Microsoft’s June release set a new record with 208 CVEs addressed across Windows, Office, Edge/Chromium components, Hyper‑V, BitLocker and more. Zero Day Initiative highlights one Defender elevation-of-privilege under active exploitation (CVE-2026-41091) and multiple critical, likely-to-be-targeted RCEs, including HTTP.sys (CVE-2026-47291, CVSS 9.8), a Windows Kernel TCP/IP bug (CVSS 9.8) and a DHCP Client RCE (CVE-2026-44815, CVSS 9.8). ZDI warns these network‑reachable issues could be wormable and urges rapid testing and deployment. Admins should also review mitigations and registry guidance for HTTP.sys while patching.
Source: Zero Day Initiative
Google fixes Chrome zero-day exploited in the wild (CVE-2026-11645)
Google patched 74 Chrome vulnerabilities, including CVE-2026-11645, a high‑severity out‑of‑bounds read/write in the V8 JavaScript engine that attackers are already exploiting. Updates are rolling out as version 149.0.7827.102/.103 on Windows and macOS and 149.0.7827.102 on Linux—admins should expedite patching given active abuse and V8’s centrality to exploit chains.
Source: Help Net Security
Check Point VPN zero-day abused by Qilin ransomware to bypass authentication
An authentication bypass flaw in Check Point VPN gateways is being exploited by the Qilin ransomware group to establish VPN sessions without valid passwords. Organizations should apply vendor mitigations, review remote access logs for suspicious sessions, revoke tokens, and rotate credentials to limit lateral movement and persistence.
Source: SecurityWeek
CISA adds LiteLLM AI gateway flaw to KEV amid active exploitation (CVE-2026-42271)
CISA confirmed attackers are exploiting a command injection bug in BerryAI’s LiteLLM, an open-source AI gateway used to broker calls to multiple LLM providers. With CVE-2026-42271 now in the Known Exploited Vulnerabilities catalog, agencies face patch deadlines; enterprises should urgently update, restrict network access to admin/test endpoints, and review logs for command execution and abuse of MCP features.
Source: Help Net Security
ServiceNow patches vulnerability exploited against some customer instances
ServiceNow said it applied a security update on June 5 to hosted customer instances to fix an issue reportedly known internally since April that attackers leveraged to gain deeper, unauthorized access. While the company has pushed fixes to cloud customers, security teams should validate instance versions, review access logs for anomalies, and rotate credentials/API tokens that may have been exposed.
Source: SecurityWeek
Critical Veeam Backup & Replication RCE lets low-privileged domain users execute code (CVE-2026-44963)
Veeam released patches for a critical RCE (CVSS 9.4) in Backup & Replication 12.x that allows an authenticated domain user to run code on the backup server. Given backups’ importance for ransomware recovery and their privileged network position, organizations should upgrade to 12.3.2.4854 immediately and restrict network access to Veeam services.
Source: The Hacker News
Anthropic’s Mythos accelerates exploit creation for N-days, shrinking defenders’ patch window
New research shows Anthropic’s Mythos‑class model can turn recently disclosed (N‑day) vulnerabilities into working exploits within hours—work that typically took days or weeks. SecurityWeek notes that even public LLMs with fewer guardrails can assist, raising the risk during the patch‑gap period; defenders should tighten prioritization, speed remediation, and expand detection for post‑disclosure exploitation.
Source: SecurityWeek
You May Also Be Interested In...
No Patch Planned for Exploited Arista EOS VulnerabilityUK Weakens Proposed Telecoms Defenses After Industry Pushback
ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact Fix Vulnerabilities