Patch Tuesday
June 2026
On the second Tuesday of each month Microsoft, Adobe, SAP, Siemens and Schneider Electric publish in bulk; Oracle on the third Tuesday of January, April, July and October. Records published that day, from our own database, sorted by action score: KEV and mature exploits first.
How it is computed: CNA stamp + publication date (two-day window, UTC). No claim of a one-to-one match with the vendor bulletin; out-of-band updates land on other days.
330 records · 0 KEV
Affecting your stack
This month's records that match the products and versions in your stack.
Sign in to see the ones matching your stack; records and notifications are free. →
Microsoft · June 9
200 · 0 KEV · 8 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-26142No exploit | Nuance PowerScribe Remote Code Execution Vulnerabilitymicrosoft · nuance powerscribe 360 · CWE-502 | Critical9.8 | — | 1.5% | Jun 9, 2026 |
39Monitor | CVE-2026-44815No exploit | DHCP Client Service Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-121 | Critical9.8 | — | 1.0% | Jun 9, 2026 |
39Monitor | CVE-2026-45657No exploit | Windows Kernel Remote Code Execution Vulnerabilitymicrosoft · windows 11 23h2 · CWE-122 | Critical9.8 | — | 1.0% | Jun 9, 2026 |
39Monitor | CVE-2026-47291No exploit | HTTP.sys Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Critical9.8 | — | 1.0% | Jun 9, 2026 |
39Monitor | CVE-2026-47643No exploit | Azure Stack Edge Remote Code Execution Vulnerabilitymicrosoft · azure stack edge · CWE-73 | Critical9.8 | — | 1.0% | Jun 9, 2026 |
38Monitor | CVE-2026-42904No exploit | Windows TCP/IP Elevation of Privilege Vulnerabilitymicrosoft · windows 10 21h2 · CWE-122 | Critical9.6 | — | 0.5% | Jun 9, 2026 |
38Monitor | CVE-2026-47281No exploit | Visual Studio Code Elevation of Privilege Vulnerabilitymicrosoft · visual studio code · CWE-306 | Critical9.6 | — | 0.8% | Jun 9, 2026 |
36Monitor | CVE-2026-45484No exploit | Microsoft SharePoint Elevation of Privilege Vulnerabilitymicrosoft · sharepoint server · CWE-502 | High8.8 | — | 2.3% | Jun 9, 2026 |
36Monitor | CVE-2026-45602No exploit | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerabilitymicrosoft · windows 10 1607 · CWE-349 | Critical9.1 | — | 0.4% | Jun 9, 2026 |
35Monitor | CVE-2026-32193No exploit | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerabilitymicrosoft · azure kubernetes service · CWE-22 | High8.8 | — | 0.4% | Jun 9, 2026 |
35Monitor | CVE-2026-40371No exploit | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerabilitymicrosoft · dynamics 365 · CWE-280 | High8.8 | — | 0.8% | Jun 9, 2026 |
35Monitor | CVE-2026-42985No exploit | Remote Desktop Client Remote Code Execution Vulnerabilitymicrosoft · remote desktop client · CWE-416 | High8.8 | — | 0.8% | Jun 9, 2026 |
- CVE-2026-2614239Monitor
Nuance PowerScribe Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 2%microsoft · nuance powerscribe 360Jun 9, 2026
- CVE-2026-4481539Monitor
DHCP Client Service Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%microsoft · windows 10 1607Jun 9, 2026
- CVE-2026-4565739Monitor
Windows Kernel Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%microsoft · windows 11 23h2Jun 9, 2026
- CVE-2026-4729139Monitor
HTTP.sys Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%microsoft · windows 10 1607Jun 9, 2026
- CVE-2026-4764339Monitor
Azure Stack Edge Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%microsoft · azure stack edgeJun 9, 2026
- CVE-2026-4290438Monitor
Windows TCP/IP Elevation of Privilege Vulnerability
CriticalCVSS 9.6No exploitEPSS 1%microsoft · windows 10 21h2Jun 9, 2026
- CVE-2026-4728138Monitor
Visual Studio Code Elevation of Privilege Vulnerability
CriticalCVSS 9.6No exploitEPSS 1%microsoft · visual studio codeJun 9, 2026
- CVE-2026-4548436Monitor
Microsoft SharePoint Elevation of Privilege Vulnerability
HighCVSS 8.8No exploitEPSS 2%microsoft · sharepoint serverJun 9, 2026
- CVE-2026-4560236Monitor
Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
CriticalCVSS 9.1No exploitEPSS 0%microsoft · windows 10 1607Jun 9, 2026
- CVE-2026-3219335Monitor
Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 0%microsoft · azure kubernetes serviceJun 9, 2026
- CVE-2026-4037135Monitor
Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · dynamics 365Jun 9, 2026
- CVE-2026-4298535Monitor
Remote Desktop Client Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · remote desktop clientJun 9, 2026
+188 moreAll records of the vendor
Adobe · June 9
123 · 0 KEV · 4 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-47938No exploit | Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)adobe · campaign · CWE-918 | Critical10.0 | — | 0.9% | Jun 9, 2026 |
40Plan | CVE-2026-48303No exploit | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)adobe · campaign · CWE-863 | Critical10.0 | — | 1.2% | Jun 9, 2026 |
38Monitor | CVE-2026-47928No exploit | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | Critical9.6 | — | 0.5% | Jun 9, 2026 |
37Monitor | CVE-2026-34691No exploit | Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)adobe · experience manager · CWE-79 | Critical9.3 | — | 0.7% | Jun 9, 2026 |
35Monitor | CVE-2026-47932No exploit | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)adobe · coldfusion · CWE-22 | High8.8 | — | 0.5% | Jun 9, 2026 |
34Monitor | CVE-2026-47906No exploit | Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)adobe · dreamweaver · CWE-1395 | High8.6 | — | 0.3% | Jun 9, 2026 |
34Monitor | CVE-2026-47907No exploit | Dreamweaver Desktop | Improper Access Control (CWE-284)adobe · dreamweaver · CWE-284 | High8.6 | — | 0.3% | Jun 9, 2026 |
33Monitor | CVE-2026-47929No exploit | ColdFusion | Incorrect Authorization (CWE-863)adobe · coldfusion · CWE-863 | High8.4 | — | 0.5% | Jun 9, 2026 |
33Monitor | CVE-2026-47931No exploit | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | High8.4 | — | 0.5% | Jun 9, 2026 |
32Monitor | CVE-2026-34693No exploit | Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CWE-79)adobe · experience manager · CWE-79 | High8.0 | — | 0.6% | Jun 9, 2026 |
32Monitor | CVE-2026-47930No exploit | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | High8.1 | — | 0.9% | Jun 9, 2026 |
31Monitor | CVE-2026-34695No exploit | InDesign Desktop | Stack-based Buffer Overflow (CWE-121)adobe · indesign · CWE-121 | High7.8 | — | 0.3% | Jun 9, 2026 |
- CVE-2026-4793840Plan
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
CriticalCVSS 10.0No exploitEPSS 1%adobe · campaignJun 9, 2026
- CVE-2026-4830340Plan
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
CriticalCVSS 10.0No exploitEPSS 1%adobe · campaignJun 9, 2026
- CVE-2026-4792838Monitor
ColdFusion | Improper Input Validation (CWE-20)
CriticalCVSS 9.6No exploitEPSS 0%adobe · coldfusionJun 9, 2026
- CVE-2026-3469137Monitor
Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)
CriticalCVSS 9.3No exploitEPSS 1%adobe · experience managerJun 9, 2026
- CVE-2026-4793235Monitor
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
HighCVSS 8.8No exploitEPSS 1%adobe · coldfusionJun 9, 2026
- CVE-2026-4790634Monitor
Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)
HighCVSS 8.6No exploitEPSS 0%adobe · dreamweaverJun 9, 2026
- CVE-2026-4790734Monitor
Dreamweaver Desktop | Improper Access Control (CWE-284)
HighCVSS 8.6No exploitEPSS 0%adobe · dreamweaverJun 9, 2026
- CVE-2026-4792933Monitor
ColdFusion | Incorrect Authorization (CWE-863)
HighCVSS 8.4No exploitEPSS 0%adobe · coldfusionJun 9, 2026
- CVE-2026-4793133Monitor
ColdFusion | Improper Input Validation (CWE-20)
HighCVSS 8.4No exploitEPSS 0%adobe · coldfusionJun 9, 2026
- CVE-2026-3469332Monitor
Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CWE-79)
HighCVSS 8.0No exploitEPSS 1%adobe · experience managerJun 9, 2026
- CVE-2026-4793032Monitor
ColdFusion | Improper Input Validation (CWE-20)
HighCVSS 8.1No exploitEPSS 1%adobe · coldfusionJun 9, 2026
- CVE-2026-3469531Monitor
InDesign Desktop | Stack-based Buffer Overflow (CWE-121)
HighCVSS 7.8No exploitEPSS 0%adobe · indesignJun 9, 2026
+111 moreAll records of the vendor
SAP · June 9
0 · 0 KEV · 0 criticalNo records in this window.
Siemens · June 9
6 · 0 KEV · 0 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-46746No exploit | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).siemens · sinec ins · CWE-78 | High8.7 | — | 0.8% | Jun 9, 2026 |
34Monitor | CVE-2026-46748No exploit | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).siemens · sinec ins · CWE-250 | High8.7 | — | 0.3% | Jun 9, 2026 |
32Monitor | CVE-2026-24349No exploit | A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versiosiemens · simatic wincc unified pc runtime · CWE-313 | High8.2 | — | 0.1% | Jun 9, 2026 |
27Monitor | CVE-2025-40808No exploit | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (Csiemens · siprotec 5 6md84 (cp300) · CWE-434 | Medium6.9 | — | 0.2% | Jun 9, 2026 |
21Monitor | CVE-2026-46747No exploit | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).siemens · sinec ins · CWE-26 | Medium5.3 | — | 0.4% | Jun 9, 2026 |
20Monitor | CVE-2026-46749No exploit | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).siemens · sinec ins · CWE-760 | Medium5.0 | — | 0.2% | Jun 9, 2026 |
- CVE-2026-4674634Monitor
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).
HighCVSS 8.7No exploitEPSS 1%siemens · sinec insJun 9, 2026
- CVE-2026-4674834Monitor
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).
HighCVSS 8.7No exploitEPSS 0%siemens · sinec insJun 9, 2026
- CVE-2026-2434932Monitor
A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versio
HighCVSS 8.2No exploitEPSS 0%siemens · simatic wincc unified pc runtimeJun 9, 2026
- CVE-2025-4080827Monitor
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (C
MediumCVSS 6.9No exploitEPSS 0%siemens · siprotec 5 6md84 (cp300)Jun 9, 2026
- CVE-2026-4674721Monitor
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).
MediumCVSS 5.3No exploitEPSS 0%siemens · sinec insJun 9, 2026
- CVE-2026-4674920Monitor
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6).
MediumCVSS 5.0No exploitEPSS 0%siemens · sinec insJun 9, 2026
Schneider Electric · June 9
1 · 0 KEV · 0 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2026-8045No exploit | CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side fischneider-electric · struxureware data center expert · CWE-611 | High7.1 | — | 0.4% | Jun 9, 2026 |
- CVE-2026-804528Monitor
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side fi
HighCVSS 7.1No exploitEPSS 0%schneider-electric · struxureware data center expertJun 9, 2026