Microsoft fixes 206 vulnerabilities in its June update

Microsoft's June 2026 Patch Tuesday covered 206 vulnerabilities disclosed across Microsoft products, including 32 rated critical. Cisco Talos highlights four critical vulnerabilities that Microsoft considers more likely to be exploited: a Remote Desktop Client heap-based buffer overflow (CVE-2026-42985), a Windows HTTP Protocol Stack integer overflow that can be triggered with specially crafted packets (CVE-2026-47291), and two Windows Graphics component vulnerabilities that could allow local code execution (CVE-2026-44803 and CVE-2026-44812).

What this means for your organisation

The volume is large, but the four highlighted flaws should set the order of work. The HTTP Protocol Stack issue lands hardest, because it can be triggered across the network against exposed servers. The Remote Desktop Client flaw works the other way: a user connecting to a server the attacker controls. For a manager, the point is that 206 vulnerabilities do not mean 206 emergencies, but that a handful must go out this week.

Berigo recommends

  • Prioritise the four highlighted vulnerabilities ahead of the rest of the June release.
  • Patch Windows servers exposing HTTP-based services first.
  • Make sure staff using Remote Desktop get the client updated, not only the servers.
  • Verify afterwards what share of machines actually received the update, and chase the remainder.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch