Client Security Bulletin | Microsoft June 2026 Patch Tuesday

Issue date: 7 July 2026 (Sydney)


Executive Summary

Microsoft's June 2026 Patch Tuesday is a critical release and its largest yet, fixing 206 security issues across Windows and supported Microsoft software. IT teams must act now: this is a major patching event with multiple priorities to assess, test, deploy, and verify in a narrow window. The release includes 37 Critical issues, which often involve remote code execution or privilege escalation and can lead to severe compromise if left unpatched. It also includes 3 zero-days that were already public, which shortens the response window because attackers can study the details or use exploit code immediately. Because the update spans desktop and server platforms, organisations need to treat this as a broad, urgent enterprise maintenance event and do not delay.

Key affected parts include HTTP.sys, the Windows kernel, DHCP Client Service, Active Directory Domain Services, Remote Desktop Client, Microsoft Office, and Hyper-V, each of which sits in a critical part of the Windows environment. HTTP.sys supports Windows web servers and IIS, the kernel is the foundation of every Windows system, DHCP keeps devices connected to the network, and Active Directory underpins enterprise identity and access control. Remote Desktop Client is a common remote access path, Office remains the most frequent phishing target, and Hyper-V is central to virtualisation and host infrastructure. CrowdStrike and other vendors have flagged this release as one of the most significant Patch Tuesdays in recent memory, which reinforces the need to move immediately. It also aligns closely with ACSC guidance to respond quickly to public and high-risk issues, especially where exposed services or identity systems are at risk.

206

Immediate vulnerability load

206 issues fixed across Windows 10, 11, Server 2016/2019/2022, and Microsoft applications — an unusually broad exposure that affects most enterprise fleets right now.

37

Critical vulnerabilities

These typically enable remote code execution or privilege escalation with no user interaction required — do not delay remediation.

3

Publicly disclosed zero-days

Exploit code or full technical details are already available to attackers, sharply reducing defenders' time to act.

High-risk affected areas

  • HTTP.sys
  • Windows kernel
  • DHCP Client Service
  • Active Directory Domain Services
  • Remote Desktop Client
  • Microsoft Office
  • Hyper-V

ACSC patching guidance

The 48-hour tier applies immediately to internet-facing systems — including the three zero-days, the HTTP.sys RCE issue, and the Windows kernel privilege escalation. For most organisations, that means starting rollout before the end of the business week. Act now.

The two-week tier covers internal systems, endpoints, and server roles not directly exposed to the internet. These patches still need urgent scheduling, tracking, and verification — internal systems remain at risk if attackers already have a foothold.


Why this matters now

Essential business services at risk

HTTP.sys, Active Directory, RDP, and Office support sign-in, email, remote work, and server operations. If one is compromised, disruption can spread quickly across the organisation. Act immediately.

Critical and publicly disclosed vulnerabilities

Critical ratings mean attackers can gain access without any user action. Public zero-days shorten the window even further — exploit code may already be circulating. Do not delay.

Internet-facing services and remote access

RDP and HTTP.sys on public-facing systems are the highest-priority targets because they are reachable by anyone on the internet. Organisations with exposed external access should treat this as an urgent call to act now.

Delays in patching increase risk

Risk compounds over time as exploit code matures and spreads to less sophisticated attackers. Unpatched systems also create compliance exposure under the Essential Eight and similar frameworks.

Virtualisation and shared infrastructure at risk

Hyper-V flaws can allow a compromised VM to break out and reach the underlying host and other workloads. In shared environments, one weak point can endanger systems across multiple teams or business units.

Critical actions to take immediately

01

Prioritise exposure review now

List every internet-facing system immediately, including web servers, RDP endpoints, VPN gateways, and HTTP.sys services. Identify domain controllers, Hyper-V hosts, and DHCP servers, then cross-reference them against Microsoft's June 2026 release notes without delay. Flag anything that cannot be patched immediately and apply compensating controls now.

02

Accelerate patch deployment immediately

Use WSUS, SCCM, Intune, or equivalent tooling to push June 2026 updates as fast as your testing process allows. For internet-facing systems and domain controllers, compress your normal testing window because the severity and public disclosure make delay dangerous. Schedule reboots during low-impact windows and track which systems are patched and which are still pending.

03

Follow ACSC timeframes without delay

The 48-hour window is the critical standard for internet-facing systems with Critical or exploited vulnerabilities — treat it as a hard deadline for the zero-days and HTTP.sys/kernel issues. The two-week window applies to internal systems and lower-risk components, but do not let that become an excuse to delay. Document your timeline immediately and record any exceptions with a named risk owner and firm remediation date.

04

Validate deployment success urgently

Confirm installation in your patch management console and cross-check it with a vulnerability scan. Verify that required reboots have completed, then review event logs and monitoring alerts in the 24–48 hours after patching for any unexpected service impact. Do not assume success until you have proof.

05

Review and compensate immediately

For systems that cannot be patched in time, block or restrict RDP from the internet, apply network segmentation, and increase logging on affected services immediately. Assign a named owner and set a firm date for resolution now. Review controls regularly until the patch is applied.

Urgent glossary

Act now to understand the cybersecurity terms in this bulletin. These definitions are designed to help non-technical readers quickly grasp the critical concepts, the immediate risk, and the serious consequences these vulnerabilities can create if left unaddressed.

1

Critical vulnerability

A weakness or flaw in software or hardware that can be exploited immediately to compromise a system, gain unauthorized access, or force it to malfunction. Treat it like an unlocked door or a weak window that an attacker can use right now.

2

Critical vulnerability

A severe security flaw that can give an attacker full control of a system or let them run malicious code without any user interaction. These are urgent threats and should be treated as if the front door were wide open.

3

Zero-day

A vulnerability that the software vendor does not yet know about, leaving them with zero days to fix it before attackers exploit it. A publicly disclosed zero-day is immediately more dangerous because the flaw is now in the open and at risk of abuse.

4

Remote code execution (RCE)

A dangerous vulnerability that lets an attacker run malicious code on a remote computer or server over the network. This is critical because it can give attackers direct control and immediate access to sensitive systems.

5

Privilege escalation

When an attacker who already has some access to a system finds a way to increase their control. For example, they may move from a standard user account to an administrator account, putting the system at even greater risk.

6

Patch Tuesday

The second Tuesday of each month, when Microsoft typically releases security updates. Do not delay reviewing these patches, because critical fixes often arrive on this schedule and may address active threats.

7

ACSC guidance

Recommendations from the Australian Cyber Security Centre on how organizations should respond to cyber threats. These timeframes are urgent guidance for patching vulnerabilities and should be followed immediately where possible.

8

Compensating controls

Security measures used to reduce risk when a patch or other primary fix cannot be applied immediately. Examples include blocking network access or increasing monitoring to protect at-risk systems until remediation is complete.

9

Hyper-V

Microsoft's virtualization technology that lets multiple operating systems run as virtual machines on a single physical server. Vulnerabilities here are critical because they can threaten an entire virtual infrastructure at once.

10

HTTP.sys

A core Windows component that handles web requests. A vulnerability in HTTP.sys can expose any Windows web server or application to immediate remote attack, so it must be treated as urgent.

11

Remote Desktop Client (RDP)

A protocol used to connect to and control a remote computer over a network. It is essential for remote work, but if it is not secured immediately, attackers may use it as a direct entry point.

12

Active Directory

A Microsoft directory service for Windows domain networks that manages user accounts, computers, and other resources. It is a critical target and must be protected immediately because compromise can impact the entire network.