Ship the Windows cumulative first — for the remote code execution, not for exploitation. Three unauthenticated, network-reachable Critical RCEs ride June's cumulative: HTTP.sys (CVE-2026-47291), a wormable Windows Kernel flaw (CVE-2026-45657), and the DHCP client (CVE-2026-44815). None is being exploited; all three reach code execution without authentication, which is why this is a five-day change and not a normal-cycle one.
Nothing published on 9 June is under active attack. The June-9 CVEs show no confirmed in-the-wild exploitation and none is CISA KEV-listed. The 'actively exploited' headlines this month point at two late-May out-of-band items, not at anything in this release.
What you should already have done. The exploited items are last month's: a Microsoft Defender elevation of privilege (CVE-2026-41091) KEV-listed 20 May with a 3 June federal deadline, and an Exchange OWA cross-site scripting flaw (CVE-2026-42897) KEV-listed 15 May. Both due dates have passed. If they are not done, they are overdue — and the Defender fix ships in the Malware Protection Engine, not a cumulative.
The highest-scored flaw is not why anything ships. The month's top CVSS is an Azure cloud-service elevation of privilege Microsoft had already fixed server-side before publication, with no customer action. Deployment order is set by unauthenticated reach, not by the score.
Publicly disclosed, not exploited. Four flaws were public before the patch — an HTTP.sys denial of service (CVE-2026-49160), a CTFMON elevation of privilege (CVE-2026-45586), and two BitLocker feature bypasses (CVE-2026-50507, CVE-2026-45585). Disclosure raises the odds of a proof-of-concept; none is confirmed exploited. They ride the same cumulative, so patching the RCEs clears them too.
Why now. Three of the release's Critical remote code execution flaws are unauthenticated and network-reachable, and each reaches code execution without user interaction: HTTP.sys (CVE-2026-47291), the Windows Kernel (CVE-2026-45657) and the DHCP client (CVE-2026-44815). None is being exploited and none is KEV-listed, so this is a structural call rather than an evidence one — but an unauthenticated Critical flaw in the core networking and kernel stack is a five-day change on any estate, because the distance from an unpatched gap to code execution is one packet.
| Product | Package | Carries |
|---|---|---|
| Windows 11 25H2 / 24H2 | KB5094126 | CVE-2026-47291, CVE-2026-45657, CVE-2026-44815 |
| Windows 11 23H2 | KB5093998 | CVE-2026-47291, CVE-2026-45657, CVE-2026-44815 |
| Windows 10 22H2 (ESU) | KB5094127 | CVE-2026-47291, CVE-2026-44815 |
| Windows Server 2025 | KB5094125 | CVE-2026-47291, CVE-2026-45657 |
| Windows Server 2022 | KB5094128 | CVE-2026-47291, CVE-2026-45657 |
| Windows Server 2019 | KB5094123 | CVE-2026-47291 |
| Windows Server 2016 | KB5094122 | CVE-2026-47291 |
Also inside: The same cumulative carries the month's publicly-disclosed set: an HTTP.sys denial of service (CVE-2026-49160, the so-called HTTP/2 Bomb), a CTFMON elevation of privilege (CVE-2026-45586) and two BitLocker feature bypasses (CVE-2026-50507 and CVE-2026-45585). Public disclosure raises the odds a proof-of-concept appears; none is confirmed exploited. Because they ride this package, deploying it for the RCEs clears them in the same change.
Then. Deploy the per-product package for your build from the table and reboot. Do not wait for an exploited-in-the-wild signal on the kernel flaw: CVE-2026-45657 is rated Exploitation Less Likely and has not been seen exploited weeks after release, which is exactly the structural false positive the model accepts — the cost of shipping it early is near zero because it rides a cumulative that is already a five-day change.
Calling this Act rather than Prioritise rests on treating an unauthenticated network RCE in HTTP.sys, the kernel and the DHCP client as core-infrastructure gate-passes with no exploitation signal. CVE-2026-47291 reportedly requires non-default registry settings to reach, which weakens it; the kernel and DHCP flaws carry the call on their own. If your estate treats a non-exploited Critical cumulative as a normal-cycle item, this drops to Prioritise and a 14-day clock, and nothing else in the brief moves.
Nothing in the 9 June release is under active exploitation; the exploited items attributed to this month are late-May KEV entries that predate the cycle.
Basis. The live CISA KEV catalog (retrieved 2026-07-16) contains no CVE first published on 9 June 2026. The only Microsoft KEV entries in the window are CVE-2026-41091 (Defender, added 20 May) and CVE-2026-42897 (Exchange OWA XSS, added 15 May), both predating June Patch Tuesday. CrowdStrike and Rapid7, scoping to the June-9 set, report no exploitation, and Rapid7 relays Microsoft's statement that it is not aware of in-the-wild exploitation for any of them.
What would lower this. A KEV addition or a credible in-the-wild report for any 9 June CVE would move this immediately. The corpus is thin and exploitation of a disclosed flaw has a short fuse, so this is a read of a moment rather than a guarantee about the month.
The Windows client and server cumulative is the only five-day change this month.
Basis. Stage-1 structural classification: the three 9.8 RCEs are core_infrastructure with a network vector and pass the impact gate, while no other unit in the release reaches the gate without an exploitation signal. There is one remediation unit, so there is no cross-unit chain and no cut to compute.
What would lower this. A per-estate exposure that puts another Microsoft product on an untrusted network, or a public proof-of-concept for one of the currently-disclosed flaws, would add units to the five-day wave and change the ordering.
None.
| Source | Admiralty | Used for |
|---|---|---|
| https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities | A1 | KEV read 2026-07-16: no 9 June CVE listed; the Defender (20 May) and Exchange (15 May) entries are the only Microsoft items in the window |
| https://www.zerodayinitiative.com/blog/2026/6/9/the-june-2026-security-update- | B2 | Count (208) and Critical (38); wormable kernel characterisation; HTTP.sys non-default-registry caveat; full CVE table |
| https://www.tenable.com/blog/microsofts-june-2026-patch-tuesday-addresses-198- | B2 | Count (198) with the six-serviced / two-other-CNA exclusion note; publicly-disclosed set |
| https://www.rapid7.com/blog/post/em-patch-tuesday-june-2026/ | B2 | Count (200); Microsoft not aware of in-the-wild exploitation for the June set; HTTP/2 CVE-number disambiguation |
| https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-june-2026/ | B2 | Count (206) and Critical (37); no exploitation in the June-9 set; Critical RCE table |
| https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tues | B2 | Count (200); per-version KB list; publicly-disclosed zero-day set |
| https://support.microsoft.com/en-us/topic/june-9-2026-kb5094126-os-builds-2620 | A2 | Windows 11 25H2/24H2 package KB5094126 and OS build of record |
| https://www.it-connect.tech/june-2026-windows-server-updates-whats-new-in-kb50 | C3 | Windows Server 2025/2019/2016 KB numbers and builds (secondary corroboration; confirm builds against the Security Update Guide) |