June 2026 Patch Tuesday: Windows Admin Priorities
The practical takeaway for June is straightforward: patch exposed Windows servers and domain controllers first, then move quickly through admin workstations and the wider endpoint estate. Microsoft is not reporting active exploitation in this release, so most organisations can use their normal staged rollout rather than abandoning testing.
There is still plenty to review. The June 2026 Patch Tuesday release includes an unauthenticated HTTP.sys remote code execution flaw, two critical domain controller issues, several Remote Desktop Client vulnerabilities, and three publicly disclosed vulnerabilities. Windows 10 and Windows Server 2022 also carry a narrowly scoped BitLocker recovery known issue.
This article turns the Microsoft Security Update Guide into a deployment plan for Windows admins, Intune teams, MSPs, and endpoint management teams. For the previous month's context, see the May 2026 Patch Tuesday deployment notes.
What changed in June 2026 Patch Tuesday
Microsoft released the June security updates on 2026-06-09. At the time of review, the June 2026 Security Update Guide release note lists:
- 206 Microsoft CVEs
- 38 Critical and 168 Important vulnerabilities
- 3 publicly disclosed vulnerabilities
- 0 vulnerabilities marked as exploited
Those numbers describe the release, but they do not tell you which devices should move first. For deployment planning, exposure and server role matter more than the headline total.
The three publicly disclosed vulnerabilities are:
- CVE-2026-45586, a Windows Collaborative Translation Framework elevation of privilege vulnerability that can lead to SYSTEM privileges after local exploitation.
- CVE-2026-49160, an HTTP.sys denial of service vulnerability affecting HTTP/2 handling.
- CVE-2026-50507, a BitLocker security feature bypass that requires physical access to the target.
Microsoft rates exploitation as "more likely" for all three, but does not mark any of them as exploited. That distinction matters: public disclosure increases attention, but it is not evidence of active attacks.
Windows KBs and builds to verify
Use the KB and build as your compliance target. Do not rely only on an update policy showing as assigned.
| Platform | June 2026 update | Build to verify |
|---|---|---|
| Windows 11, version 26H1 | KB5095051 | 28000.2269 |
| Windows 11, versions 25H2 and 24H2 | KB5094126 | 26200.8655 / 26100.8655 |
| Windows 11, version 23H2 | KB5093998 | 22631.7219 |
| Supported Windows 10 22H2 / 21H2 servicing paths | KB5094127 | 19045.7417 / 19044.7417 |
| Windows Server 2025 | KB5094125 | 26100.32995 |
| Windows Server 2022 | KB5094128 | 20348.5256 |
| Windows Server 2019 | KB5094123 | 17763.8880 |
| Windows Server 2016 | KB5094122 | 14393.9234 |
Check the exact edition, architecture, and servicing entitlement in your environment. Windows 10 devices outside a supported LTSC or ESU path should not be treated as compliant simply because an older cumulative update is installed.
What Windows admins should prioritise
1. Internet-facing HTTP.sys workloads
CVE-2026-47291 is the clearest first priority for exposed Windows servers. Microsoft rates it Critical with a 9.8 base score and says an unauthenticated attacker could send a crafted packet to a server using the Windows HTTP Protocol Stack. Microsoft also assesses exploitation as more likely.
Start with servers that accept untrusted HTTP or HTTPS traffic and confirm whether HTTP.sys is in the request path. netsh http show servicestate is useful for an initial check, but map the listeners back to the owning service before making decisions.
The publicly disclosed CVE-2026-49160 is a separate HTTP.sys denial of service issue. The June update enables Microsoft's protection. Microsoft also documents a MaxHeadersCount control for limiting accepted HTTP/2 and HTTP/3 request headers in KB5102602. Treat that registry control as a hardening decision to test, not a value to push blindly across every server.
2. Domain controllers
Two Critical vulnerabilities make domain controllers an early server wave:
- CVE-2026-45648 is an Active Directory Domain Services remote code execution vulnerability. Microsoft says a domain-authenticated attacker with access to the NSPI RPC interface can trigger it without admin rights or user interaction.
- CVE-2026-47288 affects the Kerberos Key Distribution Center. Exploitation requires an authenticated domain attacker and has high attack complexity, but the target is still a domain controller.
Patch domain controllers in a sequence that preserves authentication and DNS availability. Check replication, SYSVOL, time service, LDAP-dependent applications, and Kerberos authentication before moving to the next DC.
3. Admin workstations and RDP jump hosts
CVE-2026-42985 is a Critical Remote Desktop Client remote code execution vulnerability that Microsoft assesses as more likely to be exploited. The documented scenario requires a user to connect the vulnerable client to an attacker-controlled Remote Desktop server.
That makes privileged endpoints more important than raw device count. Prioritise helpdesk workstations, jump hosts, MSP technician devices, and admin laptops that initiate RDP sessions into customer or third-party environments.
4. Hyper-V, WDS, and role-specific servers
The June release also contains Critical fixes for Windows Hyper-V, Windows Deployment Services, Windows graphics components, and other Windows roles. Use the Security Update Guide product filters to match vulnerabilities to roles you actually run.
For Hyper-V clusters, drain and patch one node at a time. For WDS or imaging infrastructure, validate PXE boot, task sequences, WinPE, storage, and driver injection after the pilot server is updated.
5. The publicly disclosed local and physical issues
Do not ignore the publicly disclosed CTFMON and BitLocker vulnerabilities, but keep their prerequisites in view. CTFMON requires local access for privilege escalation. The BitLocker bypass requires physical access to the device.
These still justify prompt endpoint patching, especially for shared workstations, kiosks, travelling laptops, and devices handled outside controlled offices. They do not justify treating every endpoint as if an unauthenticated remote exploit is already in progress.
What I'd prioritise first
- Internet-facing Windows servers that use HTTP.sys, after a focused service check and application smoke test.
- Domain controllers, patched in redundant waves with replication and authentication validation between each wave.
- Privileged workstations, RDP jump hosts, helpdesk endpoints, and MSP technician devices.
- Windows 10 and Windows Server 2022 devices that might match the PCR7 BitLocker known-issue configuration.
- Hyper-V, WDS, and other role-based servers, followed by the wider workstation estate through normal rings.
The absence of Microsoft-confirmed exploitation supports a controlled rollout. It does not support leaving exposed or identity-critical systems until the end of a month-long endpoint deadline.
How to roll this month
Use the Patch Tuesday Intune and WUfB operations guide for rings, Intune checks, sample build validation, monitoring, exception logs, and hold criteria. Do not copy that operating model into every monthly briefing.
For June, expedite only internet-facing HTTP.sys servers, domain controllers, and privileged RDP endpoints after a focused pilot. Keep normal rings for the rest of the estate. The patch management hub and Windows Server hub still apply.
Watch for known issues
Microsoft currently lists no known issues for the June updates covering Windows 11 26H1, 25H2, 24H2, or 23H2. That is a point-in-time status, not a guarantee that no issue will emerge after wider deployment.
There are three platform-specific items to account for:
Windows 10 KB5094127: Microsoft lists a limited BitLocker recovery issue on devices with an unrecommended PCR7 validation policy. All documented conditions must be present, including explicit PCR7 policy, msinfo32.exe showing PCR7 Binding as "Not Possible", the Windows UEFI CA 2023 certificate in the Secure Boot DB, and the older boot manager still in use.
Windows Server 2022 KB5094128: The same PCR7 BitLocker recovery condition is listed. Microsoft also notes that WSUS does not display synchronisation error details after specified earlier updates.
Windows Server 2025 KB5094125: Microsoft lists the WSUS error-detail issue. Treat missing detail as an observability limitation, not proof that synchronisation itself failed.
Microsoft's June notes explicitly say the earlier boot manager servicing issue that could trigger BitLocker recovery is fixed for Windows 11 23H2 and Windows Server 2025. If your support team handled that problem in April or May, keep the BitLocker recovery key Entra backup guide available during rollout.
Re-check Windows release health and each relevant KB before promoting a ring.
Secure Boot certificate readiness is now a June task
The Secure Boot certificate transition is no longer a distant planning item. Microsoft's current dates are:
- 2026-06-24: Microsoft Corporation KEK CA 2011 expires.
- 2026-06-27: Microsoft UEFI CA 2011 expires.
- 2026-10-19: Microsoft Windows Production PCA 2011 expires.
Microsoft says devices without the newer 2023 certificates will continue to start and receive normal Windows updates, but they may not receive future early-boot protections, Secure Boot database updates, revocation lists, or mitigations.
Several June cumulative updates expand Microsoft's high-confidence device targeting for automatic certificate delivery and add Secure Boot status or policy changes. That helps, but it does not replace estate visibility. Use the Secure Boot CA 2023 enterprise readiness guide to check client devices, servers, recovery media, virtual machines, and Intune reporting.
There is also a deployment-media detail in the June KBs: when applying Dynamic Update packages to an existing Windows image, ensure the matching boot.stl file is included. Microsoft warns that missing it can prevent media from starting and produce error 0xc0430001.
What to monitor after deployment
Use the Patch Tuesday operations guide for the shared 24–48 hour watch list. For June, add HTTP.sys service health, domain-controller replication and authentication, privileged RDP, and the PCR7 BitLocker pattern on Windows 10 and Server 2022.
Admin checklist
- Review the June 2026 Microsoft Security Update Guide and retain the filtered export with the change record.
- Identify affected products and map every supported Windows version to the expected June KB and build.
- Patch representative pilot devices and servers before broad approval.
- Prioritise internet-facing HTTP.sys workloads, domain controllers, privileged endpoints, and other high-risk systems.
- Audit Windows 10 and Windows Server 2022 BitLocker PCR7 policy and recovery-key readiness.
- Review Intune or Windows Update for Business rings, exclusions, deadlines, restart settings, and recent device sync.
- Check Windows release health and each KB known-issues section before promoting a ring.
- Confirm rollback, console access, backup, recovery, and Microsoft support ownership.
- Monitor update failures, BitLocker prompts, authentication, RDP, HTTP services, endpoint security, and application health.
- Document exceptions with an owner, reason, compensating control, and review date.
Final recommendation
Run June as a fast, evidence-led rollout. Move exposed HTTP.sys servers, domain controllers, and privileged RDP endpoints through focused pilots first. Keep normal rings for the wider estate, but shorten promotion decisions when telemetry is clean.
Do not let the 206-CVE headline replace environment-specific prioritisation. The useful question is not "How many vulnerabilities shipped?" It is "Which of our systems expose the affected component, and what evidence do we need before expanding deployment?"
Official sources
- Microsoft Security Update Guide
- June 2026 Security Update Guide release note
- Windows release health
- Windows Secure Boot certificate expiration and CA updates
- Secure Boot certificate guidance for IT professionals
- Microsoft Intune method for Secure Boot certificate updates
- Monitoring Secure Boot certificate status with Intune remediations
Jack Hadcroft
LinkedInBand 6 Endpoint Specialist and author of AdminSignal
Technical claims are reviewed against current Microsoft documentation. Lab or tenant checks are named only when they were done.
Independent publication. About · Editorial policy