Microsoft June 2026 Patch Tuesday, (Tue, Jun 9th)
Microsoft today released patches for 204 vulnerabilities. 38 of these vulnerabilities are considered critical, and three have been disclosed before today. Six of the vulnerabilities affect Microsoft cloud solutions and do not require any user action. In addition, Microsoft incorporated 360 different vulnerabilities affecting Chromium into its Edge browser. This is certainly a busier-than-usual patch Tuesday. In particular, the large number of patched Chromium/Edge vulnerabilities underscores the impact of AI tools on vulnerability discovery. Some noteworthy vulnerabilities: CVE-2026-49160 : This vulnerability was made public a week ago. As implemented, the HPACK compression algorithm in HTTP/2 and HTTP/3 can lead to a compression bomb that consumes excessive resources. Many HTTP/2 implementations are vulnerable. Microsoft addressed this issue by adding a MaxHeadersCount registry setting that limits the amount of allocated resources. CVE-2026-47291 : Affecting the Microsoft web server engine http.sys, just like CVE-2026-49160, this vulnerability is rated critical and allows for remote code execution. The integer overflow requires an oversized request to trigger it. Microsoft recommends restricting the MaxRequestBytes to prevent exploitation until the patch can be rolled out. CVE-2026-45648: A stack-based buffer overflow in Active Directory Domain Services. A successful attack requires authentication, and Microsoft considers exploit development as unlikely . Microsoft fixed three different BitLocker security feature bypass vulnerabilities. One of the vulnerabilities was already publicly known. An anonymous researcher is credited with the discovery, but I assume it is one of the Nightmare Eclipse vulnerabilities. Several critical vulnerabilities affect Microsoft Office, Outlook, and Word. Description CVE Disclosed Exploited Exploitability (old versions) current version Severity CVSS Base (AVG) CVSS Temporal (AVG) .NET SDK Elevation of Privilege Vulnerability %%cve:2026-45490%% No No - - Important 7.8 6.8 .NET Tampering Vulnerability %%cve:2026-45491%% No No - - Important 6.2 5.4 ASP.NET Core Denial of Service Vulnerability %%cve:2026-45591%% No No - - Important 7.5 6.5 Azure HorizonDB Elevation of Privilege Vulnerability (no customer action required) %%cve:2026-48567%% No No - - Critical 10.0 8.7 Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability %%cve:2026-32193%% No No - - Critical 8.8 7.7 Azure Stack Edge Remote Code Execution Vulnerability %%cve:2026-47643%% No No - - Important 9.8 8.5 Azure Stack Edge Spoofing Vulnerability %%cve:2026-41098%% No No - - Important 8.4 7.3 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability (no customer action required) %%cve:2026-47644%% No No - - Critical 6.5 5.7 DHCP Client Service Remote Code Execution Vulnerability %%cve:2026-44815%% No No - - Critical 9.8 8.5 HTTP.sys Denial of Service Vulnerability %%cve:2026-49160%% Yes No - - Important 7.5 6.5 HTTP.sys Remote Code Execution
Sign in to read the full article
Create a free account to access all news, downloads, and community features
Originally published by SANS ISC
Source: https://isc.sans.edu/diary/rss/33064
This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.