Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Fortra: June 2026 Patch Tuesday: 568 CVEs Breakdown

Fortra
10/08/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I'm here today to discuss the June patch Tuesday. And this was a big one, with 206 Microsoft CVEs and another 362 non-Microsoft CVEs, 360 of which were Chrome. If we add that up, we get 568 CVEs, which makes this the biggest patch Tuesday that I think I've ever seen. While Microsoft has had some negative publicity when it comes to security over the last little It was nice to see that they're still actually pushing forward. There were 38 acknowledgements of Microsoft employees in this month's patch drop, which is a pretty decent amount for them to contribute internally. We did see three publicly disclosed CVEs this month. Here they come, so get ready to write them down. There's CVE-2026-45586 in CFTmon, CVE-2026-50507 in Affecting BitLocker, and finally CVE-2026-4998 in CVE-2026-49160, which was the HTTP2 bomb denial of service that impacted many platforms. There's a really great write-up out there about this one if you want to check it out. The one CVE that I really want to pay attention to this month to see what happens is CVE-2026-47291. This was a remote code execution in HTTPSYS with a CVSS score of 9.8. It mentions unauthenticated attackers targeting the HTTP protocol stack. It says exploitation is more likely, and there were three different acknowledgements associated with this, so I'm really curious to see what comes of this one. Right now, there's no exploit out there for it, but it's definitely one that I'm going to pay attention to. And that's it for today. Once again, I'm Tyler Reguli, and this has been your June Patch Tuesday Recap.

TL;DR

  • June 2026 Patch Tuesday is one of the largest ever recorded, totaling 568 CVEs across Microsoft and third-party vendors, with Chrome accounting for 360 of the non-Microsoft disclosures.
  • Three CVEs were publicly disclosed this month, including a BitLocker flaw and an HTTP/2 bomb denial-of-service vulnerability affecting multiple platforms.
  • CVE-2026-47291, an unauthenticated remote code execution in HTTP.sys with a CVSS 9.8 score, is flagged as the highest-priority vulnerability to monitor for active exploitation.

Summary

June 2026's Patch Tuesday stands out as one of the largest on record, with a combined 568 CVEs spanning 206 Microsoft vulnerabilities and 362 non-Microsoft disclosures — 360 of which originated from Chrome. Tyler Reguly, Associate Director of Security R&D at Fortra, walks through the month's most significant findings in this rapid-fire recap. Three publicly disclosed CVEs are called out specifically: CVE-2026-45586 in CTFmon, CVE-2026-50507 affecting BitLocker, and CVE-2026-49160, an HTTP/2 bomb denial-of-service vulnerability with broad platform impact. The standout vulnerability this month is CVE-2026-47291, a remote code execution flaw in HTTP.sys carrying a CVSS score of 9.8. Targeting unauthenticated attackers via the HTTP protocol stack and rated as 'exploitation more likely,' this CVE drew three separate researcher acknowledgements — a signal that security teams should monitor it closely even though no public exploit currently exists. Notably, Microsoft also received 38 internal employee acknowledgements in this patch drop, a positive indicator of internal security investment despite recent public scrutiny of the company's security posture.

Chapters

0:00 - Introduction & Scale of June Patch Tuesday
0:21 - Microsoft Internal Security Contributions
0:38 - Three Publicly Disclosed CVEs
1:04 - CVE-2026-47291: HTTP.sys RCE Deep Dive

Key Quotes

0:16 "If we add that up, we get 568 CVEs, which makes this the biggest patch Tuesday that I think I've ever seen."
1:12 "This was a remote code execution in HTTPSYS with a CVSS score of 9.8."
1:22 "It says exploitation is more likely, and there were three different acknowledgements associated with this, so I'm really curious to see what comes of this one."

FAQ

Which vulnerability from June 2026 Patch Tuesday should security teams prioritize?

CVE-2026-47291, a remote code execution vulnerability in HTTP.sys, is the top priority. It carries a CVSS score of 9.8, targets unauthenticated attackers over the HTTP protocol stack, and is rated by Microsoft as 'exploitation more likely.' Three separate researcher acknowledgements add further urgency.

What were the three publicly disclosed CVEs in June 2026 Patch Tuesday?

The three publicly disclosed CVEs are CVE-2026-45586 (CTFmon), CVE-2026-50507 (BitLocker), and CVE-2026-49160, an HTTP/2 bomb denial-of-service vulnerability that impacted multiple platforms.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Threat Intelligence
  • Security Operations
  • Getting Started
  • How-To
  • Patch Tuesday
  • CVE Analysis
  • Remote Code Execution
  • HTTP.sys
  • BitLocker
  • Denial of Service
  • Microsoft Security
  • Chrome Vulnerabilities
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Fortra: June 2026 Patch Tuesday: 568 CVEs Breakdown

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      11:00 AM
                      10/27/2026
                      Maximize Security, Value, and Returns on Your Microsoft Investment
                      https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      02:00 PM
                      11/05/2026
                      HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                    • 11/05/2026
                      02:00 PM
                      11/05/2026
                      Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                      https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version