Skip to content
Noroxi

Patch Tuesday

June 2026

On the second Tuesday of each month Microsoft, Adobe, SAP, Siemens and Schneider Electric publish in bulk; Oracle on the third Tuesday of January, April, July and October. Records published that day, from our own database, sorted by action score: KEV and mature exploits first.

How it is computed: CNA stamp + publication date (two-day window, UTC). No claim of a one-to-one match with the vendor bulletin; out-of-band updates land on other days.

330 records · 0 KEV

Affecting your stack

This month's records that match the products and versions in your stack.

Sign in to see the ones matching your stack; records and notifications are free. →

Microsoft · June 9

200 · 0 KEV · 8 critical
  • Nuance PowerScribe Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    microsoft · nuance powerscribe 360Jun 9, 2026

  • DHCP Client Service Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    microsoft · windows 10 1607Jun 9, 2026

  • Windows Kernel Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    microsoft · windows 11 23h2Jun 9, 2026

  • HTTP.sys Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    microsoft · windows 10 1607Jun 9, 2026

  • Azure Stack Edge Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    microsoft · azure stack edgeJun 9, 2026

  • Windows TCP/IP Elevation of Privilege Vulnerability

    CriticalCVSS 9.6No exploitEPSS 1%

    microsoft · windows 10 21h2Jun 9, 2026

  • Visual Studio Code Elevation of Privilege Vulnerability

    CriticalCVSS 9.6No exploitEPSS 1%

    microsoft · visual studio codeJun 9, 2026

  • Microsoft SharePoint Elevation of Privilege Vulnerability

    HighCVSS 8.8No exploitEPSS 2%

    microsoft · sharepoint serverJun 9, 2026

  • Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability

    CriticalCVSS 9.1No exploitEPSS 0%

    microsoft · windows 10 1607Jun 9, 2026

  • Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    microsoft · azure kubernetes serviceJun 9, 2026

  • Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · dynamics 365Jun 9, 2026

  • Remote Desktop Client Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · remote desktop clientJun 9, 2026

+188 moreAll records of the vendor

Adobe · June 9

123 · 0 KEV · 4 critical
  • Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)

    CriticalCVSS 10.0No exploitEPSS 1%

    adobe · campaignJun 9, 2026

  • Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)

    CriticalCVSS 10.0No exploitEPSS 1%

    adobe · campaignJun 9, 2026

  • ColdFusion | Improper Input Validation (CWE-20)

    CriticalCVSS 9.6No exploitEPSS 0%

    adobe · coldfusionJun 9, 2026

  • Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)

    CriticalCVSS 9.3No exploitEPSS 1%

    adobe · experience managerJun 9, 2026

  • ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

    HighCVSS 8.8No exploitEPSS 1%

    adobe · coldfusionJun 9, 2026

  • Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)

    HighCVSS 8.6No exploitEPSS 0%

    adobe · dreamweaverJun 9, 2026

  • Dreamweaver Desktop | Improper Access Control (CWE-284)

    HighCVSS 8.6No exploitEPSS 0%

    adobe · dreamweaverJun 9, 2026

  • ColdFusion | Incorrect Authorization (CWE-863)

    HighCVSS 8.4No exploitEPSS 0%

    adobe · coldfusionJun 9, 2026

  • ColdFusion | Improper Input Validation (CWE-20)

    HighCVSS 8.4No exploitEPSS 0%

    adobe · coldfusionJun 9, 2026

  • Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CWE-79)

    HighCVSS 8.0No exploitEPSS 1%

    adobe · experience managerJun 9, 2026

  • ColdFusion | Improper Input Validation (CWE-20)

    HighCVSS 8.1No exploitEPSS 1%

    adobe · coldfusionJun 9, 2026

  • InDesign Desktop | Stack-based Buffer Overflow (CWE-121)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · indesignJun 9, 2026

+111 moreAll records of the vendor

SAP · June 9

0 · 0 KEV · 0 critical

No records in this window.

Siemens · June 9

6 · 0 KEV · 0 critical
  • A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).

    HighCVSS 8.7No exploitEPSS 1%

    siemens · sinec insJun 9, 2026

  • A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).

    HighCVSS 8.7No exploitEPSS 0%

    siemens · sinec insJun 9, 2026

  • A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versio

    HighCVSS 8.2No exploitEPSS 0%

    siemens · simatic wincc unified pc runtimeJun 9, 2026

  • A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (C

    MediumCVSS 6.9No exploitEPSS 0%

    siemens · siprotec 5 6md84 (cp300)Jun 9, 2026

  • A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).

    MediumCVSS 5.3No exploitEPSS 0%

    siemens · sinec insJun 9, 2026

  • A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).

    MediumCVSS 5.0No exploitEPSS 0%

    siemens · sinec insJun 9, 2026

All records of the vendor

Schneider Electric · June 9

1 · 0 KEV · 0 critical
  • CVE-2026-8045
    28Monitor

    CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side fi

    HighCVSS 7.1No exploitEPSS 0%

    schneider-electric · struxureware data center expertJun 9, 2026

All records of the vendor