Microsoft Fixes 200 CVEs in June Patch Tuesday
2026-06-10T08:52:17Z•dc68289617aa6347ff8159418d0c6459b551f517cebc44bb03c2cd3e4a8f9125
ai-assisted-attacksauth-bypasscheck-pointchromecve-2026-11645edr-evasioneverest-formsexploited-in-the-wildinfosecurity-europeinstagram-breachmicrosoftnation-statenpm-backdoornso-grouppatch-managementpatch-tuesdayphpbbqilinsupply-chainwhatsappwordpress-rcezero-day
What happened
A large batch of security stories: Microsoft shipped June patches covering ~200 CVEs (including three zero‑days). Google patched Chrome CVE-2026-11645 — a sandbox escape exploited in the wild. Multiple actively exploited critical issues were reported, including a Check Point remote access/mobile access authentication bypass (attributed to Qilin), a critical phpBB auth bypass allowing account takeover with one request, and an Everest Forms Pro RCE used to create rogue WordPress admin accounts. Supply‑chain and developer targeting continue: 32 Red Hat npm‑scoped packages were backdoored to steal
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- dc68289617aa6347ff8159418d0c6459b551f517cebc44bb03c2cd3e4a8f9125
- Enrichment time
- 2026-06-10T08:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.