{"id":8445,"date":"2026-06-10T14:53:28","date_gmt":"2026-06-10T14:53:28","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8445"},"modified":"2026-06-10T14:53:28","modified_gmt":"2026-06-10T14:53:28","slug":"june-patch-tuesday-marks-a-new-normal-with-over-200-cves-32-rated-critical","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8445","title":{"rendered":"June Patch Tuesday marks a \u2018new normal\u2019 with over 200 CVEs, 32 rated \u2018critical\u2019"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p>June\u2019s Patch Tuesday security updates have arrived, with SAP fixing four critical vulnerabilities and Microsoft addressing over 200 CVEs. Microsoft\u2019s to-do list includes fixes for three zero days, 32 patches rated as \u2018critical\u2019, and a batch of other high-risk vulnerabilities that need urgent assessment. There\u2019s also one older flaw under exploit, and some patches affecting enterprise products for which Microsoft says exploitation is likely. Adobe, too, fixed critical vulnerabilities in enterprise software.<\/p>\n<h2 class=\"wp-block-heading\">Vulnerability surge<\/h2>\n<p>It\u2019s a record haul for Patch Tuesday CVEs \u2014 and that\u2019s not counting the other exploited vulnerabilities Microsoft has patched out-of-band since its May update.<\/p>\n<p>Microsoft recently told customers it expects the number of vulnerabilities in monthly updates to continue rising, influenced by the growing use of AI tools. As a <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/blog\/2026\/05\/a-note-on-patch-tuesday\" target=\"_blank\" rel=\"noopener\">May post<\/a> by the Microsoft Security Response Center put it: \u201cAs larger releases settle in as a norm, the way we deliver and decide on updates remains consistent. Patch Tuesday continues as our predictable rhythm for on-premises software,\u201d Going forward, customers should brace themselves for more out-of-band updates, it added.<\/p>\n<p>According to <a href=\"https:\/\/www.linkedin.com\/in\/nirwan-dogra-11a24047\/\" target=\"_blank\" rel=\"noopener\">Nirwan Dogra<\/a>, a Senior Software Engineer at Microsoft Security, May and June 2026 represent a new norm that will challenge traditional, slower test-and-deploy patching.<\/p>\n<p>\u201cThe 200+ CVE count isn\u2019t an anomaly. It\u2019s the new baseline. AI-assisted vulnerability discovery (fuzzing, static analysis, variant hunting) is compressing the timeline between \u2018a bug exists\u2019 and \u2018bug is found\u2019 dramatically,\u201d he said via email.<\/p>\n<p>Ominously, according to Dogra, AI tools used were also resulting in more flaws being uncovered in components previous seen as too complex for manual audit such as hypervisor code and Kerberos. He recommended that organizations move towards risk-based vulnerability prioritization, automated patching pipelines, and a focus on the flaws that were likely to be exploited.<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/dustincchilds\/\" target=\"_blank\" rel=\"noopener\">Dustin Childs<\/a>, Head of Threat Awareness for TrendAI\u2019s Zero Day Initiative (ZDI) agreed: \u201cWe are heading into a high-stakes summer for cybersecurity. June\u2019s record-shattering drop of 210 Microsoft vulnerabilities is a stark warning that AI is supercharging flaw discovery at an uncontrollable scale,\u201d he said.<\/p>\n<h2 class=\"wp-block-heading\">Microsoft\u2019s high-priority fixes<\/h2>\n<p>Three vulnerabilities are rated as zero days because they have been publicly disclosed. Two are connected to adversarial disclosures affecting Windows by the researcher <a href=\"https:\/\/www.csoonline.com\/article\/4178869\/microsoft-and-security-researchers-dueling-posts-about-cybersecurity-disclosures-get-nasty.html\">Nightmare Eclipse<\/a> which have attracted a lot of attention: <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-45586\" target=\"_blank\" rel=\"noopener\">CVE-2026-45586<\/a> (CTFMON) and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-50507\" target=\"_blank\" rel=\"noopener\">CVE-2026-50507<\/a> (BitLocker bypass). The third is <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-49160\" target=\"_blank\" rel=\"noopener\">CVE-2026-49160<\/a>, a CVSS 7.8-rated denial of service zero day vulnerability in the Windows HTTP Protocol Stack used by various Windows services.<\/p>\n<p>Security teams should also note the patch for <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-42897\" target=\"_blank\" rel=\"noopener\">CVE-2026-42897<\/a>, an Exchange Server flaw under active exploitation <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/exchange\/released-june-2026-exchange-server-security-updates\/4524491\" target=\"_blank\" rel=\"noopener\">originally disclosed<\/a> in May. This was originally addressed using workarounds but has now been patched.<\/p>\n<p>The list of 15 vulnerabilities where exploitation is said to be \u201cmore likely\u201d is headlined by <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-47291\" target=\"_blank\" rel=\"noopener\">CVE-2026-47291<\/a>, a dangerous CVSS 9.8-rated kernel-level RCE flaw in http.sys that attackers could use to target multiple important enterprise applications, for IIS, WinRM, or Windows Admin Center.<\/p>\n<p>Also worth paying attention to are a series of \u2018high\u2019 rated Hyper-V VM escape flaws, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-47652\" target=\"_blank\" rel=\"noopener\">CVE-2026-47652<\/a>, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-45641\" target=\"_blank\" rel=\"noopener\">CVE-2026-45641<\/a>, and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-45607\" target=\"_blank\" rel=\"noopener\">CVE-2026-45607<\/a>. Anyone running on-premises networks will also be interested in <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-47288\" target=\"_blank\" rel=\"noopener\">CVE-2026-47288<\/a>, an RCE affecting the Active Directory Kerberos core, and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-45648\" target=\"_blank\" rel=\"noopener\">CVE-2026-45648<\/a>, a CVSS 8.8 affecting Active Directory Domain Services (AD DS).<\/p>\n<h2 class=\"wp-block-heading\">Four critical SAP vulnerabilities<\/h2>\n<p>SAP\u2019s Security Patch Day haul <a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/june-2026.html\" target=\"_blank\" rel=\"noopener\">for June<\/a> comprises 15 patches across a range of core enterprise products including, prominently, NetWeaver, Commerce Cloud, SAP S\/4HANA, and the Business Objects Business Intelligence Platform.<\/p>\n<p>Four of these are rated \u2018critical\u2019, the most eye-catching of which is <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-27671\" target=\"_blank\" rel=\"noopener\">CVE-2026-27671<\/a>, a CVSS 9.8 memory corruption vulnerability in Application Server ABAP and ABAP Platform. The problem here, said <a href=\"https:\/\/pathlock.com\/author\/jonathan-stross\/\" target=\"_blank\" rel=\"noopener\">Jonathan Stross<\/a>, SAP security analyst at security company Pathlock, is that it \u201crequires no authentication and can affect confidentiality, integrity, and availability at the same time. A successful exploit can undermine the trustworthiness of the entire ABAP instance and everything connected to it.\u201d<\/p>\n<p>\u201cThis is one of the most serious notes in the batch because the attack requires no authentication and can affect confidentiality, integrity, and availability at the same time. A successful exploit can undermine the trustworthiness of the entire ABAP instance and everything connected to it.<\/p>\n<p>Not far behind it is <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44748\" target=\"_blank\" rel=\"noopener\">CVE-2026-44748<\/a>, a CVSS 9.9 XML Signature Wrapping in SAML Authentication vulnerability in the SAP NetWeaver Application Server ABAP and ABAP Platform. This allows authenticated attacker with low-level user privileges to capture a signed SAML message and modify and submit an XML payload with a forged identity data.<\/p>\n<p>The final critical-rated flaws are <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-22732\" target=\"_blank\" rel=\"noopener\">CVE-2026-22732<\/a>, a CVSS 9.1 Spring Security weakness within SAP Commerce Cloud and SAP Data Hub, and <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40128\" target=\"_blank\" rel=\"noopener\">CVE-2026-40128<\/a>, a CVSS 9.0 directory traversal vulnerability in the Application Server Java (Web Container).<\/p>\n<p>This month\u2019s update also patches two vulnerabilities marked \u2018high\u2019, the CVSS 7.4 <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-29145\" target=\"_blank\" rel=\"noopener\">CVE-2026-29145<\/a>, addressing multiple weaknesses in Apache Tomcat within SAP Commerce Cloud, and <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44751\" target=\"_blank\" rel=\"noopener\">CVE-2026-44751<\/a>, a missing authorization check affecting Application Server ABAP of SAP NetWeaver and ABAP Platform.<\/p>\n<h2 class=\"wp-block-heading\">Adobe patches enterprise vulnerabilities<\/h2>\n<p>Adobe\u2019s June update addresses 123 vulnerabilities across Reader, ColdFusion, Experience Manager Forms, InDesign, InCopy, Substance 3D Sampler, Content Credentials SDK, Dreamweaver, Format Plugins, and Adobe Campaign Classic.<\/p>\n<p>Of note are the two CVSS 10-rated CVEs (<a href=\"https:\/\/helpx.adobe.com\/security\/products\/campaign\/apsb26-66.html\" target=\"_blank\" rel=\"noopener\">APSB26-66<\/a>) in the Adobe Campaign Classic enterprise marketing platform, the seven mostly \u2018critical\u2019 or \u2018high\u2019-rated CVEs affecting ColdFusion (<a href=\"https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb26-64.html\" target=\"_blank\" rel=\"noopener\">APSB26-64<\/a>), and a total of 20 CVEs affecting Reader (<a href=\"https:\/\/helpx.adobe.com\/security\/products\/acrobat\/apsb26-63.html\" target=\"_blank\" rel=\"noopener\">APSB26-63<\/a>). It\u2019s also a busy month for InDesign, which features 12 vulnerabilities (<a href=\"https:\/\/helpx.adobe.com\/security\/products\/indesign\/apsb26-58.html\" target=\"_blank\" rel=\"noopener\">APSB26-58<\/a>), and Experience Manager which features three (<a href=\"https:\/\/helpx.adobe.com\/security\/products\/aem-forms\/apsb26-57.html\">AP<\/a><a href=\"https:\/\/helpx.adobe.com\/security\/products\/aem-forms\/apsb26-57.html\" target=\"_blank\" rel=\"noopener\">S<\/a><a href=\"https:\/\/helpx.adobe.com\/security\/products\/aem-forms\/apsb26-57.html\">B26-57<\/a>).<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>June\u2019s Patch Tuesday security updates have arrived, with SAP fixing four critical vulnerabilities and Microsoft addressing over 200 CVEs. Microsoft\u2019s to-do list includes fixes for three zero days, 32 patches rated as \u2018critical\u2019, and a batch of other high-risk vulnerabilities that need urgent assessment. There\u2019s also one older flaw under exploit, and some patches affecting [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8446,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8445","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8445"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8445"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8445\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8446"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8445"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8445"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8445"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}