Security 10960 Published by

Microsoft just released the June 2026 security update, and the patch count alone will make most IT admins sweat. The release tackles critical remote code execution flaws in HTTP.sys, patches firmware checks in Secure Boot and BitLocker, and closes dozens of Office and Exchange vulnerabilities that have been sitting in the wild. Administrators should always apply the latest servicing stack update first, because an outdated stack will silently skip newer security packages and leave systems exposed. Once the main patch installs and the system reboots, networks and workstations will stay out of the crosshairs until the next rollout.





June 2026 Security Updates Brings a Massive Patch Rollout to Windows and Office

Microsoft just pushed out its June 2026 security updates, and the patch count alone will make most IT admins sweat. The release tackles over two hundred Microsoft CVEs alongside dozens of third party vulnerabilities in Chrome and ARM components. This is not a minor maintenance drop. The update fixes critical memory corruption flaws in Windows HTTP.sys, patches multiple BitLocker and Secure Boot weaknesses, and addresses a long list of Office and Exchange vulnerabilities that have been sitting in the wild for months.

Win10

The June 2026 Security Update Fixes the Critical Flaws

The headline grabber here is the HTTP.sys remote code execution flaw, which carries a base score of 9.8 and has already been flagged as more likely to be exploited. That component handles core network traffic for Windows, so leaving it unpatched is like leaving the front door wide open. Several Secure Boot and BitLocker vulnerabilities also made the cut, which matters because attackers have been quietly refining ways to bypass firmware checks before the OS even loads. Exchange Server and Office SharePoint got their share of patches too, mostly targeting privilege escalation and injection flaws that have been circulating in targeted campaigns. If you run Windows Server or host mail systems, these are the ones that actually keep you awake at night. The rest of the list includes standard kernel, DWM, and Win32K fixes, which are important but rarely make headlines unless you are running specialized legacy software.

What the Patch Numbers Mean for Your System

The cumulative nature of Windows updates means this release bundles every security fix since the last major build, plus defense in depth improvements and servicing stack updates. Administrators should check ADV990001 before deploying anything, because the servicing stack update is the foundation that actually lets Windows install these patches without corrupting the registry or breaking driver signatures. The update also rolls out to Windows 11 version 24H2, 25H2, Windows Server 2025, and the extended support branches for Windows 10 and Server 2022. Hotpatching is now generally available for Azure Linux and Windows Server virtual machines, which allows kernel updates to apply without rebooting, though that feature still requires careful compatibility testing before pushing it to production workloads. Forcing admins to download standalone packages from the Microsoft Update Catalog for routine desktop updates feels like a step backward, but the offline binaries remain the only reliable way to stage deployments when Windows Update fails to deliver cleanly.

How to Install the Update Without Breaking Your Workflow

Deploying this update requires a bit of planning rather than just clicking install and walking away. The servicing stack update should always be applied first, even if Windows Update tries to handle it automatically, because an outdated servicing stack can silently fail to extract newer security binaries. We have watched this exact pattern play out after a rushed servicing stack deployment, where Windows silently skips newer security packages and leaves the system vulnerable until the next patch cycle. After the main patch installs, the system will require a reboot to replace locked kernel drivers and apply the defense in depth changes to Secure Boot and BitLocker components. Testing on a non critical workstation first is still the only reliable way to catch the occasional known issue listed in KB 5089549 and KB 5094125, because cumulative patches occasionally clash with third party anti malware or virtualization drivers. Once the reboot completes, the system will resume normal operations with the patched network stack, firmware checks, and Office components in place.

The security updates in detail:

TagCVEBase Score
Nuance PowerScribe CVE-2026-261429.8
Microsoft Azure Kubernetes Service CVE-2026-321938.8
Microsoft Office SharePoint CVE-2026-331135.4
Microsoft Azure Attestation service and Device Health Attestation Service CVE-2026-338287.8
Windows Ancillary Function Driver for WinSock CVE-2026-343357.0
Microsoft Dynamics 365 (on-premises) CVE-2026-403718.8
Visual Studio Code CVE-2026-403767.5
Windows Universal Disk Format File System Driver (UDFS) CVE-2026-404047.8
Windows Universal Disk Format File System Driver (UDFS) CVE-2026-404097.8
Microsoft Kinect CVE-2026-410927.8
Azure Stack Edge CVE-2026-410988.4
Microsoft Windows DNS CVE-2026-411087.0
M365 Copilot CVE-2026-428246.5
Windows Projected File System Filter Driver CVE-2026-428287.8
Windows Administrator Protection CVE-2026-428297.8
Microsoft Teams for Android CVE-2026-428358.1
Function Discovery Service (fdwsd.dll) CVE-2026-428367.0
Windows Projected File System Filter Driver CVE-2026-428377.8
Microsoft PowerToys CVE-2026-429027.8
Windows Kerberos CVE-2026-429036.5
Windows TCP/IP CVE-2026-429049.6
Windows DWM Core Library CVE-2026-429057.8
Windows Shell CVE-2026-429065.5
Windows Shell CVE-2026-429076.5
Windows RDP CVE-2026-429087.5
Remote Desktop Client CVE-2026-429097.5
Windows Hotpatch Monitoring Service CVE-2026-429107.8
Windows Ancillary Function Driver for WinSock CVE-2026-429117.0
Windows Telephony Service CVE-2026-429127.0
Remote Desktop Client CVE-2026-429137.5
Windows Kerberos CVE-2026-429145.3
Windows TCP/IP CVE-2026-429155.7
Windows NT OS Kernel CVE-2026-429167.8
Windows Telephony Service CVE-2026-429685.5
Windows Push Notifications CVE-2026-429695.5
Windows Push Notifications CVE-2026-429705.5
Windows Push Notifications CVE-2026-429715.5
Role: Windows Hyper-V CVE-2026-429725.5
Windows Push Notifications CVE-2026-429735.5
Windows Performance Monitor CVE-2026-429748.1
Windows Push Notifications CVE-2026-429777.8
Windows Push Notifications CVE-2026-429787.8
Windows Push Notifications CVE-2026-429797.8
Windows NT OS Kernel CVE-2026-429807.8
Windows Performance Monitor CVE-2026-429818.1
Windows DWM Core Library CVE-2026-429837.8
Windows Kernel CVE-2026-429847.0
Remote Desktop Client CVE-2026-429858.8
Microsoft Graphics Component CVE-2026-429867.8
Windows Deployment Services CVE-2026-429878.1
Winlogon CVE-2026-429897.8
Windows Push Notifications CVE-2026-429917.8
Remote Desktop Client CVE-2026-429927.5
Remote Desktop Client CVE-2026-429937.5
Remote Desktop Client CVE-2026-447997.5
Remote Desktop Client CVE-2026-448017.5
Windows DWM Core Library CVE-2026-448027.8
Windows Win32K - GRFX CVE-2026-448037.8
Windows DWM Core Library CVE-2026-448047.8
Windows Network Controller (NC) Host Agent CVE-2026-448055.5
Windows DWM Core Library CVE-2026-448077.8
Windows DWM Core Library CVE-2026-448087.8
Windows Common Log File System Driver CVE-2026-448097.8
Windows Cryptographic Services CVE-2026-448108.4
Windows DWM Core Library CVE-2026-448117.8
Windows Win32K - GRFX CVE-2026-448127.8
Windows DWM Core Library CVE-2026-448137.8
Windows DWM Core Library CVE-2026-448145.5
Windows DHCP Client CVE-2026-448159.8
Microsoft Office Excel CVE-2026-448177.8
Microsoft Office Excel CVE-2026-448187.0
Microsoft Office CVE-2026-448197.8
Microsoft Office Excel CVE-2026-448207.8
Microsoft Office CVE-2026-448215.5
Microsoft Office Excel CVE-2026-448228.2
Microsoft Office Excel CVE-2026-448237.8
Microsoft Office CVE-2026-448247.8
Microsoft Office SharePoint CVE-2026-454535.4
Microsoft Office SharePoint CVE-2026-454546.5
Microsoft Office Excel CVE-2026-454553.3
Microsoft Office CVE-2026-454568.4
Microsoft Office Word CVE-2026-454577.8
Microsoft Office CVE-2026-454588.4
Microsoft Office Excel CVE-2026-454593.3
Microsoft Office CVE-2026-454604.7
Microsoft Office CVE-2026-454618.4
Microsoft Office SharePoint CVE-2026-454624.6
Microsoft Office CVE-2026-454638.4
Microsoft Office SharePoint CVE-2026-454645.4
Microsoft Office SharePoint CVE-2026-454655.4
Microsoft Office Word CVE-2026-454663.3
Microsoft Office SharePoint CVE-2026-454674.6
Microsoft Office SharePoint CVE-2026-454684.6
Microsoft Office Excel CVE-2026-454697.8
Microsoft Office Word CVE-2026-454717.8
Microsoft Office CVE-2026-454728.4
Microsoft Office CVE-2026-454748.4
Microsoft Office CVE-2026-454757.8
Linux MANA Driver CVE-2026-454768.2
Microsoft Office SharePoint CVE-2026-454794.6
Microsoft Office SharePoint CVE-2026-454817.3
GitHub Copilot and Visual Studio Code CVE-2026-454828.4
Microsoft Office Project CVE-2026-454834.6
Microsoft Office SharePoint CVE-2026-454848.8
Microsoft Office CVE-2026-454853.3
Microsoft Office Word CVE-2026-454867.8
Windows Program Compatibility Assistant Service CVE-2026-454877.8
.NET CVE-2026-454907.8
.NET CVE-2026-454916.2
Microsoft Copilot CVE-2026-454977.7
Microsoft Exchange Server CVE-2026-455006.1
Microsoft Exchange Server CVE-2026-455016.5
Microsoft Exchange Server CVE-2026-455025.0
Microsoft Exchange Server CVE-2026-455038.1
Microsoft Exchange Server CVE-2026-455048.8
Microsoft Exchange Server CVE-2026-455837.5
Windows Collaborative Translation Framework CVE-2026-455867.8
Windows Secure Boot CVE-2026-455887.9
ASP.NET Core CVE-2026-455917.5
Windows Internet (wininet.dll) CVE-2026-455927.8
Windows SDK CVE-2026-455937.8
Windows Application Identity (AppID) Subsystem CVE-2026-455945.5
Windows Mark of the Web (MOTW) CVE-2026-455955.4
Windows Ancillary Function Driver for WinSock CVE-2026-455967.0
UI Automation Manager (uiamanager.dll) CVE-2026-455977.0
Windows Ancillary Function Driver for WinSock CVE-2026-455987.0
Universal Plug and Play (upnp.dll) CVE-2026-455998.1
Windows Kernel-Mode Drivers CVE-2026-456007.8
Windows Ancillary Function Driver for WinSock CVE-2026-456017.0
Windows DHCP Server CVE-2026-456029.1
Windows Ancillary Function Driver for WinSock CVE-2026-456037.0
Windows Application Identity (AppID) Subsystem CVE-2026-456045.5
Windows Bluetooth Service CVE-2026-456057.8
Microsoft UxTheme Library (uxtheme.dll) CVE-2026-456065.5
Windows Hyper-V CVE-2026-456078.4
Windows DHCP Client CVE-2026-456086.8
Windows DHCP Server CVE-2026-456345.5
Universal Plug and Play (upnp.dll) CVE-2026-456358.1
Windows NTFS CVE-2026-456367.8
Windows DWM Core Library CVE-2026-456377.8
Windows Ancillary Function Driver for WinSock CVE-2026-456387.8
Windows RDP CVE-2026-456397.5
Windows Bluetooth Port Driver CVE-2026-456407.0
Role: Windows Hyper-V CVE-2026-456418.4
Microsoft Azure Attestation service and Device Health Attestation Service CVE-2026-456423.9
Microsoft Office Word CVE-2026-456437.8
Microsoft Live Share Canvas SDK CVE-2026-456448.0
Microsoft Office CVE-2026-456457.8
Microsoft Defender for Endpoint CVE-2026-456475.5
Active Directory Domain Services CVE-2026-456488.8
Office for Android CVE-2026-456497.1
Microsoft Bing CVE-2026-456504.3
Windows Kernel CVE-2026-456537.0
Windows Secure Boot CVE-2026-456547.9
Windows BitLocker CVE-2026-456555.3
Windows UEFI CVE-2026-456567.8
Windows Kernel CVE-2026-456579.8
Windows BitLocker CVE-2026-456587.8
Visual Studio Code CVE-2026-472819.6
Visual Studio Code CVE-2026-472846.5
Visual Studio Code CVE-2026-472876.5
Windows Kerberos CVE-2026-472887.1
Remote Desktop Client CVE-2026-472898.8
Windows HTTP.sys CVE-2026-472919.8
Visual Studio Code CVE-2026-472927.8
Microsoft Office Click-To-Run CVE-2026-472937.0
Microsoft Office SharePoint CVE-2026-472988.0
Microsoft Exchange Server CVE-2026-476318.1
Microsoft Office SharePoint CVE-2026-476347.3
Microsoft Office CVE-2026-476358.4
Microsoft Office SharePoint CVE-2026-476365.4
Microsoft Office SharePoint CVE-2026-476374.6
Microsoft Office SharePoint CVE-2026-476384.6
Microsoft Office SharePoint CVE-2026-476395.4
Microsoft Office SharePoint CVE-2026-476404.6
Microsoft Office SharePoint CVE-2026-476414.6
Azure Stack Edge CVE-2026-476439.8
Copilot Chat (Microsoft Edge) CVE-2026-476446.5
Windows Storage CVE-2026-476487.0
Windows Hyper-V CVE-2026-476528.2
Remote Desktop Client CVE-2026-476538.8
Remote Desktop Client CVE-2026-476547.5
Microsoft Graph CVE-2026-476556.5
Windows Boot Manager CVE-2026-476567.9
Microsoft Office SharePoint CVE-2026-485605.4
Microsoft Office SharePoint CVE-2026-485624.6
Remote Desktop Client CVE-2026-485637.5
Windows Narrator Braille CVE-2026-485657.8
Windows DWM Core Library CVE-2026-485665.5
Azure HorizonDB CVE-2026-4856710.0
Windows Secure Boot CVE-2026-485687.9
Visual Studio Code CVE-2026-485697.1
Windows Secure Boot CVE-2026-485707.9
Windows Secure Boot CVE-2026-485737.9
Windows Media CVE-2026-485747.8
Windows Secure Boot CVE-2026-485757.9
Windows Secure Boot CVE-2026-485767.9
Windows Secure Boot CVE-2026-485787.9
Microsoft Exchange Online CVE-2026-485799.1
Windows Kernel CVE-2026-485837.8
HTTP/2 CVE-2026-491607.5
Microsoft PC Manager CVE-2026-491617.8
Windows BitLocker CVE-2026-505076.8
Windows NTLM CVE-2026-505086.5

Keep your update schedule tight this month, and do not skip the servicing stack step. The patches will handle themselves once you let them, and your systems will stay out of the crosshairs until the next rollout.