VulnerabilityBleeping Computer
9.8 — CRITICAL
Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws
Today is Microsoft's June 2026 Patch Tuesday, with security updates for 200 flaws, including five publicly disclosed zero-day vulnerabilities and one actively exploited in attacks. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Microsoft released a June 2026 Patch Tuesday, addressing six zero-day vulnerabilities and 200 flaws across various products, including .NET, Active Directory Domain Services, ASP.NET Core, Azure Stack Edge, and Microsoft Office.
⚙️Technical Details
💥Impact Assessment
Severity: High
Who Is at Risk
Organizations using affected products, including financial institutions, healthcare providers, and government agencies
🛡️Recommended Actions
1Apply patches for .NET vulnerabilities (CVE-2026-45491, CVE-2026-45490) as soon as possible
2Implement security updates for Azure Stack Edge (CVE-2026-47643, CVE-2026-41098)
3Use secure configurations and validate inputs for ASP.NET Core applications
📦Affected Products
.NETActive Directory Domain ServicesASP.NET CoreAzure Stack EdgeMicrosoft Office
🔐NVD Verified DataVERIFIED
CVE-2026-45491 ↗CVSS 6.2 — MEDIUM
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NWeaknesses
CWE-59
CVE-2026-45490 ↗CVSS 7.8 — HIGH
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-285
CVE-2026-45648 ↗CVSS 8.8 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-121
CVE-2026-45591 ↗CVSS 7.5 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HWeaknesses
CWE-400
CVE-2026-47643 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-73
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
