June 2026 Patch Tuesday forecast: Where are the CVEs?
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-45498 +1 in the same advisory: …41091 | Denial-of-Service Vulnerability in Microsoft Defender Antimalware Platform CVE-2026-45498 is a denial-of-service flaw (CWE-400, uncontrolled resource consumption) in the Microsoft Defender antimalware platform, rated 7.5 (High) with a network attack vector and no privileges or user interaction required. A remote, unauthenticated attacker can trigger excessive resource consumption that disrupts the Defender service, with high impact on availability but no confidentiality or integrity impact per the CVSS scoring. An attacker gains the ability to crash, hang, or disable antimalware protection on targeted systems, potentially leaving endpoints temporarily unprotected. Any deployment of Microsoft Defender — which is the default antimalware on modern Windows and is also deployed as a cloud service — is in scope, and CISA's required action explicitly points defenders to BOD 22-01 guidance for cloud services. The flaw has been added to CISA's KEV catalog (2026-05-20), EPSS assigns it a 63.1% probability of exploitation within 30 days, and headlines confirm it is being exploited in the wild alongside CVE-2026-41091. Do: Apply mitigations per Microsoft's vendor instructions and follow applicable CISA BOD 22-01 guidance for cloud services, as required by the KEV entry. Ensure the Defender antimalware platform and its security intelligence updates are fully current on all endpoints, and check event logs for Defender service crashes or disabled protection that may indicate exploitation. Ransomware use is currently listed as unknown, so treat any Defender outage on exposed systems as a potential precursor to follow-on activity. | 7.5 group max | 63% | KEV |
| masshundreds of millions of Windows endpoints (Defender is the default antimalware on modern Windows client and server) | |
| CVE-2026-42897 | Cross-Site Scripting in Microsoft Exchange Server Actively Exploited by Laundry Bear CVE-2026-42897 is an improper-neutralization flaw (CWE-79) in Microsoft Exchange Server that lets an unauthenticated remote attacker perform cross-site scripting and carry out spoofing. Per the CVSS vector (AV:N/PR:N/UI:R), exploitation requires a victim to interact with attacker-controlled content — reported attacks by the Russian actor Laundry Bear (TA488) trigger when a crafted email is opened in Exchange's webmail interface (Outlook Web Access). The attacker gains the ability to spoof the victim within their webmail session, and reported intrusions show mailbox access persisting even after organizations rotate credentials. Any organization running on-premises Microsoft Exchange Server or Exchange Server Subscription Edition is potentially exposed, particularly those publishing webmail to the internet; specific affected version ranges are not provided in the available data. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2026-05-15 and carries a very high EPSS score of 71.2%, though no public proof-of-concept is known. Do: Apply Microsoft's security update for CVE-2024-42897 to all on-premises Exchange and Exchange Subscription Edition servers per vendor guidance — no specific patch versions are provided in the available data, so consult the vendor advisory for build numbers. Federal agencies must patch or apply mitigations per BOD 22-01 given the KEV listing. Because reported attacks (Laundry Bear/TA488) maintain mailbox access after password resets, treat any suspected compromise as persistent: review OWA access logs and inbox rules for anomalies, and invalidate active webmail sessions and tokens, not just credentials. | 6.1 | 71% | KEV |
| large≈20,000+ internet-exposed Exchange servers (public-scan reporting) | |
| CVE-2026-45659 | Authenticated Deserialization RCE in Microsoft SharePoint Server (Actively Exploited) CVE-2026-45659 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Microsoft SharePoint Server in which an authorized (authenticated, low-privilege) attacker can submit crafted serialized data over the network, with no user interaction required, to execute code on the server. Successful exploitation carries high impact on confidentiality, integrity, and availability within the SharePoint service context, giving attackers a foothold for follow-on activity, and CISA notes that ransomware use is known. Organizations running on-premises Microsoft SharePoint Server are affected; the source data lists no specific version ranges, and the CPE scope (sharepoint server) points to the on-premises product rather than the Microsoft-managed SharePoint Online service. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-01 after active exploitation, and its EPSS score of 76.1% (100th percentile) indicates a high probability of near-term exploitation. The CVE record lists no public proof-of-concept, though related reporting describes exploitation activity following a public PoC release for a SharePoint authentication bypass. Do: Apply Microsoft's current security updates for SharePoint Server following vendor instructions, prioritizing internet-facing servers, and comply with CISA BOD 26-04, which requires applying mitigations per vendor guidance (including the cited Forensics Triage Requirements) or discontinuing use of the product if mitigations are unavailable. Because in-the-wild exploitation and ransomware use are confirmed, triage exposed servers for compromise: review IIS/SharePoint logs for unexpected authenticated requests, look for webshells or newly modified files in SharePoint web roots, and check for unusual child processes spawned by the SharePoint application pool. Given related reporting on an authentication-bypass PoC, also verify that any related SharePoint authentication-bypass patches are… | 8.8 | 76% | KEV ransomware |
| mass≈100,000 internet-exposed SharePoint Server deployments (order-of-magnitude estimate), with total users across on-premises deployments likely in the millions |
Full article752 words · extracted from helpnetsecurity.com · click to collapse
June 2026 Patch Tuesday is now live:
Record Microsoft Patch Tuesday, fresh zero-day

My forecast from last month was only partly right. After the Anthropic Mythos announcements and the deluge of newly discovered vulnerabilities from vendors like Mozilla, Microsoft’s updates were standard fare, 65 CVEs reported in Windows 11 and 58 in Windows 10.
The Microsoft Office releases were a bit higher with 19 CVEs or so reported for the online versions. Apple did indeed release their OS security updates the day before Patch Tuesday, which garnered some attention, and helped with a combined Windows and macOS set of deployments. The good news, with the exception of a minor Windows 11 problem, is that it all passed normally without a lot of reported issues in the following days.

Microsoft Defender blocks newly exploited RedSun and UnDefend threats
Microsoft only had one major out-of-band release since May Patch Tuesday. A May 21st release addressed CVE-2026-45659, a remote code execution vulnerability in Windows SharePoint Server. Three KBs covered SharePoint Enterprise Server 2016, Server 2019 and Server Subscription Edition. This vulnerability carries a CVSS of 8.8 and is not known to be publicly disclosed or exploited at this point.
The fix will be rolled into the June Patch Tuesday release. The June Patch Tuesday release will contain a fix for the failures and errors when installing KB5089549 for Windows 11. Microsoft acknowledged “this issue occurs on devices that have limited free space on the EFI System Partition (ESP), especially if it has 10 MB or less available.”
Last month I mentioned the Microsoft Defender exploit Bluehammer was fixed with a zero-day update on April Patch Tuesday. Fixes for two additional exploits, RedSun associated with CVE-2026-41091 and UnDefend with CVE-2026-45498, were released and dynamically updated the malware protection engine in Microsoft Defender on May 19th.
There was some controversy surrounding these vulnerabilities because their disclosure was made with proof-of-concept code and they were quickly exploited by threat actors. Regardless, ensure you have Microsoft Defender enabled and that it has updated to the latest version.
Microsoft launches Driver Quality Initiative
Microsoft reported exploitation of CVE-2026-42897, a spoofing vulnerability rated Critical in Microsoft Exchange Server. It carries a CVSS of 8.1. This is a cross-site scripting issue within Outlook Web Access. There is no patch for the vulnerability at this time but per Microsoft, “the Exchange Emergency Mitigation Service will provide mitigation automatically, and is on by default.” Make sure to check your configuration and confirm the service is enabled so you are protected from the known active threats.
This month, Microsoft held their first Windows Hardware Engineering Conference (WinHEC 2026) since 2018. At the conference they introduced the new Driver Quality Initiative project. Per the article, they want to “fundamentally raise the bar on driver quality, reliability and security across Windows.” A positive user experience is based on hardware devices, drivers and software working together smoothly and Microsoft emphasized this requires a partnership between hardware and software vendors.
With this project, Microsoft will be working closely with its partners by providing tools and utilities to raise driver quality. This looks to be an interesting initiative and we’ll have to watch how it evolves and its impact on the user experience.
June 2026 Patch Tuesday forecast
- Expect the standard Microsoft OS, Office and SharePoint updates. Be on the lookout for an Exchange Server update to address the reported exploited vulnerability CVE-2026-42897.
- The Adobe rotation for Creative Cloud Apps updates will most likely contain inCopy, inDesign, Photoshop, and perhaps Acrobat depending on which vulnerabilities have surfaced.
- Apple’s security update on May 11th covered all their operating systems and Safari. Based on their release schedule, we shouldn’t see anything new next week.
- Google Chrome 150 was released into the beta channel this week so we should see the final Desktop version on Patch Tuesday.
- Mozilla released Firefox 151.0.3 this week addressing two vulnerabilities rated High. I expect corresponding Thunderbird, Thunderbird ESR, and Firefox ESR updates either before or on Patch Tuesday. Mozilla has accelerated some of their releases to once a week for the past several weeks.
- Oracle has announced they will be providing security updates on the months between their quarterly Critical Product Updates. The Critical Security Patch Update Advisory, May 2026 was recently announced.
Microsoft didn’t have many new patches to release throughout the month despite a lot of company activity I reported. We’ll have to wait and see if the AI tools discover more issues and if the reported CVEs increase this month.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/06/05/june-2026-patch-tuesday-forecast/