Microsoft June 2026 Patch Tuesday record vulnerabilities
Back to Blog
Vulnerability Research

Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Fixed

PublishedJune 10, 2026
Read time8 min read
Share
Originally reported viaMicrosoft Security Response Center — June 2026 Security Updates · SANS Internet Storm Centre

Microsoft's June 2026 Patch Tuesday — released 10 June 2026 — addresses 206 vulnerabilities across Windows, Office, Azure, Exchange, Hyper-V, and the .NET runtime. This is the largest single Patch Tuesday release in Microsoft's history. Of the 206 CVEs, 18 are rated Critical, 3 are confirmed as exploited in the wild, and 11 have public proof-of-concept exploit code available.

The three actively exploited zero-days

CVE-2026-30190 (Windows MSHTML Platform Remote Code Execution, CVSS 8.8) is being actively exploited via crafted Office documents. CVE-2026-31166 (Windows Print Spooler Elevation of Privilege, CVSS 7.8) continues a long line of Print Spooler vulnerabilities and is being abused post-compromise for SYSTEM-level access. CVE-2026-32034 (Microsoft Exchange Server Authentication Bypass, CVSS 9.1) allows an attacker on the local network segment to authenticate as any Exchange user without credentials.

Source: Microsoft Security Response Center — 10 June 2026
MSRC confirmed CVE-2026-30190 is being exploited in phishing campaigns delivering malicious Office attachments. No user interaction beyond opening the document is required. Microsoft rates exploitation as 'Exploitation Detected' with 'More Likely' future exploitation for an additional 14 CVEs in this release.

Priority triage for enterprise patch teams

Prioritisation should follow three tiers. Tier 1 (patch within 24 hours): CVE-2026-30190 (MSHTML RCE), CVE-2026-32034 (Exchange auth bypass), and CVE-2026-31166 (Print Spooler LPE). Tier 2 (patch within 72 hours): all 18 Critical-rated CVEs affecting internet-facing services. Tier 3 (standard 30-day cycle): remaining Important-rated CVEs on internal assets with compensating controls.

Source: SANS Internet Storm Centre — June 2026 Patch Tuesday Analysis
SANS ISC noted that CVE-2026-32034 (Exchange auth bypass) affects on-premises Exchange 2019 and Exchange 2016. Organisations still running on-premises Exchange should treat this as an emergency patch — Exchange is consistently the highest-value initial access target for both ransomware affiliates and nation-state actors.
  • Deploy patches for CVE-2026-30190, CVE-2026-32034, and CVE-2026-31166 within 24 hours on all internet-exposed and critical assets.
  • Disable the Windows Print Spooler service on all non-print servers as a standing compensating control.
  • Review Exchange server IIS logs for anomalous authentication patterns in the 72 hours preceding patch deployment.
  • Validate that Microsoft 365 tenants have applied the corresponding Exchange Online service updates.
  • Run a vulnerability scan post-patch to confirm successful deployment — failed patching is a primary cause of repeat exploitation.

Stay ahead of the threat curve

Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.