
Today is Microsoft's June 2026 Patch Tuesday, with security updates for 200 flaws and three publicly disclosed zero-day vulnerabilities.
This Patch Tuesday addresses 33 "Critical" vulnerabilities, 28 of which are remote code execution, 4 are elevation of privilege, and 1 is an information disclosure flaw.
The number of bugs in each vulnerability category is listed below:
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today.
Therefore, the number of flaws does not include flaws in Mariner, Azure HorizonDB, Microsoft Copilot, Copilot Chat, M365 Copilot, Microsoft Exchange Online, and Microsoft Graph that were fixed by Microsoft earlier this month.
There were also a massive 360 Microsoft Edge/Chromium flaws that were fixed by Google this month, which were excluded from this Patch Tuesday roundup.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5094126 & KB5093998 cumulative updates and the Windows 10 KB5094127 extended security update.
This month's Patch Tuesday fixes three publicly disclosed zero-day vulnerabilities, none of which are known to have been exploited in attacks.
Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available.
The two publicly disclosed zero-days are:
Microsoft has patched a publicly disclosed Windows CTFMON vulnerability that grants SYSTEM privileges.
"Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally," explains Microsoft.
Microsoft credited the flaw to an anonymous researcher, but BleepingComputer has learned that this is a fix for the "GreenPlasma" zero-day flaw that was disclosed by security researcher Nightmare Eclipse.
GreenPlasma is a privilege escalation vulnerability that could be exploited to obtain a shell with SYSTEM permissions
Nightmare Eclipse has released a wave of Windows zero-day vulnerabilities, including BlueHammer, MiniPlasma, RedSun, UnDefend, and YellowKey (also fixed today) in protest of Microsoft's handling of its bug bounty and vulnerability disclosure programs.
CVE-2026-49160 - HTTP.sys Denial of Service Vulnerability
Microsoft has patched a publicly disclosed HTTP/2 denial of service flaw called "HTTP/2 Bomb" that was disclosed this month by researchers at the offensive security firm Calif.
"Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network," explains Microsoft.
The HTTP/2 Bomb attack is a denial-of-service technique that abuses how the HTTP/2 protocol compresses and manages web traffic headers, allowing attackers to send very small amounts of data that force servers to allocate disproportionately large amounts of memory.
Researchers found the attack could dramatically increase memory usage on affected servers. Attackers can also keep the memory tied up by manipulating flow-control settings, preventing the server from freeing resources and potentially causing performance issues or outages.
To help mitigate this attack, Microsoft has introduced a new "MaxHeadersCount" registry setting to limit the number of headers in a request, along with a support bulletin on how to use it.
"Microsoft also introduced a new MaxHeadersCount registry setting. This setting allows you to limit the number of headers included in HTTP/2 and HTTP/3 requests that are accepted by the HTTP server. For more information, see KB5102602," continued Microsoft.
This flaw was attributed to Quang Luong and Codex of Calif.io.
CVE-2026-50507 - Windows BitLocker Security Feature Bypass Vulnerability
Microsoft has patched a publicly disclosed Windows BitLocker bypass flaw that allowed local attackers to gain access to an encrypted drive.
"Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack," explains Microsoft.
While Microsoft attributed the flaw to an anonymous researcher, BleepingComputer has learned that this is a fix for the YellowKey vulnerability that was also publicly disclosed last month by a cybersecurity researcher named Nightmare Eclipse.
The YellowKey vulnerability could be exploited by placing specially crafted files on a USB drive or EFI partition and booting into the Windows Recovery Environment (WinRE), where holding down the CTRL key triggered a command shell with unrestricted access to encrypted BitLocker-protected drives.
The flaw primarily affects systems that used TPM-only BitLocker protection on Windows 11 and Windows Server 2022/2025 devices. Microsoft previously shared temporary mitigations for the issue, including enabling TPM+PIN authentication instead of relying solely on TPM protection.
Other vendors who released updates or advisories in May 2026 include:
Below is the complete list of resolved vulnerabilities in the May 2026 Patch Tuesday updates, excluding flaws fixed before today.
To access the full description of each vulnerability and the systems it affects, you can view the full report here.
| Tag | CVE ID | CVE Title | Severity |
|---|---|---|---|
| .NET | CVE-2026-45491 | .NET Tampering Vulnerability | Important |
| .NET | CVE-2026-45490 | .NET SDK Elevation of Privilege Vulnerability | Important |
| Active Directory Domain Services | CVE-2026-45648 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | Critical |
| ASP.NET Core | CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability | Important |
| Azure Stack Edge | CVE-2026-47643 | Azure Stack Edge Remote Code Execution Vulnerability | Important |
| Azure Stack Edge | CVE-2026-41098 | Azure Stack Edge Spoofing Vulnerability | Important |
| Function Discovery Service (fdwsd.dll) | CVE-2026-42836 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | Important |
| GitHub Copilot and Visual Studio Code | CVE-2026-45482 | Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability | Important |
| HTTP/2 | CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | Important |
| Linux MANA Driver | CVE-2026-45476 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability | Critical |
| Microsoft Azure Attestation service and Device Health Attestation Service | CVE-2026-45642 | Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability | Important |
| Microsoft Azure Attestation service and Device Health Attestation Service | CVE-2026-33828 | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability | Critical |
| Microsoft Azure Kubernetes Service | CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability | Critical |
| Microsoft Bing | CVE-2026-45650 | Microsoft Bing Search Spoofing Vulnerability | Important |
| Microsoft Defender for Endpoint | CVE-2026-45647 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | Important |
| Microsoft Dynamics 365 (on-premises) | CVE-2026-40371 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45500 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45501 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-47631 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45503 | Microsoft Exchange Server Information Disclosure Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45504 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability | Important |
| Microsoft Exchange Server | CVE-2026-45583 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important |
| Microsoft Graphics Component | CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability | Important |
| Microsoft Kinect | CVE-2026-41092 | Microsoft Kinect Elevation of Privilege Vulnerability | Important |
| Microsoft Live Share Canvas SDK | CVE-2026-45644 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability | Important |
| Microsoft Office | CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-44821 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-45485 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-45645 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-45460 | Microsoft Office Information Disclosure Vulnerability | Critical |
| Microsoft Office | CVE-2026-47635 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office Click-To-Run | CVE-2026-47293 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office Excel | CVE-2026-45459 | Microsoft Excel Security Feature Bypass Vulnerability | Important |
| Microsoft Office Project | CVE-2026-45483 | Microsoft Office Project Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45465 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47634 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47640 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45481 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45468 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47638 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47639 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47641 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47637 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45467 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45453 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47636 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-48560 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-47298 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45454 | Microsoft SharePoint Remote Code Execution Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-33113 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45479 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-48562 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45464 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office SharePoint | CVE-2026-45462 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office Word | CVE-2026-45643 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2026-45457 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2026-45486 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Microsoft Office Word | CVE-2026-45466 | Microsoft Word Information Disclosure Vulnerability | Important |
| Microsoft PC Manager | CVE-2026-49161 | Microsoft PC Manager Security Feature Bypass Vulnerability | Important |
| Microsoft PowerToys | CVE-2026-42902 | Microsoft PowerToys Elevation of Privilege Vulnerability | Important |
| Microsoft Teams for Android | CVE-2026-42835 | Microsoft Teams for Android Information Disclosure Vulnerability | Important |
| Microsoft UxTheme Library (uxtheme.dll) | CVE-2026-45606 | Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability | Important |
| Microsoft Windows DNS | CVE-2026-41108 | Windows DNS Client Elevation of Privilege Vulnerability | Important |
| Nuance PowerScribe | CVE-2026-26142 | Nuance PowerScribe Remote Code Execution Vulnerability | Critical |
| Office for Android | CVE-2026-45649 | Office for Android Spoofing Vulnerability | Important |
| Remote Desktop Client | CVE-2026-42993 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Remote Desktop Client | CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-47653 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Remote Desktop Client | CVE-2026-47289 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-42909 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Remote Desktop Client | CVE-2026-47654 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-42992 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-42913 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Remote Desktop Client | CVE-2026-44801 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-44799 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Remote Desktop Client | CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Role: Windows Hyper-V | CVE-2026-45641 | Windows Hyper-V Remote Code Execution Vulnerability | Critical |
| Role: Windows Hyper-V | CVE-2026-42972 | Windows Hyper-V Information Disclosure Vulnerability | Important |
| UI Automation Manager (uiamanager.dll) | CVE-2026-45597 | Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability | Important |
| Universal Plug and Play (upnp.dll) | CVE-2026-45599 | Windows UPnP Device Host Remote Code Execution Vulnerability | Important |
| Universal Plug and Play (upnp.dll) | CVE-2026-45635 | Windows UPnP Device Host Remote Code Execution Vulnerability | Important |
| Visual Studio Code | CVE-2026-47287 | Visual Studio Code Tampering Vulnerability | Important |
| Visual Studio Code | CVE-2026-47292 | Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability | Important |
| Visual Studio Code | CVE-2026-40376 | Visual Studio Code Elevation of Privilege Vulnerability | Important |
| Visual Studio Code | CVE-2026-47284 | Visual Studio Code Information Disclosure Vulnerability | Important |
| Visual Studio Code | CVE-2026-47281 | Visual Studio Code Elevation of Privilege Vulnerability | Important |
| Visual Studio Code | CVE-2026-48569 | Visual Studio Code Security Feature Bypass Vulnerability | Important |
| Windows Administrator Protection | CVE-2026-42829 | Windows Administrator Protection Secure Feature Bypass Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-42911 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-45598 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-45601 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-45603 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-34335 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-45596 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Ancillary Function Driver for WinSock | CVE-2026-45638 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important |
| Windows Application Identity (AppID) Subsystem | CVE-2026-45604 | Windows Managed Installer Information Disclosure Vulnerability | Important |
| Windows Application Identity (AppID) Subsystem | CVE-2026-45594 | Windows Application Identity (AppID) Information Disclosure Vulnerability | Important |
| Windows BitLocker | CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability | Important |
| Windows BitLocker | CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability | Important |
| Windows BitLocker | CVE-2026-45655 | Windows BitLocker Security Feature Bypass Vulnerability | Important |
| Windows Bluetooth Port Driver | CVE-2026-45640 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability | Important |
| Windows Bluetooth Service | CVE-2026-45605 | Windows Bluetooth Service Elevation of Privilege Vulnerability | Important |
| Windows Boot Manager | CVE-2026-47656 | Windows Boot Manager Security Feature Bypass Vulnerability | Important |
| Windows Collaborative Translation Framework | CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability | Important |
| Windows Common Log File System Driver | CVE-2026-44809 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important |
| Windows Cryptographic Services | CVE-2026-44810 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Critical |
| Windows Deployment Services | CVE-2026-42987 | Windows Deployment Services (WDS) Remote Code Execution | Critical |
| Windows DHCP Client | CVE-2026-44815 | DHCP Client Service Remote Code Execution Vulnerability | Critical |
| Windows DHCP Client | CVE-2026-45608 | Windows DHCP Client Information Disclosure Vulnerability | Important |
| Windows DHCP Server | CVE-2026-45634 | Windows DHCP Client Information Disclosure Vulnerability | Important |
| Windows DHCP Server | CVE-2026-45602 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44807 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44814 | Windows DWM Core Library Information Disclosure Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44811 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44808 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-48566 | Windows DWM Core Library Information Disclosure Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-45637 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44813 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-42983 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44802 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows DWM Core Library | CVE-2026-44804 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important |
| Windows Hotpatch Monitoring Service | CVE-2026-42910 | Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability | Important |
| Windows HTTP.sys | CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability | Critical |
| Windows Hyper-V | CVE-2026-47652 | Windows Hyper-V Remote Code Execution Vulnerability | Critical |
| Windows Hyper-V | CVE-2026-45607 | Windows Hyper-V Remote Code Execution Vulnerability | Critical |
| Windows Internet (wininet.dll) | CVE-2026-45592 | Windows Internet (wininet.dll) Elevation of Privilege Vulnerability | Important |
| Windows Kerberos | CVE-2026-47288 | Windows Kerberos Key Distribution Center (KDC) Remote Code Execution | Critical |
| Windows Kerberos | CVE-2026-42914 | Windows Kerberos Denial of Service Vulnerability | Important |
| Windows Kerberos | CVE-2026-42903 | Windows Kerberos Denial of Service Vulnerability | Important |
| Windows Kernel | CVE-2026-42984 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows Kernel | CVE-2026-45653 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows Kernel | CVE-2026-48583 | Windows Kernel Elevation of Privilege Vulnerability | Important |
| Windows Kernel | CVE-2025-10263 | ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] | Critical |
| Windows Kernel | CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability | Critical |
| Windows Kernel-Mode Drivers | CVE-2026-45600 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important |
| Windows Mark of the Web (MOTW) | CVE-2026-45595 | Windows Mark of the Web Security Feature Bypass Vulnerability | Important |
| Windows Media | CVE-2026-48574 | Windows Media Remote Code Execution Vulnerability | Critical |
| Windows Narrator Braille | CVE-2026-48565 | Windows Narrator Braille Elevation of Privilege Vulnerability | Important |
| Windows Network Controller (NC) Host Agent | CVE-2026-44805 | Windows Network Controller (NC) Host Agent Denial of Service Vulnerability | Important |
| Windows NT OS Kernel | CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | Important |
| Windows NT OS Kernel | CVE-2026-42916 | NT OS Kernel Elevation of Privilege Vulnerability | Important |
| Windows NTFS | CVE-2026-45636 | Windows NTFS Remote Code Execution Vulnerability | Important |
| Windows NTLM | CVE-2026-50508 | Windows NTLM Spoofing Vulnerability | Important |
| Windows Performance Monitor | CVE-2026-42981 | Windows Performance Monitor Remote Code Execution Vulnerability | Important |
| Windows Performance Monitor | CVE-2026-42974 | Windows Performance Monitor Remote Code Execution Vulnerability | Important |
| Windows Program Compatibility Assistant Service | CVE-2026-45487 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | Important |
| Windows Projected File System Filter Driver | CVE-2026-42828 | Windows Projected File System Elevation of Privilege Vulnerability | Important |
| Windows Projected File System Filter Driver | CVE-2026-42837 | Windows Projected File System Elevation of Privilege Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42991 | Windows Push Notifications Elevation of Privilege Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42977 | Windows Push Notifications Elevation of Privilege Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42979 | Windows Push Notifications Elevation of Privilege Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42978 | Windows Push Notifications Elevation of Privilege Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42973 | Windows Push Notification Information Disclosure Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42970 | Windows Push Notification Information Disclosure Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42969 | Windows Push Notification Information Disclosure Vulnerability | Important |
| Windows Push Notifications | CVE-2026-42971 | Windows Push Notification Information Disclosure Vulnerability | Important |
| Windows RDP | CVE-2026-45639 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Important |
| Windows RDP | CVE-2026-42908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Important |
| Windows SDK | CVE-2026-45593 | Windows SDK Elevation of Privilege Vulnerability | Important |
| Windows Secure Boot | CVE-2026-45588 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-45654 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48570 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48568 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48575 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48578 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48573 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Secure Boot | CVE-2026-48576 | Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Shell | CVE-2026-42907 | Windows Shell Information Disclosure Vulnerability | Important |
| Windows Shell | CVE-2026-42906 | Windows Shell Information Disclosure Vulnerability | Important |
| Windows Storage | CVE-2026-47648 | Windows Storage Elevation of Privilege Vulnerability | Important |
| Windows TCP/IP | CVE-2026-42904 | Windows TCP/IP Elevation of Privilege Vulnerability | Important |
| Windows TCP/IP | CVE-2026-42915 | Windows TCP/IP Denial of Service Vulnerability | Important |
| Windows Telephony Service | CVE-2026-42968 | Windows Telephony Server Information Disclosure Vulnerability | Important |
| Windows Telephony Service | CVE-2026-42912 | Windows Telephony Service Elevation of Privilege Vulnerability | Important |
| Windows UEFI | CVE-2026-8863 | UEFI Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows UEFI | CVE-2026-45656 | UEFI Secure Boot Security Feature Bypass Vulnerability | Important |
| Windows Universal Disk Format File System Driver (UDFS) | CVE-2026-40404 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Important |
| Windows Universal Disk Format File System Driver (UDFS) | CVE-2026-40409 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Important |
| Windows Win32K - GRFX | CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability | Critical |
| Windows Win32K - GRFX | CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability | Critical |
| Winlogon | CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability | Important |
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.