What’s New Wednesday: June 2026 June 10, 2026 – Posted in: Cyber Security, What's New Wednesdays – Tags: Cyber Security, cybersecurity, Patch Tuesday, patching, SoftwareSupport, WhatsNewWednesday
Welcome to Patch Tuesday June 2026, this month Microsoft has released patches for 200 flaws including 3 publicly disclosed zero-day vulnerabilities. This count doesn’t include flaws in Mariner, Copilot, Exchange Online and Graph that Microsoft released patches for earlier this month. It’s a good idea to restart your PC today, and we may restart some of your servers overnight this week if a patch requires it.
NEW THIS WEDNESDAY
Overall Microsoft patched:
- 65 Elevation of Privilege Vulnerabilities
- 19 Security Feature Bypass vulnerabilities
- 55 Remote Code Execution Vulnerabilities
- 30 Information Disclosure Vulnerabilities
- 7 Denial of Service Vulnerabilities
- 27 Spoofing Vulnerabilities
There were 3 publicly disclosed zero-day vulnerabilities patched:
CVE-2026-45586 – Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
Improper link resolution before file access (‘link following’) in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
CVE-2026-49160 – HTTP.sys Denial of Service Vulnerability
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
CVE-2026-50507 – Windows BitLocker Security Feature Bypass Vulnerability
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Releases from other software providers include:
- Acer – warned about 2 max-severity unpatched flaws that could be used to hijack Acer Wave 7 routers.
- Adobe – security updates for multiple products including Experience Manager, InDesign, InCopy, Substance 3D Sampler, Dreamweaver, Reader, ColdFusion.
- Check Point – updates for a Remote Access VPN and Mobile Access flaw that was exploited in Qilin ransomware attacks.
- Cisco – updates for multiple products including an SD-WAN zero-day exploited in attacks and a Unified CM flaw with a PoC exploit.
- Fortinet – security updates for multiple flaws in FortiOS, FortiSandbox, and FortiProxy.
- Google – released Android’s June security bulletin, fixing 124 flaws and 1 actively exploited vulnerability, and fixed a new Google Chrome zero-day that was exploited in attacks.
- Ivanti – updates for vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) and Ivanti Sentry.
- Ubiquiti – updates for 3 vulnerabilities with maximum-severity ratings that could lead to remote code execution.
- SAP – June security updates, which include fixes for four critical flaws.
- Veeam – updates for a critical Backup & Replication security flaw that could be exploited to gain remote code execution (RCE) on domain-joined backup servers.
FULL LIST OF KNOWN PATCHES
| Vulnerable Service | CVE ID | CVE Title | Severity |
| .NET | CVE-2026-45491 | .NET Tampering Vulnerability | Important |
| .NET | CVE-2026-45490 | .NET SDK Elevation of Privilege Vulnerability | Important |
| Active Directory Domain Services | CVE-2026-45648 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | Critical |
| ASP.NET Core | CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability | Important |
| Azure Stack Edge | CVE-2026-47643 | Azure Stack Edge Remote Code Execution Vulnerability | Important |
| Azure Stack Edge | CVE-2026-41098 | Azure Stack Edge Spoofing Vulnerability | Important |
| Function Discovery Service (fdwsd.dll) | CVE-2026-42836 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | Important |
| GitHub Copilot and Visual Studio Code | CVE-2026-45482 | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability | Important |
| HTTP/2 | CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | Important |
| Linux MANA Driver | CVE-2026-45476 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability | Critical |
| Microsoft Azure Attestation service and Device Health Attestation Service | CVE-2026-45642 | Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability | Important |
| Microsoft Azure Attestation service and Device Health Attestation Service | CVE-2026-33828 | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability | Critical |
| Microsoft Azure Kubernetes Service | CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability | Critical |
| Microsoft Bing | CVE-2026-45650 | Microsoft Bing Search Spoofing Vulnerability | Important |
| Microsoft Defender for Endpoint | CVE-2026-45647 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | Important |
| Microsoft Dynamics 365 (on-premises) | CVE-2026-40371 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45500 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45501 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-47631 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45503 | Microsoft Exchange Server Information Disclosure Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45504 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45583 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important |
| Microsoft Graphics Component | CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability | Important |
| Microsoft Kinect | CVE-2026-41092 | Microsoft Kinect Elevation of Privilege Vulnerability | Important |
| Microsoft Live Share Canvas SDK | CVE-2026-45644 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability | Important |
| Microsoft Office | CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-44821 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-45485 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-45645 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-45460 | Microsoft Office Information Disclosure Vulnerability | Critical |
| Microsoft Office | CVE-2026-47635 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office Click-To-Run | CVE-2026-47293 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-45459 | Microsoft Excel Security Feature Bypass Vulnerability | Important |
| Microsoft Office Project | CVE-2026-45483 | Microsoft Office Project Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45465 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47634 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47640 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45481 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45468 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47638 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47639 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47641 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47637 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45467 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45453 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47636 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-48560 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47298 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45454 | Microsoft SharePoint Remote Code Execution Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-33113 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45479 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-48562 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45464 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45462 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office Word | CVE-2026-45643 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2026-45457 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2026-45486 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2026-45466 | Microsoft Word Information Disclosure Vulnerability | Important |
| Microsoft PC Manager | CVE-2026-49161 | Microsoft PC Manager Security Feature Bypass Vulnerability | Important |
| Microsoft PowerToys | CVE-2026-42902 | Microsoft PowerToys Elevation of Privilege Vulnerability | Important |
| Microsoft Teams for Android | CVE-2026-42835 | Microsoft Teams for Android Information Disclosure Vulnerability | Important |
| Microsoft UxTheme Library (uxtheme.dll) | CVE-2026-45606 | Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability | Important |
| Microsoft Windows DNS | CVE-2026-41108 | Windows DNS Client Elevation of Privilege Vulnerability | Important |
| Nuance PowerScribe | CVE-2026-26142 | Nuance PowerScribe Remote Code Execution Vulnerability | Critical |
| Office for Android | CVE-2026-45649 | Office for Android Spoofing Vulnerability | Important |
| Remote Desktop Client | CVE-2026-42993 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Remote Desktop Client | CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-47653 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Remote Desktop Client | CVE-2026-47289 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-42909 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Remote Desktop Client | CVE-2026-47654 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-42992 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-42913 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Remote Desktop Client | CVE-2026-44801 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-44799 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Role: Windows Hyper-V | CVE-2026-45641 | Windows Hyper-V Remote Code Execution Vulnerability | Critical |
| Role: Windows Hyper-V | CVE-2026-42972 | Windows Hyper-V Information Disclosure Vulnerability | Important |
| UI Automation Manager (uiamanager.dll) | CVE-2026-45597 | Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability | Important |
| Universal Plug and Play (upnp.dll) | CVE-2026-45599 | Windows UPnP Device Host Remote Code Execution Vulnerability | Important |
| Universal Plug and Play (upnp.dll) | CVE-2026-45635 | Windows UPnP Device Host Remote Code Execution Vulnerability | Important |
| Visual Studio Code | CVE-2026-47287 | Visual Studio Code Tampering Vulnerability | Important |
| Visual Studio Code | CVE-2026-47292 | Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability | Important |
| Visual Studio Code | CVE-2026-40376 | Visual Studio Code Elevation of Privilege Vulnerability | Important |
| Visual Studio Code | CVE-2026-47284 | Visual Studio Code Information Disclosure Vulnerability | Important |
| Visual Studio Code | CVE-2026-47281 | Visual Studio Code Elevation of Privilege Vulnerability | Important |
| Visual Studio Code | CVE-2026-48569 | Visual Studio Code Security Feature Bypass Vulnerability | Important |
| Windows Administrator Protection | CVE-2026-42829 | Windows Administrator Protection Secure Feature Bypass Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-42911 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-45598 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-45601 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-45603 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-34335 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-45596 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-45638 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Application Identity (AppID) Subsystem | CVE-2026-45604 | Windows Managed Installer Information Disclosure Vulnerability | Important |
| Windows Application Identity (AppID) Subsystem | CVE-2026-45594 | Windows Application Identity (AppID) Information Disclosure Vulnerability | Important |
| Windows BitLocker | CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability | Important |
| Windows BitLocker | CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability | Important |
| Windows BitLocker | CVE-2026-45655 | Windows BitLocker Security Feature Bypass Vulnerability | Important |
| Windows Bluetooth Port Driver | CVE-2026-45640 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability | Important |
| Windows Bluetooth Service | CVE-2026-45605 | Windows Bluetooth Service Elevation of Privilege Vulnerability | Important |
| Windows Boot Manager | CVE-2026-47656 | Windows Boot Manager Security Feature Bypass Vulnerability | Important |
| Windows Collaborative Translation Framework | CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability | Important |
| Windows Common Log File System Driver | CVE-2026-44809 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important |
| Windows Cryptographic Services | CVE-2026-44810 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Critical |
| Windows Deployment Services | CVE-2026-42987 | Windows Deployment Services (WDS) Remote Code Execution | Critical |
| Windows DHCP Client | CVE-2026-44815 | DHCP Client Service Remote Code Execution Vulnerability | Critical |
| Windows DHCP Client | CVE-2026-45608 | Windows DHCP Client Information Disclosure Vulnerability | Important |
| Windows DHCP Server | CVE-2026-45634 | Windows DHCP Client Information Disclosure Vulnerability | Important |
| Windows DHCP Server | CVE-2026-45602 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44807 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44814 | Windows DWM Core Library Information Disclosure Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44811 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44808 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-48566 | Windows DWM Core Library Information Disclosure Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-45637 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44813 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-42983 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44802 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44804 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows Hotpatch Monitoring Service | CVE-2026-42910 | Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability | Important |
| Windows HTTP.sys | CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability | Critical |
| Windows Hyper-V | CVE-2026-47652 | Windows Hyper-V Remote Code Execution Vulnerability | Critical |
| Windows Hyper-V | CVE-2026-45607 | Windows Hyper-V Remote Code Execution Vulnerability | Critical |
| Windows Internet (wininet.dll) | CVE-2026-45592 | Windows Internet (wininet.dll) Elevation of Privilege Vulnerability | Important |
| Windows Kerberos | CVE-2026-47288 | Windows Kerberos Key Distribution Center (KDC) Remote Code Execution | Critical |
| Windows Kerberos | CVE-2026-42914 | Windows Kerberos Denial of Service Vulnerability | Important |
| Windows Kerberos | CVE-2026-42903 | Windows Kerberos Denial of Service Vulnerability | Important |
| Windows Kernel | CVE-2026-42984 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows Kernel | CVE-2026-45653 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows Kernel | CVE-2026-48583 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows Kernel | CVE-2025-10263 | ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] | Critical |
| Windows Kernel | CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability | Critical |
| Windows Kernel-Mode Drivers | CVE-2026-45600 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important |
| Windows Mark of the Web (MOTW) | CVE-2026-45595 | Windows Mark of the Web Security Feature Bypass Vulnerability | Important |
| Windows Media | CVE-2026-48574 | Windows Media Remote Code Execution Vulnerability | Critical |
| Windows Narrator Braille | CVE-2026-48565 | Windows Narrator Braille Elevation of Privilege Vulnerability | Important |
| Windows Network Controller (NC) Host Agent | CVE-2026-44805 | Windows Network Controller (NC) Host Agent Denial of Service Vulnerability | Important |
| Windows NT OS Kernel | CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | Important |
| Windows NT OS Kernel | CVE-2026-42916 | NT OS Kernel Elevation of Privilege Vulnerability | Important |
| Windows NTFS | CVE-2026-45636 | Windows NTFS Remote Code Execution Vulnerability | Important |
| Windows NTLM | CVE-2026-50508 | Windows NTLM Spoofing Vulnerability | Important |
| Windows Performance Monitor | CVE-2026-42981 | Windows Performance Monitor Remote Code Execution Vulnerability | Important |
| Windows Performance Monitor | CVE-2026-42974 | Windows Performance Monitor Remote Code Execution Vulnerability | Important |
| Windows Program Compatibility Assistant Service | CVE-2026-45487 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | Important |
| Windows Projected File System Filter Driver | CVE-2026-42828 | Windows Projected File System Elevation of Privilege Vulnerability | Important |
| Windows Projected File System Filter Driver | CVE-2026-42837 | Windows Projected File System Elevation of Privilege Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42991 | Windows Push Notifications Elevation of Privilege Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42977 | Windows Push Notifications Elevation of Privilege Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42979 | Windows Push Notifications Elevation of Privilege Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42978 | Windows Push Notifications Elevation of Privilege Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42973 | Windows Push Notification Information Disclosure Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42970 | Windows Push Notification Information Disclosure Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42969 | Windows Push Notification Information Disclosure Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42971 | Windows Push Notification Information Disclosure Vulnerability | Important |
| Windows RDP | CVE-2026-45639 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Important |
| Windows RDP | CVE-2026-42908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Important |
| Windows SDK | CVE-2026-45593 | Windows SDK Elevation of Privilege Vulnerability | Important |
| Windows Secure Boot | CVE-2026-45588 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-45654 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48570 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48568 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48575 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48578 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48573 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48576 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Shell | CVE-2026-42907 | Windows Shell Information Disclosure Vulnerability | Important |
| Windows Shell | CVE-2026-42906 | Windows Shell Information Disclosure Vulnerability | Important |
| Windows Storage | CVE-2026-47648 | Windows Storage Elevation of Privilege Vulnerability | Important |
| Windows TCP/IP | CVE-2026-42904 | Windows TCP/IP Elevation of Privilege Vulnerability | Important |
| Windows TCP/IP | CVE-2026-42915 | Windows TCP/IP Denial of Service Vulnerability | Important |
| Windows Telephony Service | CVE-2026-42968 | Windows Telephony Server Information Disclosure Vulnerability | Important |
| Windows Telephony Service | CVE-2026-42912 | Windows Telephony Service Elevation of Privilege Vulnerability | Important |
| Windows UEFI | CVE-2026-8863 | UEFI Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows UEFI | CVE-2026-45656 | UEFI Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Universal Disk Format File System Driver (UDFS) | CVE-2026-40404 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Important |
| Windows Universal Disk Format File System Driver (UDFS) | CVE-2026-40409 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Important |
| Windows Win32K – GRFX | CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability | Critical |
| Windows Win32K – GRFX | CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability | Critical |
| Winlogon | CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability | Important |
GLOSSARY
- Authentication – proving who you are so you can be given access to what you need/have rights to.
- MFA – multi-factor authentication, proving who you are in multiple ways, something you know (like a password or pin), something you are (a fingerprint or retina scan), something you have (like your phone – proved with a code).
- Vulnerability – a defect in software that could allow an attacker to gain control of a system or service.
- Patch – a change to a piece of software, released after sale, to fix a problem or add a feature.
- Zero Day – Microsoft classifies a vulnerability as a zero-day if it is publicly disclosed or actively exploited with no official fix available.
- Actively Exploited – an actively exploited vulnerability is one that is being used by malicious actors.
- DDOS / DOS – (Distributed) Denial of Service attack, a method of swamping a service or server with so many false queries at once that it is forced offline.
- Disclosed – a disclosed vulnerability is one that the software creators have published, meaning that it can be easily found out about by anyone who knows where to look.
- CVE ID – CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws, the ID is the number assigned to that vulnerability.
- Severity – a disclosed vulnerability is one that the software creators have published, meaning that it can be easily found out about by anyone who knows where to look.
- Security Feature Bypass Vulnerabilities – allow for intruders to bypass security features such as password protection or MFA.
- Remote Code Execution Vulnerabilities – allow people to remotely trigger potentially malicious code on your device.
- Information Disclosure Vulnerabilities – allow the wrong people access to your data.
- Denial of Service Vulnerabilities – allow a DOS/DDOS attack to succeed.
- Spoofing Vulnerabilities – allow someone to pretend to be you/your systems.
If you have any concerns about cybersecurity, or would like to discuss any other IT Support needs you might have please give us a call on 01245 265100 or email us at . To stay up to date with our regular What’s New Wednesday emails and receive industry news straight to your inbox, subscribe to our newsletters in the top right.