. Patch immediately.
  2. CVE-2026-26142 (Nuance PowerScribe): CVSS 9.8 remote code execution. If PowerScribe is deployed in your environment, patch now.
  3. CVE-2025-10263 (ARM kernel): CVSS 9.3, affects ARM-based Windows devices. Prioritize if you have Surface Pro X, ARM-based servers, or similar hardware.
  4. CVE-2026-32193 (AKS) and CVE-2026-32208 (Entra ID): Both CVSS 8.8, affecting critical cloud infrastructure and identity services.
  5. CVE-2026-32174 (Azure Bot Service) and CVE-2026-33828 (Windows DHA): Address in your next maintenance window.
  6. Remaining browser patches: Roll out Edge updates organization-wide.
  7. Exchange and SharePoint: Schedule updates for internet-facing infrastructure within the week.

This Patch Tuesday is notable for its volume but presents a manageable risk profile, with no actively exploited vulnerabilities and only one CISA KEV entry requiring immediate attention.

Sources: Microsoft Security Response Center, CISA Known Exploited Vulnerabilities, National Vulnerability Database

Not sure which of these affect your environment?

Find out what is exploitable in your network.

Request Free Assessment