
Microsoft’s June 2026 Patch Tuesday has 210 vulnerabilities, of which 67 are Elevation of Privilege. SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of June 2026 and has produced coverage for 14 of the reported vulnerabilities.
CVE | CVE Title | Signature |
| CVE-2020-17103 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | ASPY 7230 Exploit-exe exe.MP_529 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | ASPY 7229 Exploit-exe exe.MP_528 |
| CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability | ASPY 7231 Exploit-exe exe.MP_530 |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | ASPY 7232 Exploit-exe exe.MP_531 |
| CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability | IPS 3036 RDP Malformed Request 2 |
| CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability | ASPY 7233 Exploit-exe exe.MP_532 |
| CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability | ASP 7234 Exploit-exe exe.MP_533 |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability | ASPY 688 Malformed-png png.MP_6 |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability | ASPY 687 Malformed-png png.MP_5 |
| CVE-2026-45585 | Windows BitLocker Security Feature Bypass Vulnerability | ASPY 686 Exploit-exe exe.MP_528 |
| CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability | ASPY 685 Exploit-exe exe.MP_526 |
| CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability | ASPY 689 Exploit-exe exe.MP_534 |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability | IPS 4620 HTTP Request with Malformed Host Header 10 |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | IPS 4619 Windows HTTP.sys DoS (CVE-2026-49160) |
The vulnerabilities can be classified into the following categories:


For June there are 38 critical and 170 important vulnerabilities.


Microsoft tracks vulnerabilities that are being actively exploited at the time of discovery and those that have been disclosed publicly before the patch Tuesday release for each month. The above chart displays these metrics as seen each month.

Defense in Depth Vulnerability
| CVE | CVE Title |
| CVE-2026-42910 | Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability |
Denial of Service Vulnerabilities
| CVE | CVE Title |
| CVE-2026-42903 | Windows Kerberos Denial of Service Vulnerability |
| CVE-2026-42914 | Windows Kerberos Denial of Service Vulnerability |
| CVE-2026-42915 | Windows TCP/IP Denial of Service Vulnerability |
| CVE-2026-44805 | Windows Network Controller (NC) Host Agent Denial of Service Vulnerability |
| CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-45606 | Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability |
Elevation of Privilege Vulnerabilities
| CVE | CVE Title |
| CVE-2020-17103 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-33828 | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability |
| CVE-2026-34335 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-40371 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability |
| CVE-2026-40376 | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-40404 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-40409 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability |
| CVE-2026-41092 | Microsoft Kinect Elevation of Privilege Vulnerability |
| CVE-2026-41108 | Windows DNS Client Elevation of Privilege Vulnerability |
| CVE-2026-42828 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-42836 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
| CVE-2026-42837 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-42902 | Microsoft PowerToys Elevation of Privilege Vulnerability |
| CVE-2026-42904 | Windows TCP/IP Elevation of Privilege Vulnerability |
| CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-42911 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-42912 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-42916 | NT OS Kernel Elevation of Privilege Vulnerability |
| CVE-2026-42977 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42978 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42979 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability |
| CVE-2026-42983 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-42984 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability |
| CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability |
| CVE-2026-42991 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-44802 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44804 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44807 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44808 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44809 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-44810 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
| CVE-2026-44811 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-44813 | Windows DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-45476 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability |
| CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability |
| CVE-2026-45487 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
| CVE-2026-45490 | .NET SDK Elevation of Privilege Vulnerability |
| CVE-2026-45504 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability |
| CVE-2026-45592 | Windows Internet (wininet.dll) Elevation of Privilege Vulnerability |
| CVE-2026-45593 | Windows SDK Elevation of Privilege Vulnerability |
| CVE-2026-45596 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45597 | Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability |
| CVE-2026-45598 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45600 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
| CVE-2026-45601 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45603 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45605 | Windows Bluetooth Service Elevation of Privilege Vulnerability |
| CVE-2026-45637 | Microsoft DWM Core Library Elevation of Privilege Vulnerability |
| CVE-2026-45638 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-45640 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability |
| CVE-2026-45644 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability |
| CVE-2026-45647 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability |
| CVE-2026-45653 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-47281 | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-47292 | Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability |
| CVE-2026-47293 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
| CVE-2026-47648 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-48565 | Windows Narrator Braille Elevation of Privilege Vulnerability |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability |
| CVE-2026-48578 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48583 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-50511 | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-50512 | Microsoft PC Manager Elevation of Privilege Vulnerability |
Information Disclosure Vulnerabilities
| CVE | CVE Title |
| CVE-2026-42824 | M365 Copilot Information Disclosure Vulnerability |
| CVE-2026-42835 | Microsoft Teams for Android Information Disclosure Vulnerability |
| CVE-2026-42906 | Windows Shell Information Disclosure Vulnerability |
| CVE-2026-42907 | Windows Shell Information Disclosure Vulnerability |
| CVE-2026-42908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-42968 | Windows Telephony Server Information Disclosure Vulnerability |
| CVE-2026-42969 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42970 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42971 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-42972 | Windows Hyper-V Information Disclosure Vulnerability |
| CVE-2026-42973 | Windows Push Notification Information Disclosure Vulnerability |
| CVE-2026-44814 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-44821 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-45460 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-45466 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-45485 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2026-45503 | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2026-45594 | Windows Application Identity (AppID) Information Disclosure Vulnerability |
| CVE-2026-45604 | Windows Managed Installer Information Disclosure Vulnerability |
| CVE-2026-45608 | Windows DHCP Client Information Disclosure Vulnerability |
| CVE-2026-45634 | Windows DHCP Client Information Disclosure Vulnerability |
| CVE-2026-45639 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2026-47284 | Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-47285 | Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-47644 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability |
| CVE-2026-47655 | Microsoft Graph Information Disclosure Vulnerability |
| CVE-2026-48566 | Windows DWM Core Library Information Disclosure Vulnerability |
| CVE-2026-48579 | Microsoft Exchange Online Information Disclosure Vulnerability |
Remote Code Execution Vulnerabilities
| CVE | CVE Title |
| CVE-2026-26142 | Nuance PowerScribe Remote Code Execution Vulnerability |
| CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability |
| CVE-2026-42909 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42913 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42974 | Windows Performance Monitor Remote Code Execution Vulnerability |
| CVE-2026-42981 | Windows Performance Monitor Remote Code Execution Vulnerability |
| CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42987 | Windows Deployment Services (WDS) Remote Code Execution |
| CVE-2026-42992 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-42993 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44799 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44801 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-44815 | DHCP Client Service Remote Code Execution Vulnerability |
| CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45454 | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45457 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45486 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45497 | Microsoft M365 Copilot Remote Code Execution Vulnerability |
| CVE-2026-45583 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2026-45599 | Windows UPnP Device Host Remote Code Execution Vulnerability |
| CVE-2026-45607 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-45635 | Windows UPnP Device Host Remote Code Execution Vulnerability |
| CVE-2026-45636 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-45641 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-45643 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-45645 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-45648 | Windows Active Directory Domain Services Remote Code Execution Vulnerability |
| CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability |
| CVE-2026-47288 | Windows Kerberos Key Distribution Center (KDC) Remote Code Execution |
| CVE-2026-47289 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability |
| CVE-2026-47298 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-47635 | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| CVE-2026-47643 | Azure Stack Edge Remote Code Execution Vulnerability |
| CVE-2026-47652 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-47653 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-47654 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-48560 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-48574 | Windows Media Remote Code Execution Vulnerability |
Security Feature Bypass Vulnerabilities
| CVE | CVE Title |
| CVE-2026-42829 | Windows Administrator Protection Secure Feature Bypass Vulnerability |
| CVE-2026-45459 | Microsoft Excel Security Feature Bypass Vulnerability |
| CVE-2026-45482 | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability |
| CVE-2026-45585 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-45588 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-45595 | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2026-45654 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-45655 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-45656 | UEFI Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-47656 | Windows Boot Manager Security Feature Bypass Vulnerability |
| CVE-2026-48568 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48569 | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-48570 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48573 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48575 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-48576 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-49161 | Microsoft PC Manager Security Feature Bypass Vulnerability |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability |
Spoofing Vulnerabilities
| CVE | CVE Title |
| CVE-2026-33113 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-41098 | Azure Stack Edge Spoofing Vulnerability |
| CVE-2026-45453 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45462 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45464 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45465 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45467 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45468 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45479 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45481 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-45483 | Microsoft Office Project Server Spoofing Vulnerability |
| CVE-2026-45500 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-45501 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-45642 | Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability |
| CVE-2026-45649 | Office for Android Spoofing Vulnerability |
| CVE-2026-45650 | Microsoft Bing Search Spoofing Vulnerability |
| CVE-2026-47631 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-47634 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47636 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47637 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47638 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47639 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47640 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-47641 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-48562 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-50508 | Windows NTLM Spoofing Vulnerability |
Tampering Vulnerability
| CVE | CVE Title |
| CVE-2026-45491 | .NET Tampering Vulnerability |
| CVE-2026-45602 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability |
| CVE-2026-47287 | Visual Studio Code Tampering Vulnerability |
Share This Article

An Article By
An Article By
Security News
Security News