Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

June 2026 Patch Tuesday: 198 CVEs Breakdown

PDQ
07/07/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Patch Tuesday recap. Did you also know that today is National Donald Duck Day? It seems fitting that the Disney character that most sysadmins can relate to, perpetually frustrated, often unlucky, overworked, prone to fits of rage, occasionally missing pants, is celebrated on a Patch Tuesday? Grab your pants and let's dive into the details. All right, so total exploits patched today, 198, 198. You remember how two months ago we talked about, you know, Project Glasswing and Clawed Mythos and how that might change how many patches and CVEs are released and stuff? Well, I mean, two months ago we had 163. Last month we had, I want to say it was like 118, somewhere around there. This month we've got 198. Before the whole Glasswing Mythos thing happened, it wasn't too uncommon for us to only have like 50, 60. I think now we're going to be considering those the good old days and maybe this is the new normal. Anyways, let's keep going with it. We got 32 of those are critical and then the rest are all important. So 166 important, that leaves zero moderate or low. And now this is kind of wild. We got 54 remote code executions and only 63 elevation of privilege. I mean, that's still a lot, but the ratio there of RCE to elevation of privilege, that's wild. I don't think I've ever seen it that close together. We've got a bunch of information disclosure, spoofing, tampering, denial of service and feature bypass CVEs in there as well, which I mean, what do you expect when you have 198? We do have three publicly disclosed, which considering the sheer amount of CVEs that we've got, that's not too bad. And none of those are being actively exploited. Okay. So those are just publicly disclosed. Let's dive into some of the highlights. This month's headliners are five CVEs, all rated at a 9.8 CBSS score, all rated remote code execution vulnerabilities, and all just waiting to ruin your day. I'm calling this group the party of five. I haven't seen the show, but the name fits. The target span HTTP.SYS, Windows kernel, the DHCP client service, Azure Stack Edge and Nuance PowerScribe. None are publicly known or actively exploited yet, but with network accessible attack vectors, low complexity and no user interaction required across the board, these are ones that I would prioritize first. All right, moving on. We got remote desktop client gets 11 RCE CVEs this month, which is a lot of attention for one component. This grouping I'm calling the Redmond football club. Now, three of these CVEs are rated at an 8.8 and the rest are all 7.5. The exploit pattern is consistent across the group. Connect a vulnerable RDP client to a malicious server and an attacker gets remote code execution on your device. None are exploited yet, but 11 CVEs in one component in one month is definitely worth keeping your eye on. For our last highlight, we have three CVEs impacting BitLocker this month, one of which is one of the three publicly disclosed CVEs this month. What's interesting is that all three CVEs were given a different rating, but CVE-2026-50507 isn't the highest rated of the three, even though that's the one that's publicly disclosed. Seems odd, but again, I don't give the scores. I just report them. Now, while these aren't the scariest CVEs this month, obviously BitLocker is there to keep your data safe if your device falls into the wrong hands. So if your users have a history of misplacing their laptops, these patches all of a sudden become a big deal. That wraps up our Patch Tuesday coverage this month. Happy Donald Duck Day to all my fellow sysadmins out there. We're overworked, underappreciated, and one faulty patch away from a meltdown, but keep the lights on anyway. Maybe system administration isn't all it's quacked up to be, but could you imagine the absolute chaos that would ensue if we let normal users touch our precious systems? If you find yourself needing a well-deserved break this Patch Tuesday, check out PDQ Connect. It can automate your Windows and third-party patching needs in just minutes. Just imagine not having to worry about new Chrome updates every other day that ends in Y. That's the dream. For PDQ, I'm Brock. Thanks for watching. We'll catch you next time.

TL;DR

  • June 2026 Patch Tuesday patched 198 CVEs — 32 Critical and 166 Important — with no Moderate or Low severity entries, suggesting triple-digit monthly releases may now be the new normal.
  • Five 9.8-rated RCEs dubbed the 'Party of Five' target HTTP.SYS, Windows kernel, DHCP client, Azure Stack Edge, and Nuance PowerScribe, with network-accessible vectors and no user interaction required.
  • Remote Desktop Client received 11 RCE CVEs in a single month, all exploitable by connecting to a malicious server — an unusual concentration in one component worth close monitoring.

Summary

June 2026 Patch Tuesday delivered a staggering 198 CVEs — a figure that host Brock frames as potentially the new normal following Microsoft's Project Glasswing and Clawed Mythos initiatives, which appear to have dramatically increased monthly patch volumes from the previous baseline of 50–60 CVEs. Of the 198 vulnerabilities, 32 are rated Critical and 166 Important, with zero Moderate or Low severity entries. The release includes 54 Remote Code Execution vulnerabilities and 63 Elevation of Privilege flaws — an unusually close ratio that Brock flags as historically unprecedented. Three CVEs are publicly disclosed but none are actively exploited. The top priority group, dubbed the 'Party of Five,' consists of five CVEs all rated 9.8 CVSS targeting HTTP.SYS, the Windows kernel, DHCP client service, Azure Stack Edge, and Nuance PowerScribe — all featuring network-accessible attack vectors with low complexity and no user interaction required. The Remote Desktop Client attracted 11 RCE CVEs this month (the 'Redmond Football Club'), rated between 7.5 and 8.8, exploitable by connecting to a malicious server. Three BitLocker vulnerabilities round out the highlights, including one publicly disclosed CVE (CVE-2026-50507), making these patches especially relevant for organizations with mobile workforces prone to device loss. PDQ Connect is positioned as the automation solution for managing this patching workload.

Chapters

0:00 - Intro & Donald Duck Day
0:31 - 198 CVEs by the Numbers
1:55 - Party of Five: 9.8-Rated RCEs
2:26 - Redmond Football Club: RDP CVEs
2:55 - BitLocker Vulnerabilities
3:50 - Automating Patches with PDQ Connect

Key Quotes

1:06 "I think now we're going to be considering those the good old days and maybe this is the new normal."
1:26 "The ratio there of RCE to elevation of privilege, that's wild. I don't think I've ever seen it that close together."
2:20 "With network accessible attack vectors, low complexity and no user interaction required across the board, these are ones that I would prioritize first."

FAQ

Which vulnerabilities should sysadmins prioritize first in the June 2026 Patch Tuesday release?

The five 9.8-rated RCEs — targeting HTTP.SYS, the Windows kernel, DHCP client service, Azure Stack Edge, and Nuance PowerScribe — should be patched first. They have network-accessible attack vectors, low complexity, and require no user interaction, making them high-risk even though none are actively exploited yet.

Are any of the June 2026 CVEs being actively exploited in the wild?

No. Three CVEs are publicly disclosed, but none of the 198 vulnerabilities patched this month are confirmed as actively exploited at the time of the recap.

Categories:
  • » Webinar Library
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Security Operations
  • Endpoint Management
  • Backup & Recovery
  • How-To
  • Getting Started
  • Patch Tuesday
  • Microsoft CVEs
  • Remote Code Execution
  • Elevation of Privilege
  • Remote Desktop Client
  • BitLocker
  • Windows Patching
  • Patch Automation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: June 2026 Patch Tuesday: 198 CVEs Breakdown

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Aug
                  13

                  Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                  08/13/202612:00 PM ET
                  More events

                  Upcoming Webinar Calendar

                  • 08/13/2026
                    12:00 PM
                    08/13/2026
                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                    https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                  • 08/27/2026
                    01:00 PM
                    08/27/2026
                    Becoming Agent Ready with Cyera: Essential Strategies and Insights
                    https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                  • 09/02/2026
                    12:00 PM
                    09/02/2026
                    Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                    https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                  • 09/30/2026
                    04:00 AM
                    09/30/2026
                    AI Command Center: Optimizing Visibility and Control in Your Operations
                    https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                  • 11/19/2026
                    01:00 PM
                    11/19/2026
                    360View: Govern, Secure & Recover Your Microsoft 365 Environment
                    https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                  Truth in IT
                  • Sponsor
                  • About Us
                  • Terms of Service
                  • Privacy Policy
                  • Contact Us
                  • Preference Management
                  Desktop version
                  Standard version