All incidents

Microsoft June 2026 Patch Tuesday addresses 208 vulnerabilities

vulnerabilityopenJun 9, 2026 — Jul 10, 2026
Microsoft June 2026 Patch Tuesday addresses 208 vulnerabilities

MICROSOFT’S June 2026 Patch Tuesday set a new record after issuing fixes for 208 vulnerabilities, the highest monthly total ever reported by the vendor. The update includes a flaw in Microsoft Defender that is already being exploited in the wild and a critical remote code execution bug in the Windows HTTP.sys driver. Administrators are urged to apply the patches without delay to reduce exposure to active threats.

The actively exploited vulnerability, tracked as CVE-2026-41091, affects Microsoft Defender and carries a CVSS score of 7.8. Although the exact nature of the flaw has not been disclosed publicly, Microsoft confirms that attackers are using it to gain elevated privileges on compromised systems. Details and the patch can be found in the Microsoft Security Response Center advisory here.

A separate critical issue, CVE-2026-47291, resides in the HTTP.sys component that underpins Internet Information Services. With a CVSS rating of 9.8, the bug stems from an integer overflow during HTTP/1.x header parsing, allowing an unauthenticated attacker to send specially crafted packets and execute arbitrary code with kernel privileges. Technical analysis of the flaw is available from The Zero Day Initiative here and a summary is provided by Security Online here. Temporary mitigations involve lowering the MaxRequestBytes registry value until the patch can be applied.

Other notable fixes in the same release address CVE-2026-45657, a Windows kernel remote code execution flaw, CVE-2026-44815, a DHCP client service vulnerability, and CVE-2026-49160, which also permits remote code execution via HTTP.sys. While these issues are not yet known to be exploited, their critical severity warrants prompt remediation. The broader context of the update is covered in a report by Security Affairs here.

The volume of patches pushes the total number of CVEs addressed by Microsoft in 2026 past the full‑year count for 2018, signalling a sustained increase in reported flaws. Although no threat actors have been linked to the HTTP.sys bug, the Defender vulnerability is already seen in active attacks, making it a priority for defenders. The Internet Storm Center diary notes that the update also resolves hundreds of Chromium‑based issues in Edge here.

Defenders should begin by deploying the June 2026 security updates across all affected systems, giving preference to the Defender and HTTP.sys patches due to their exploitation potential. Where immediate rebooting is not feasible, applying the MaxRequestBytes registry adjustment offers a short‑term safeguard against the HTTP.sys flaw. Monitoring HTTP request header volumes and reviewing TLS application data logs can help detect attempted exploitation.

Maintaining a rigorous patch management cycle, validating updates in a test environment before wide rollout, and leveraging vulnerability scanning tools will reduce the chance of missing critical fixes. Administrators should consult the MSRC advisories for each CVE to confirm applicable mitigations and verify that patches have been installed successfully. Staying current with Microsoft’s monthly releases remains the most effective defence against the growing tide of vulnerabilities.

Intelligence briefing updated Jul 10, 2026

CVE-2026-44815 9.8 CVE-2026-45657 9.8 CVE-2026-47291 9.8 CVE-2026-41091 7.8 KEV CVE-2026-49160 7.5
Root sourcemsrc.microsoft.com
Timeline Coverage

Swipe to explore timeline