Microsoft patched more than 200 vulnerabilities in June 2026, the largest Patch Tuesday the company has ever released. Among them: 33 to 38 rated Critical, six zero-days (five of which were publicly known before fixes shipped), and at least one flaw already being actively exploited in real attacks against businesses.
If your environment runs Microsoft 365, Exchange, or Windows endpoints, this is not a month to defer. One specific vulnerability is on CISA's Known Exploited Vulnerabilities catalog right now. Here is what to know and what to do about it.
Why This Month Broke Records
BleepingComputer and Qualys both counted approximately 206 Microsoft CVEs in June 2026, not including the 360-plus Chromium browser vulnerabilities that shipped alongside them. The Zero Day Initiative put the combined total above 570.
Dark Reading headlined it "Blame AI: Patch Tuesday Hits Record 206 CVEs." The argument: Microsoft has shipped an enormous amount of AI-powered code in the past 18 months. Copilot in Windows, M365 Copilot across every 365 subscription tier, Copilot Studio, Azure AI services, AI features baked into Visual Studio Code. Each new feature adds code. More code means more attack surface. More attack surface means more vulnerabilities to find and patch. That dynamic is not reversing.
The practical result is that June 2026 is the first month that broke 200. It probably will not be the last.
The Vulnerabilities That Matter Most Right Now
CVE-2026-42897: Exchange Server, Actively Exploited
This is the one that requires action now. Exchange Server contains a spoofing vulnerability that lets an attacker inject JavaScript into Outlook Web Access through a crafted email. CISA added it to the Known Exploited Vulnerabilities catalog, which is the federal government's closest thing to a mandatory-patch designation.
For businesses running Exchange Server on-premises or in a hybrid Microsoft 365 configuration, this patch goes first. If you are fully in Exchange Online with no on-prem Exchange in the mix, your exposure is narrower but still worth reviewing with your IT team. Hardening guidance applies to Outlook Web Access configuration regardless of hosting model.
CVE-2026-41091: Microsoft Defender Elevation of Privilege
The Zero Day Initiative reported this as exploited in the wild. An attacker who already has a foothold on a machine can use this flaw to escalate to SYSTEM-level privileges.
The practical scenario: an employee clicks a phishing link, installs something, and Defender has not been updated. CVE-2026-41091 is what turns that initial infection into a domain-level problem. Endpoint protection with a privilege escalation hole in it is protection with a gap in it.
CVE-2026-47291: HTTP.sys Remote Code Execution (CVSS 9.8)
Not confirmed as exploited yet, but a 9.8 CVSS score on a remote code execution flaw in a core Windows networking component gets patched immediately in well-managed environments. The window between a public 9.8 and active exploitation is not a reliable planning buffer.
HTTP.sys is the Windows kernel component that handles web traffic. Any Windows Server running web-facing services touches this. If that includes servers in your environment, this patch matters.
BitLocker Security Feature Bypasses
Microsoft patched several BitLocker vulnerabilities this month, including CVE-2026-45585 ("YellowKey"), which was publicly disclosed before the patch shipped. These require physical access to exploit, so risk is lower for office workstations.
Laptop fleets are a different calculation. For businesses where employees take machines home or travel, physical-access BitLocker bypasses are not academic. Deploy these, but test on a subset first. BitLocker patches occasionally interact poorly with specific hardware configurations, and a bad deployment can affect boot behavior.
The Larger Pattern Here
One month of 200 patches is a sprint. Every month of 200 patches is a sustained operation.
A business running 75 Windows endpoints with Exchange and Microsoft 365 has to go through this cycle monthly: figure out which vulnerabilities are actually being exploited versus which are theoretical, test patches against their specific configuration before pushing fleet-wide, deploy in stages, confirm deployment actually happened, and document it. Cyber insurance applications and compliance frameworks now ask specifically about patch cadence.
The volume question is also getting harder. The average Patch Tuesday in 2025 ran somewhere in the 80-to-140 Microsoft CVE range. June 2026 at 206 is an outlier, but the trend line has been climbing. A growing business running its own patch management through Windows Update alone is not necessarily keeping up with the triage and verification side.
What Your IT Team Should Prioritize This Month
If you are reviewing this with your IT provider or internal team, here is the triage order:
- CVE-2026-42897 (Exchange Server): Patch first. CISA's KEV designation means treat this as an active threat, not a future risk.
- CVE-2026-41091 (Defender EoP): Patch second. Endpoint protection with a privilege escalation bypass undermines the whole point.
- CVE-2026-47291 (HTTP.sys CVSS 9.8): High priority, especially for servers running web-facing services.
- BitLocker patches: Deploy to laptop fleet, test first on a small group before rolling out broadly.
For context on how unpatched systems contribute to actual breaches, the 2026 Verizon DBIR put unpatched vulnerabilities and credential theft at the top of the causation list again this year. The gap between "patch released" and "patch deployed" is where most exploitation happens.
If you want to understand what AI-powered threats are doing to the broader security environment, how ransomware groups are using AI in 2026 covers what changed on the attacker side in the past year.
Frequently Asked Questions
What is Patch Tuesday? Patch Tuesday is Microsoft's scheduled monthly security update release, held on the second Tuesday of each month. It covers vulnerabilities across Windows, Exchange, Office, and other Microsoft products. Adobe and other vendors often release patches on the same schedule.
How many vulnerabilities does Microsoft patch each month in 2026? The count has grown considerably. Monthly totals in 2025 and early 2026 ran in the 80-to-140 range for Microsoft CVEs. June 2026 set a record at approximately 206 Microsoft CVEs, with security researchers pointing to Microsoft's expanded AI product surface as a contributing factor. Including Chromium browser patches, the total exceeded 570.
What happens if my business skips or delays Patch Tuesday? Unpatched systems stay exposed to known attacks. In June 2026, CVE-2026-42897 (Exchange Server) was confirmed exploited in active attacks within the same window the patch was released, and CISA added it to the Known Exploited Vulnerabilities catalog. Delayed patching is one of the most consistent factors in successful breaches. The Verizon 2026 DBIR found it again at the top of the list.
Do computers need to restart after Windows security patches? Yes, most of the time. Kernel-level and driver patches do not take effect until the system restarts. Deployment processes that apply patches without confirming a restart often show machines as patched in the console when the vulnerable code is still running. Verification matters.
What does a managed IT provider do with Patch Tuesday that Windows Update does not? The difference is in three things Windows Update does not do on its own: triage (which patches are actively exploited versus theoretical), staged testing (verifying patches against your specific software stack before pushing to every machine), and verification (confirming via reporting that patches installed and systems rebooted). For organizations running Exchange, that also means tracking Exchange-specific patches on a separate schedule from OS patches.
Managing patch deployment and verification across 50 to 200 endpoints every month requires more than Windows Update. Talk to us about how a managed IT approach handles patch triage, testing, and documentation for growing businesses.