Forum Discussion
Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs
On June 9, Microsoft released its June 2026 Patch Tuesday release which patched 198 CVEs with 32 rated as critical and 166 rated as important. This month's updates included three zero-days that were publicly disclosed prior to patches being made available.
This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CVEs in the October 2025 Patch Tuesday release.
One of the zero-days is CVE-2026-50507, a security feature bypass vulnerability affecting Windows BitLocker. It received a CVSSv3 score of 6.8 and is rated as important.
According to Microsoft, an attacker with physical access to the system could bypass the BitLocker Device Encryption feature in order to gain access to the device's encrypted data. This vulnerability appears to be the flaw known as Bitskrieg and a collaboration between Chaotic Eclipse (Nightmare Eclipse) and Jonas L. Chaotic Eclipse or Nightmare Eclipse has published several additional zero-days recently, including BlueHammer (CVE-2026-33825), GreenPlasma, MiniPlasma and YellowKey (CVE-2026-45585).
This month’s update includes patches for:
- .NET
- ASP.NET Core
- Active Directory Domain Services
- Azure HorizonDB
- Azure Stack Edge
- Copilot Chat (Microsoft Edge)
- Function Discovery Service (fdwsd.dll)
- GitHub Copilot and Visual Studio Code
- HTTP/2
- Linux MANA Driver
- M365 Copilot
- Microsoft Azure Attestation service and Device Health Attestation Service
- Microsoft Azure Kubernetes Service
- Microsoft Bing
- Microsoft Copilot
- Microsoft Defender for Endpoint
- Microsoft Dynamics 365 (on-premises)
- Microsoft Exchange Online
- Microsoft Exchange Server
- Microsoft Graph
- Microsoft Graphics Component
- Microsoft Kinect
- Microsoft Live Share Canvas SDK
- Microsoft Office
- Microsoft Office Click-To-Run
- Microsoft Office Excel
- Microsoft Office Project
- Microsoft Office SharePoint
- Microsoft Office Word
- Microsoft PC Manager
- Microsoft PowerToys
- Microsoft Teams for Android
- Microsoft UxTheme Library (uxtheme.dll)
- Microsoft Windows DNS
- Nuance PowerScribe
- Office for Android
- Remote Desktop Client
- Role: Windows Hyper-V
- UI Automation Manager (uiamanager.dll)
- Universal Plug and Play (upnp.dll)
- Visual Studio Code
- Windows Administrator Protection
- Windows Ancillary Function Driver for WinSock
- Windows Application Identity (AppID) Subsystem
- Windows BitLocker
- Windows Bluetooth Port Driver
- Windows Bluetooth Service
- Windows Boot Manager
- Windows Collaborative Translation Framework
- Windows Common Log File System Driver
- Windows Cryptographic Services
- Windows DHCP Client
- Windows DHCP Server
- Windows DWM Core Library
- Windows Deployment Services
- Windows HTTP.sys
- Windows Hotpatch Monitoring Service
- Windows Hyper-V
- Windows Internet (wininet.dll)
- Windows Kerberos
- Windows Kernel
- Windows Kernel-Mode Drivers
- Windows Mark of the Web (MOTW)
- Windows Media
- Windows NT OS Kernel
- Windows NTFS
- Windows Narrator Braille
- Windows Network Controller (NC) Host Agent
- Windows Performance Monitor
- Windows Program Compatibility Assistant Service
- Windows Projected File System Filter Driver
- Windows Push Notifications
- Windows RDP
- Windows SDK
- Windows Secure Boot
- Windows Shell
- Windows Storage
- Windows TCP/IP
- Windows Telephony Service
- Windows UEFI
- Windows Universal Disk Format File System Driver (UDFS)
- Windows Win32K - GRFX
- Winlogon
For more information, please visit our blog.
1 Reply
- jodoj80Connect Contributor
Hey Tenable team,
The filter referenced in the "Tenable Solutions" blog section appears to be incorrect. It's currently missing the "Windows: Microsoft Bulletins" family filter, which results in the error message: "Invalid query. Please try again.".
Could you please review and update the filter accordingly in the blog.
Thanks.