Microsoft’s Security Update in June of High-Risk Vulnerability Notice for Multiple Products

Overview

On June 9, NSFOCUS CERT detected that Microsoft released a security update patch for June, fixing 206 security issues involving widely used products such as Windows, Microsoft Office, Microsoft Exchange Server, Visual Studio Code, Azure, etc., including remote code execution vulnerabilities, High-risk vulnerability types such as information leakage vulnerabilities and privilege escalation vulnerabilities.

Of the vulnerabilities fixed in Microsoft’s monthly update this month, 38 were critical and 168 were important. Please update the patch as soon as possible for protection. For a complete list of vulnerabilities, please refer to the appendix.

Reference link: https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun

Key Vulnerabilities

Based on the product popularity and vulnerability importance, this update contains vulnerabilities with greater impact. Relevant users are requested to pay special attention:

Remote Desktop Client remote code execution vulnerability (CVE-2026-47289):

A remote code execution vulnerability exists in the remote desktop client. Since there is a stack buffer overflow when processing response data from a malicious server, an unauthenticated attacker can build a malicious remote desktop server to induce users to initiate connections and process malicious certificates when connecting to trigger the vulnerability, thereby executing arbitrary code with the user permissions of the client. CVSS score 8.8.

Official announcement link: https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-47289

Microsoft Office Remote Code Execution Vulnerability (CVE-2026-45461/CVE-2026-45472/CVE-2026-45474):

A use-after-free vulnerability exists in Microsoft Office, where an unauthenticated attacker can trick users into previewing or opening a specially crafted malicious document that causes arbitrary code execution. CVSS score 8.4.

Official announcement links:

https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-45461

https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-45472

https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-45474

Windows Kernel Remote Code Execution Vulnerability (CVE-2026-45657):

A remote code execution vulnerability exists in the Windows Kernel. Due to post-release use and stack buffer overflow issues when the kernel processes objects, an unauthenticated attacker can trigger a defect in the Windows kernel’s processing of specific TCP/IP data through a specially crafted request, thereby executing arbitrary code with system-level privileges. CVSS score 9.8

Official announcement link: https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-45657

HTTP.sys Remote Code Execution Vulnerability (CVE-2026-47291):

A remote code execution vulnerability exists in HTTP.sys, where an unauthenticated attacker can trigger memory corruption by constructing a specially crafted HTTP packet to execute arbitrary code on the target system due to integer overflow or wraparound issues in the HTTP protocol stack when processing specially crafted requests. CVSS score 9.8.

Official announcement link: https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-47291

DHCP Client Service Remote Code Execution Vulnerability (CVE-2026-44815):

A remote code execution vulnerability exists in the DHCP client service. Due to a stack buffer overflow when the DHCP client processes network data, an unauthenticated attacker can trigger memory corruption through a specially crafted DHCP response packet, thereby executing arbitrary code on the target device. CVSS score 9.8.

Official announcement link: https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-44815

Windows Graphics Component Remote Code Execution Vulnerability (CVE-2026-44803/CVE-2026-44812):

There is a remote code execution vulnerability in the Windows graphics component. Due to the integer overflow or wraparound problem when the graphics component processes specially crafted images or files, an unauthenticated attacker can trigger the vulnerability by tricking users into opening maliciously constructed files or visiting malicious websites. Users previewing panes or opening files will cause arbitrary code execution. CVSS score 7.8.

Official announcement links:

https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-44803

https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-44812

Windows Hyper-V Remote Code Execution Vulnerability (CVE-2026-45607/CVE-2026-45641):

A remote code execution vulnerability exists in Windows Hyper-V. Due to out-of-bounds read and type obfuscation issues in Hyper-V, an authenticated attacker on a VM can execute code on the host server by sending specially crafted file operation requests to the hardware resources of the virtual machine. CVSS score 8.4.

Official announcement links:

https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-45607

https://msrc.microsoft.com/update-guide/zh-cn/vulnerability/CVE-2026-45641

Scope of Impact

The following are the affected product versions of some key vulnerabilities. For the scope of products affected by other vulnerabilities, please refer to the official announcement link.

Vulnerability NumberAffected product versions
CVE-2026-47289Windows App Client for Windows Desktop
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 11 Version 26H1 for ARM64-based Systems
Windows 11 version 26H1 for x64-based Systems
Windows Server 2025
Windows 11 Version 24H2 for x64-based Systems
Windows 11 Version 24H2 for ARM64-based Systems
Windows 11 Version 23H2 for x64-based Systems
Windows 11 Version 23H2 for ARM64-based Systems
Windows 11 Version 25H2 for x64-based Systems
Windows 11 Version 25H2 for ARM64-based Systems
Windows Server 2025 (Server Core installation)
Windows 10 Version 22H2 for 32-bit Systems
Windows 10 Version 22H2 for ARM64-based Systems
Windows 10 Version 22H2 for x64-based Systems
Windows 10 Version 21H2 for x64-based Systems
Windows 10 Version 21H2 for ARM64-based Systems
Windows 10 Version 21H2 for 32-bit Systems
Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
CVE-2026-45461
CVE-2026-45472
CVE-2026-45474
Microsoft Office 2016 (64-bit edition)
Microsoft Office 2016 (32-bit edition)
Microsoft Office LTSC for Mac 2024
Microsoft Office LTSC 2024 for 64-bit editions
Microsoft Office LTSC 2024 for 32-bit editions
Microsoft Office LTSC 2021 for 32-bit editions
Microsoft Office LTSC 2021 for 64-bit editions
Microsoft Office LTSC for Mac 2021
Microsoft 365 Apps for Enterprise for 64-bit Systems
Microsoft 365 Apps for Enterprise for 32-bit Systems
Microsoft Office 2019 for 64-bit editions
Microsoft Office 2019 for 32-bit editions
Microsoft Office 365 for Mac
Microsoft Office for Android
CVE-2026-45657Windows 11 Version 23H2 for ARM64-based Systems
Windows 11 Version 23H2 for x64-based Systems
Windows 11 Version 24H2 for ARM64-based Systems
Windows 11 Version 24H2 for x64-based Systems
Windows 11 Version 25H2 for ARM64-based Systems
Windows 11 Version 25H2 for x64-based Systems
Windows 11 Version 26H1 for ARM64-based Systems
Windows 11 version 26H1 for x64-based Systems
Windows Server 2022
Windows Server 2022 (Server Core installation)
Windows Server 2025
Windows Server 2025 (Server Core installation)
CVE-2026-47291 CVE-2026-44815Windows 10 Version 1607 for 32-bit Systems
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 21H2 for 32-bit Systems
Windows 10 Version 21H2 for ARM64-based Systems
Windows 10 Version 21H2 for x64-based Systems
Windows 10 Version 22H2 for 32-bit Systems
Windows 10 Version 22H2 for ARM64-based Systems
Windows 10 Version 22H2 for x64-based Systems
Windows 11 Version 23H2 for ARM64-based Systems
Windows 11 Version 23H2 for x64-based Systems
Windows 11 Version 24H2 for ARM64-based Systems
Windows 11 Version 24H2 for x64-based Systems
Windows 11 Version 25H2 for ARM64-based Systems
Windows 11 Version 25H2 for x64-based Systems
Windows 11 Version 26H1 for ARM64-based Systems
Windows 11 version 26H1 for x64-based Systems
Windows Server 2012
Windows Server 2012 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 R2 (Server Core installation)
Windows Server 2016
Windows Server 2016 (Server Core installation)
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server 2022
Windows Server 2022 (Server Core installation)
Windows Server 2025
Windows Server 2025 (Server Core installation)
CVE-2026-44803
CVE-2026-44812
Microsoft Word for Android
Microsoft PowerPoint for Android
Microsoft Excel for Android
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2016 (Server Core installation)
Windows Server 2022 (Server Core installation)
Windows Server 2022
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 11 Version 26H1 for ARM64-based Systems
Windows 10 Version 21H2 for ARM64-based Systems
Windows 10 Version 21H2 for 32-bit Systems
Windows 11 version 26H1 for x64-based Systems
Windows Server 2025
Windows 11 Version 24H2 for x64-based Systems
Windows 11 Version 24H2 for ARM64-based Systems
Windows 11 Version 23H2 for x64-based Systems
Windows 11 Version 23H2 for ARM64-based Systems
Windows 11 Version 25H2 for x64-based Systems
Windows 11 Version 25H2 for ARM64-based Systems
Windows Server 2025 (Server Core installation)
Windows 10 Version 22H2 for 32-bit Systems
Windows 10 Version 22H2 for ARM64-based Systems
Windows 10 Version 22H2 for x64-based Systems
Windows 10 Version 21H2 for x64-based Systems
CVE-2026-45607Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for x64-based Systems
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows 11 Version 26H1 for ARM64-based Systems
Windows 11 version 26H1 for x64-based Systems
Windows Server 2025
Windows 11 Version 24H2 for x64-based Systems
Windows 11 Version 24H2 for ARM64-based Systems
Windows 11 Version 23H2 for x64-based Systems
Windows 11 Version 23H2 for ARM64-based Systems
Windows 11 Version 25H2 for x64-based Systems
Windows 11 Version 25H2 for ARM64-based Systems
Windows Server 2025 (Server Core installation)
Windows 10 Version 22H2 for x64-based Systems
Windows 10 Version 21H2 for x64-based Systems
Windows Server 2022 (Server Core installation)
Windows Server 2022
CVE-2026-45641Windows 11 version 26H1 for x64-based Systems
Windows Server 2025
Windows 11 Version 24H2 for x64-based Systems
Windows 11 Version 23H2 for x64-based Systems
Windows 11 Version 25H2 for x64-based Systems
Windows Server 2025 (Server Core installation)
Windows 10 Version 22H2 for x64-based Systems
Windows 10 Version 21H2 for x64-based Systems
Windows Server 2022 (Server Core installation)
Windows Server 2022

Mitigation

Patch update

At present, Microsoft has officially released security patches to fix the above vulnerabilities for supported product versions. It is strongly recommended that affected users install patches as soon as possible for protection. The official download link:

https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun

Note: Patch updates for Windows Update may fail due to network problems, computer environment problems, etc. After installing the patch, users should check whether the patch has been successfully updated in time.

Right-click the Windows icon, select “Settings (N)”, select “Update and Security”-“Windows Update”, view the prompt information on this page, or click “View Update History” to view the historical update status.

For updates that have not been successfully installed, you can click the update name to jump to the Microsoft official download page. It is recommended that users click the link on this page and go to the “Microsoft Update Catalog” website to download the independent program package and install it.

Appendix: Vulnerability List

Affected productsCVE No.Vulnerability TitleSeverity
Microsoft OfficeCVE-2026-45472Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2026-45474Microsoft Office Remote Code Execution VulnerabilityCritical
Copilot Chat (Microsoft Edge)CVE-2026-47644Copilot Chat (Microsoft Edge) information disclosure vulnerabilityCritical
AzureCVE-2026-47655Microsoft Graph information disclosure vulnerabilityCritical
WindowsCVE-2026-33828Windows Device Health Attestation (DHA) Privilege Escalation VulnerabilityCritical
Microsoft OfficeCVE-2026-45456Microsoft Outlook and Word remote code execution vulnerabilityCritical
Microsoft OfficeCVE-2026-45458Microsoft Outlook and Word remote code execution vulnerabilityCritical
Microsoft OfficeCVE-2026-45460Microsoft Office Information Disclosure VulnerabilityCritical
Microsoft OfficeCVE-2026-45461Microsoft Office Remote Code Execution VulnerabilityCritical
WindowsCVE-2026-45607Windows Hyper-V remote code execution vulnerabilityCritical
WindowsCVE-2026-45641Windows Hyper-V remote code execution vulnerabilityCritical
WindowsCVE-2026-45648Windows Active Directory Domain Services Remote Code Execution VulnerabilityCritical
WindowsCVE-2026-45657Windows Kernel Remote Code Execution VulnerabilityCritical
WindowsCVE-2026-47288Windows Kerberos Key Distribution Center (KDC) Remote Code ExecutionCritical
WindowsCVE-2026-47289Remote Desktop Client remote code execution vulnerabilityCritical
WindowsCVE-2026-47291HTTP.sys Remote Code Execution VulnerabilityCritical
AzureCVE-2026-32193Azure Kubernetes Service (AKS) Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2026-47635Microsoft Outlook and Word remote code execution vulnerabilityCritical
WindowsCVE-2026-47652Windows Hyper-V remote code execution vulnerabilityCritical
WindowsCVE-2026-47654Remote Desktop Client remote code execution vulnerabilityCritical
WindowsCVE-2026-48563Remote Desktop Client remote code execution vulnerabilityCritical
OtherCVE-2026-26142Nuance PowerScribe remote code execution vulnerabilityCritical
Microsoft OfficeCVE-2026-45463Microsoft Office Remote Code Execution VulnerabilityCritical
OtherCVE-2026-45476Microsoft Azure Network Adapter privilege escalation vulnerabilityCritical
WindowsCVE-2026-48574Windows Media Remote Code Execution VulnerabilityCritical
WindowsCVE-2026-44810Microsoft Cryptographic Services privilege escalation vulnerabilityCritical
WindowsCVE-2026-42992Remote Desktop Client remote code execution vulnerabilityCritical
WindowsCVE-2026-44799Remote Desktop Client remote code execution vulnerabilityCritical
WindowsCVE-2026-44815DHCP Client Service Remote Code Execution VulnerabilityCritical
WindowsCVE-2026-44801Remote Desktop Client remote code execution vulnerabilityCritical
WindowsCVE-2026-42985Remote Desktop Client remote code execution vulnerabilityCritical
WindowsCVE-2026-42987Windows Deployment Services (WDS) Remote Code ExecutionCritical
Microsoft Office,Apps,WindowsCVE-2026-44803Windows Graphics Component Remote Code Execution VulnerabilityCritical
Microsoft Office,Apps,WindowsCVE-2026-44812Windows Graphics Component Remote Code Execution VulnerabilityCritical
AppsCVE-2026-45497Microsoft M365 Copilot Remote Code Execution VulnerabilityCritical
AppsCVE-2026-42824M365 Copilot Information Disclosure VulnerabilityCritical
AzureCVE-2026-48567Azure HorizonDB privilege escalation vulnerabilityCritical
Microsoft Exchange OnlineCVE-2026-48579Microsoft Exchange Online information disclosure vulnerabilityCritical
WindowsCVE-2026-41108Windows DNS Client Privilege Escalation VulnerabilityImportant
Microsoft OfficeCVE-2026-45467Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-45468Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-45469Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-45475Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-45471Microsoft Word remote code execution vulnerabilityImportant
Microsoft OfficeCVE-2026-45479Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-45486Microsoft Word remote code execution vulnerabilityImportant
Microsoft OfficeCVE-2026-45485Microsoft Office Information Disclosure VulnerabilityImportant
Microsoft OfficeCVE-2026-45483Microsoft Office Project Server spoofing vulnerabilityImportant
WindowsCVE-2026-40409Windows Universal Disk Format File System Driver (UDFS) Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-40404Windows Universal Disk Format File System Driver (UDFS) Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-34335Windows Ancillary Function Driver for WinSock Privilege Escalation VulnerabilityImportant
AppsCVE-2026-42902Microsoft PowerToys Privilege Escalation VulnerabilityImportant
Microsoft OfficeCVE-2026-44817Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-44818Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-44819Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-44820Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-44821Microsoft Office Information Disclosure VulnerabilityImportant
Microsoft OfficeCVE-2026-44823Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-44824Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-45453Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-45466Microsoft Word Information Disclosure VulnerabilityImportant
WindowsCVE-2026-45487Windows Program Compatibility Assistant Service privilege escalation vulnerabilityImportant
.NET 10.0 installed on Windows,
.NET 9.0 installed on Windows,
.NET 8.0 installed on Windows
CVE-2026-45490.NET SDK Privilege Escalation VulnerabilityImportant
.NET,.NET 10.0 installed on Linux,
.NET 9.0 installed on Linux,
.NET 8.0 installed on Mac OS,
.NET 8.0 installed on Linux,
.NET 10.0 installed on Windows,
.NET 9.0 installed on Mac OS,
.NET 8.0 installed on Windows,
.NET 10.0 installed on Mac OS,
.NET 9.0 installed on Windows
CVE-2026-45491.NET Tampering VulnerabilityImportant
WindowsCVE-2026-45605Windows Bluetooth Service Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45639Windows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityImportant
WindowsCVE-2026-45640Windows Bluetooth Port Driver privilege escalation vulnerabilityImportant
WindowsCVE-2026-45606Microsoft UxTheme Library (uxtheme.dll) Denial of Service VulnerabilityImportant
WindowsCVE-2026-45634Windows DHCP Client Information Disclosure VulnerabilityImportant
WindowsCVE-2026-45642Microsoft Azure Attestation service and Device Health Attestation Service spoofing vulnerabilityImportant
Microsoft OfficeCVE-2026-45643Microsoft Word remote code execution vulnerabilityImportant
Microsoft OfficeCVE-2026-45645Microsoft Office Remote Code Execution VulnerabilityImportant
Apps,Microsoft OfficeCVE-2026-45649Office for Android spoofing vulnerabilityImportant
AppsCVE-2026-45650Microsoft Bing Search Spoofing VulnerabilityImportant
WindowsCVE-2026-45655Windows BitLocker security feature bypass vulnerabilityImportant
WindowsCVE-2026-45656UEFI Secure Boot security feature bypass vulnerabilityImportant
Visual Studio CodeCVE-2026-47287Visual Studio Code Tampering VulnerabilityImportant
Visual Studio Code – MSSQL ExtensionCVE-2026-47292Visual Studio Code MSSQL Extension Remote Code Execution VulnerabilityImportant
WindowsCVE-2026-41092Microsoft Kinect privilege escalation vulnerabilityImportant
Microsoft OfficeCVE-2026-47298Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
AzureCVE-2026-41098Azure Stack Edge Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-47636Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-47637Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-47638Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-47639Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-47641Microsoft SharePoint Server Spoofing VulnerabilityImportant
WindowsCVE-2026-45588Secure Boot security feature bypass vulnerabilityImportant
WindowsCVE-2026-47648Windows Storage Permission Escalation VulnerabilityImportant
WindowsCVE-2026-47653Remote Desktop Client remote code execution vulnerabilityImportant
WindowsCVE-2026-48566Windows DWM Core Library Information Disclosure  VulnerabilityImportant
WindowsCVE-2026-48568Secure Boot security feature bypass vulnerabilityImportant
WindowsCVE-2026-48570Secure Boot security feature bypass vulnerabilityImportant
WindowsCVE-2026-48573Secure Boot security feature bypass vulnerabilityImportant
WindowsCVE-2026-48575Secure Boot security feature bypass vulnerabilityImportant
WindowsCVE-2026-48576Secure Boot security feature bypass vulnerabilityImportant
WindowsCVE-2026-48578Secure Boot security feature bypass vulnerabilityImportant
WindowsCVE-2026-48583Windows Kernel privilege escalation vulnerabilityImportant
AppsCVE-2026-49161Microsoft PC Manager security feature bypass vulnerabilityImportant
WindowsCVE-2026-50508Windows NTLM spoofing vulnerabilityImportant
Microsoft OfficeCVE-2026-33113Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft DynamicsCVE-2026-40371Microsoft Dynamics 365 (on-premises) Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-42828Windows Projected File System Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-42829Windows Administrator Protection Secure feature bypass vulnerabilityImportant
Microsoft OfficeCVE-2026-42835Microsoft Teams for Android Information Disclosure VulnerabilityImportant
Visual Studio CodeCVE-2026-40376Visual Studio Code privilege escalation vulnerabilityImportant
Microsoft OfficeCVE-2026-44822Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft OfficeCVE-2026-45454Microsoft SharePoint Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-45455Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft OfficeCVE-2026-45457Microsoft Word remote code execution vulnerabilityImportant
Microsoft OfficeCVE-2026-45459Microsoft Excel security feature bypass vulnerabilityImportant
Microsoft OfficeCVE-2026-45462Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-45464Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-45465Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft Visual Studio Code CoPilot Chat ExtensionCVE-2026-45482Microsoft Visual Studio Code CoPilot Chat Extension security feature bypass vulnerabilityImportant
WindowsCVE-2026-45586Windows Collaborative Translation Framework (CTFMON) Privilege Escalation VulnerabilityImportant
.NET 10.0 installed on Linux,
.NET 9.0 installed on Linux,
.NET 8.0 installed on Mac OS,
.NET 8.0 installed on Linux,
.NET 10.0 installed on Windows,
.NET 9.0 installed on Mac OS,Microsoft Visual Studio,
.NET 8.0 installed on Windows,
.NET 10.0 installed on Mac OS,
.NET 9.0 installed on Windows,ASP.NET Core
CVE-2026-45591ASP.NET Core denial of service vulnerabilityImportant
WindowsCVE-2026-45592Windows Internet (wininet.dll) Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45593Windows SDK Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45594Windows Application Identity (AppID) Information Disclosure VulnerabilityImportant
WindowsCVE-2026-45604Windows Managed Installer Information Disclosure VulnerabilityImportant
WindowsCVE-2026-45595Windows Mark of the Web security feature bypass vulnerabilityImportant
WindowsCVE-2026-45597Windows UI Automation Manager (uiamanager.dll) Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45599Windows UPnP Device Host Remote Code Execution VulnerabilityImportant
WindowsCVE-2026-45601Windows Ancillary Function Driver for WinSock Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45598Windows Ancillary Function Driver for WinSock Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45636Windows NTFS Remote Code Execution VulnerabilityImportant
WindowsCVE-2026-45596Windows Ancillary Function Driver for WinSock Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45600Windows Kernel-Mode Driver privilege escalation vulnerabilityImportant
WindowsCVE-2026-45602Windows Dynamic Host Configuration Protocol (DHCP) Tampering VulnerabilityImportant
WindowsCVE-2026-45635Windows UPnP Device Host Remote Code Execution VulnerabilityImportant
WindowsCVE-2026-45638Windows Ancillary Function Driver for WinSock Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45603Windows Ancillary Function Driver for WinSock Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45637Microsoft DWM Core Library Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45608Windows DHCP Client Information Disclosure VulnerabilityImportant
Microsoft Live Share Canvas SDKCVE-2026-45644Microsoft Live Share Canvas SDK Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45653Windows Kernel privilege escalation vulnerabilityImportant
WindowsCVE-2026-45654Secure Boot security feature bypass vulnerabilityImportant
System CenterCVE-2026-45647Microsoft Defender for Endpoint for Mac Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-45658Windows BitLocker security feature bypass vulnerabilityImportant
Visual Studio CodeCVE-2026-47281Visual Studio Code privilege escalation vulnerabilityImportant
Visual Studio CodeCVE-2026-47284Visual Studio Code Information Disclosure VulnerabilityImportant
Microsoft OfficeCVE-2026-47293Microsoft Office Click-To-Run privilege escalation vulnerabilityImportant
WindowsCVE-2026-42910Windows Hotpatch Monitoring Service privilege escalation vulnerabilityImportant
Microsoft OfficeCVE-2026-47634Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-47640Microsoft SharePoint Server Spoofing VulnerabilityImportant
AzureCVE-2026-47643Azure Stack Edge Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2026-45481Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-45484Microsoft SharePoint privilege escalation vulnerabilityImportant
WindowsCVE-2026-47656Windows Boot Manager security feature bypass vulnerabilityImportant
Microsoft OfficeCVE-2026-48560Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft OfficeCVE-2026-48562Microsoft SharePoint Server Spoofing VulnerabilityImportant
WindowsCVE-2026-48565Windows Narrator Braille privilege escalation vulnerabilityImportant
Visual Studio CodeCVE-2026-48569Visual Studio Code security feature bypass vulnerabilityImportant
WindowsCVE-2026-49160HTTP.sys denial of service vulnerabilityImportant
WindowsCVE-2026-50507Windows BitLocker security feature bypass vulnerabilityImportant
WindowsCVE-2026-42836Windows Function Discovery Service (fdwsd.dll) Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-42837Windows Projected File System Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-42903Windows Kerberos denial of service vulnerabilityImportant
WindowsCVE-2026-42904Windows TCP/IP privilege escalation vulnerabilityImportant
WindowsCVE-2026-42905Windows DWM Core Library privilege escalation vulnerabilityImportant
WindowsCVE-2026-42906Windows Shell Information Disclosure VulnerabilityImportant
WindowsCVE-2026-42907Windows Shell Information Disclosure VulnerabilityImportant
WindowsCVE-2026-42908Windows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityImportant
WindowsCVE-2026-42980NT OS Kernel Permission Escalation VulnerabilityImportant
WindowsCVE-2026-42909Remote Desktop Client remote code execution vulnerabilityImportant
WindowsCVE-2026-42916NT OS Kernel Permission Escalation VulnerabilityImportant
WindowsCVE-2026-42911Windows Ancillary Function Driver for WinSock Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-42913Remote Desktop Client remote code execution vulnerabilityImportant
WindowsCVE-2026-42912Windows Telephony Service privilege escalation vulnerabilityImportant
WindowsCVE-2026-42914Windows Kerberos denial of service vulnerabilityImportant
WindowsCVE-2026-42915Windows TCP/IP denial of service vulnerabilityImportant
WindowsCVE-2026-42968Windows Telephony Server Information Disclosure VulnerabilityImportant
WindowsCVE-2026-42972Windows Hyper-V Information Disclosure VulnerabilityImportant
WindowsCVE-2026-42969Windows Push Notification Information Disclosure VulnerabilityImportant
WindowsCVE-2026-42971Windows Push Notification Information Disclosure VulnerabilityImportant
WindowsCVE-2026-42970Windows Push Notification Information Disclosure VulnerabilityImportant
WindowsCVE-2026-42973Windows Push Notification Information Disclosure VulnerabilityImportant
WindowsCVE-2026-42984Windows Kernel privilege escalation vulnerabilityImportant
WindowsCVE-2026-42981Windows Performance Monitor Remote Code Execution VulnerabilityImportant
WindowsCVE-2026-42974Windows Performance Monitor Remote Code Execution VulnerabilityImportant
WindowsCVE-2026-42986Microsoft Graphics Component privilege escalation vulnerabilityImportant
WindowsCVE-2026-42978Windows Push Notifications privilege escalation vulnerabilityImportant
WindowsCVE-2026-42977Windows Push Notifications privilege escalation vulnerabilityImportant
WindowsCVE-2026-42979Windows Push Notifications privilege escalation vulnerabilityImportant
WindowsCVE-2026-42991Windows Push Notifications privilege escalation vulnerabilityImportant
WindowsCVE-2026-42989Winlogon Privilege Escalation VulnerabilityImportant
WindowsCVE-2026-44809Windows Common Log File System Driver Escalation VulnerabilityImportant
WindowsCVE-2026-44805Windows Network Controller (NC) Host Agent Denial of ServiceImportant
WindowsCVE-2026-44811Windows DWM Core Library privilege escalation vulnerabilityImportant
WindowsCVE-2026-44808Windows DWM Core Library privilege escalation vulnerabilityImportant
WindowsCVE-2026-44807Windows DWM Core Library privilege escalation vulnerabilityImportant
WindowsCVE-2026-42983Windows DWM Core Library privilege escalation vulnerabilityImportant
WindowsCVE-2026-44802Windows DWM Core Library privilege escalation vulnerabilityImportant
WindowsCVE-2026-44814Windows DWM Core Library Information Disclosure  VulnerabilityImportant
WindowsCVE-2026-42993Remote Desktop Client remote code execution vulnerabilityImportant
WindowsCVE-2026-44813Windows DWM Core Library privilege escalation vulnerabilityImportant
WindowsCVE-2026-44804Windows DWM Core Library privilege escalation vulnerabilityImportant
AppsCVE-2026-50512Microsoft PC Manager privilege escalation vulnerabilityImportant
AppsCVE-2026-50511Microsoft PC Manager privilege escalation vulnerabilityImportant
Microsoft Exchange Server, Microsoft Exchange Server Subscription Edition RTMCVE-2026-47631Microsoft Exchange Server spoofing vulnerabilityImportant
Microsoft Exchange Server, Microsoft Exchange Server Subscription Edition RTMCVE-2026-45500Microsoft Exchange Server spoofing vulnerabilityImportant
Microsoft Exchange Server, Microsoft Exchange Server Subscription Edition RTMCVE-2026-45501Microsoft Exchange Server spoofing vulnerabilityImportant
Microsoft Exchange Server, Microsoft Exchange Server Subscription Edition RTMCVE-2026-45502Microsoft Exchange Server Information Disclosure VulnerabilityImportant
Microsoft Exchange Server, Microsoft Exchange Server Subscription Edition RTMCVE-2026-45503Microsoft Exchange Server Information Disclosure VulnerabilityImportant
Microsoft Exchange Server, Microsoft Exchange Server Subscription Edition RTMCVE-2026-45504Microsoft Exchange Server privilege escalation vulnerabilityImportant
Microsoft Exchange Server, Microsoft Exchange Server Subscription Edition RTMCVE-2026-45583Microsoft Exchange Server Remote Code Execution VulnerabilityImportant

About NSFOCUS

NSFOCUS, a pioneering leader in cybersecurity, is dedicated to safeguarding telecommunications, Internet service providers, hosting providers, and enterprises from sophisticated cyberattacks.

Founded in 2000, NSFOCUS operates globally with over 3000 employees at two headquarters in Beijing, China, and Santa Clara, CA, USA, and over 50 offices worldwide. It has a proven track record of protecting over 25% of the Fortune Global 500 companies, including four of the five largest banks and six of the world’s top ten telecommunications companies.

Leveraging technical prowess and innovation, NSFOCUS delivers a comprehensive suite of security solutions, including the Intelligent Security Operations Platform (ISOP) for modern SOC, DDoS Protection, Continuous Threat Exposure Management (CTEM) Service and Web Application and API Protection (WAAP). All the solutions and services are augmented by the Security Large Language Model (SecLLM), ML, patented algorithms and other cutting-edge research achievements developed by NSFOCUS.

Deixe um comentário

O seu endereço de e-mail não será publicado. Campos obrigatórios são marcados com *