DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // MSRC-2026-Jun // PUBLISHED 2026-06-09

Microsoft June 2026 Patch Tuesday: Record 206 CVEs Including 6 Zero-Days, Critical RCE in Windows Kernel TCP/IP and HTTP.sys

Microsoft's June 2026 Patch Tuesday — the largest in Patch Tuesday history — addressed 206 vulnerabilities including 6 zero-days and 39 rated Critical. Highest-priority issues include CVE-2026-45657 (Windows Kernel TCP/IP RCE, CVSS 9.8), CVE-2026-47291 (Windows HTTP.sys integer overflow RCE, CVSS 9.8), CVE-2026-41091 (Microsoft Defender privilege escalation, confirmed exploited in the wild, CVSS 7.8), and three publicly named BitLocker bypasses (YellowKey CVE-2026-45585, Bitskrieg CVE-2026-50507). The Secure Boot KEK certificate lifecycle transition also began June 25, 2026, requiring urgent attention from organizations managing UEFI boot environments.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
Windows 11 24H2, 25H2
CRITICAL
NONE
PATCHED
Windows 10 (extended support)
CRITICAL
NONE
PATCHED
Windows Server 2025, 2022
CRITICAL
NONE
PATCHED
Microsoft Defender
CRITICAL
NONE
PATCHED
Microsoft Office / Outlook / Word
CRITICAL
NONE
PATCHED
Windows Remote Desktop Client
CRITICAL
NONE
PATCHED
Windows Hyper-V
CRITICAL
NONE
PATCHED
Windows HTTP.sys / IIS
CRITICAL
NONE
PATCHED
Windows BitLocker
CRITICAL
NONE
PATCHED
Microsoft Exchange Server
CRITICAL
NONE
PATCHED
Microsoft SharePoint Server
CRITICAL
NONE
PATCHED

Apply June 2026 cumulative updates immediately via Windows Update / WSUS / Intune. Install servicing stack update (ADV990001) before deploying other patches. Enable TPM+PIN for BitLocker to mitigate YellowKey/Bitskrieg. Restrict internet-facing RDP and enforce NLA. Apply KB5102602 MaxHeadersCount registry setting for HTTP.sys. Verify Exchange EEMS is enabled and CVE-2026-42897 patch applied. Update Secure Boot KEK certificates per Microsoft guidance before June 2026 deadline.

Alert on exploitation of CVE-2026-41091 (Defender link-following EoP — confirmed in-the-wild). Monitor for anomalous kernel-level process creation indicative of TCP/IP or HTTP.sys exploitation. Audit Hyper-V guest-to-host trust boundaries. Review SharePoint and Exchange Server logs for spoofing/XSS indicators. Use Microsoft Defender for Endpoint telemetry for zero-day behavioral coverage.

  • https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun
  • https://arcticwolf.com/resources/blog/microsoft-patch-tuesday-security-recap-june-2026-edition/
  • https://blog.qualys.com/vulnerabilities-threat-research/2026/06/09/microsoft-and-adobe-patch-tuesday-june-2026-security-update-review
SHARE BRIEF:✕ Post on Xin Share on LinkedIn