Patch Tuesday Special: June 2026
June 18th, 2026

Overview:
Microsoft’s June 9, 2026 Patch Tuesday addressed ~66–67 vulnerabilities (counts vary slightly by tracker methodology), including one publicly disclosed zero-day and ten critical vulnerabilities. While no vulnerabilities were confirmed as actively exploited at release, the presence of a publicly disclosed WebDAV flaw and several critical Remote Code Execution (RCE) vulnerabilities affecting core Windows services makes this a high-priority patch cycle.
Vulnerability Category Breakdown:
• Remote Code Execution (RCE): ~25 vulnerabilities (~37%)
• Elevation of Privilege (EoP): ~18 vulnerabilities (~27%)
• Information Disclosure: ~9 vulnerabilities (~13%)
• Denial of Service (DoS): ~7 vulnerabilities (~10%)
• Spoofing: ~5 vulnerabilities (~7%)
• Security Feature Bypass: ~3 vulnerabilities (~4%)
• Tampering: ~1 vulnerability (~1%)
Top 5:
1) CVE-2026-33053: Web Distributed Authoring and Versioning (WebDAV) Remote Code Execution (Publicly Disclosed Zero-Day)
• Why it matters: This vulnerability was publicly disclosed before a patch was available and allows remote code execution through WebDAV. Microsoft assessed exploitation as "More Likely," increasing concern that threat actors may quickly weaponize the flaw.
• Affected systems: Windows systems with the WebDAV client enabled.
• Pivotalogic Priority Rating: 💥SHUT IT DOWN; Patch immediately, especially on user endpoints and systems that regularly interact with external content.
2) CVE-2026-33073: Windows SMB Client Remote Code Execution
• Why it matters: This critical SMB Client vulnerability carries a CVSS score of 8.8 and could allow remote code execution through specially crafted network traffic. SMB remains one of the most targeted Windows services due to its widespread deployment and history of abuse.
• Affected systems: Windows clients utilizing SMB connectivity.
• Pivotalogic Priority Rating: 💥SHUT IT DOWN; Patch ASAP, particularly for systems communicating across untrusted networks.
3) CVE-2026-33071: Windows KDC Proxy Service (KPSSVC) Remote Code Execution
• Why it matters: This critical vulnerability affects the Kerberos Key Distribution Center Proxy Service and may allow remote code execution with minimal attacker interaction. Identity-related services are high-value targets due to their role in authentication and domain operations.
• Affected systems: Windows systems utilizing KDC Proxy Service functionality.
• Pivotalogic Priority Rating: 🚨Yikes!; Patch within 72 hours, especially on domain-connected and identity-related infrastructure.
4) CVE-2026-33070: Windows Netlogon Remote Code Execution
• Why it matters: Netlogon is a core authentication service within Active Directory environments. Successful exploitation could allow attackers to gain significant control within enterprise networks and potentially facilitate lateral movement.
• Affected systems: Windows Server systems functioning as domain controllers and systems utilizing Netlogon services.
• Pivotalogic Priority Rating: 💥SHUT IT DOWN; Patch immediately on domain controllers and critical authentication infrastructure.
5) CVE-2026-33072: Windows SMB Server Remote Code Execution
• Why it matters: This critical SMB Server vulnerability affects systems accepting SMB connections. Given SMB's ubiquity and historical attractiveness to attackers, organizations should prioritize patching servers exposed to internal or external network traffic.
• Affected systems: Windows systems hosting SMB services.
• Pivotalogic Priority Rating: 🚨Yikes!; Patch within 72 hours, prioritizing file servers, application servers, and other systems providing SMB services.
Pivotalogic Priority Rating Scale:
💥SHUT IT DOWN (not literally) = Critical
🚨Yikes! = High
⚠️Welp. = Medium
💡Eh = Low
Read Microsoft's full patch notes HERE
