MilikMilik

Microsoft and Google Ship Record Patches as Attackers Target Unpatched Systems

Microsoft and Google Ship Record Patches as Attackers Target Unpatched Systems
Interest|High-Quality Software

Why Patch Tuesday June 2026 Is Different—and More Dangerous

Patch Tuesday June 2026 refers to an unusually large monthly wave of coordinated software security updates that address hundreds of critical vulnerabilities across Microsoft, Google, and major enterprise platforms, turning routine patching into an urgent race against active cyberattacks targeting unpatched systems worldwide. Microsoft’s June release fixes over 200 vulnerabilities, including 32 critical flaws and three zero-days that attackers are already exploiting. At the same time, Google updated Chrome to address 74 security issues, among them a high-severity Chrome zero-day CVE in the V8 engine. Security agencies responded by adding exploited bugs from Cisco, Chrome, and Arista to official high-risk vulnerability lists, signaling that attackers are quickly operationalizing these flaws. Together with critical updates from SAP, Fortinet, and Ivanti, this patch cycle marks a shift from occasional emergency fixes to a constant sprint for both users and administrators.

Microsoft and Google Ship Record Patches as Attackers Target Unpatched Systems

Microsoft Security Updates: 200+ Windows and Cloud Fixes

Microsoft security updates for June bring the largest Patch Tuesday drop on record, with more than 200 CVEs across Windows, Office, developer tools, and cloud services. Analysts report that 32 are critical vulnerabilities, and at least three Windows security flaws are zero-days already exploited in the wild. According to TechRepublic, “June’s record-shattering drop of 210 Microsoft vulnerabilities is a stark warning that AI is supercharging flaw discovery at an uncontrollable scale.” This volume strains traditional monthly patching, especially for enterprises with complex test cycles. Admins should prioritize critical vulnerabilities patch sets affecting remote code execution, authentication, and internet-facing services before tackling lower-severity bugs. Given that the number of Microsoft CVEs this year already exceeds the company’s total for 2018, June underscores how fast the attack surface is growing and why deferring core Patch Tuesday updates is no longer an acceptable risk.

Chrome Zero-Day CVE-2026-11645 and Other Browser Risks

Google has released security updates for 74 Chrome vulnerabilities, including a high-severity Chrome zero-day CVE tracked as CVE-2026-11645 in the V8 JavaScript and WebAssembly engine. This out-of-bounds read and write flaw allows a remote attacker to execute arbitrary code in the browser sandbox via a crafted HTML page, and Google confirms that “an exploit for CVE-2026-11645 exists in the wild.” Users should update to Chrome 149.0.7827.102/.103 on Windows and macOS and 149.0.7827.102 on Linux by visiting More > Help > About Google Chrome and relaunching. Other Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi will release equivalent fixes and must be updated as well. With Google already addressing five actively exploited Chrome zero-days since the start of the year, timely browser patching is now as important as installing operating system updates.

Microsoft and Google Ship Record Patches as Attackers Target Unpatched Systems

CISA KEV Alerts: Cisco, Chrome, and Arista Under Active Attack

Security urgency increased when CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog: Cisco CVE-2026-20245, Chrome CVE-2026-11645, and Arista CVE-2026-7473. The Cisco flaw is an improper encoding or escaping of output issue in Catalyst SD-WAN Manager that lets an authenticated local attacker execute commands as root via a crafted file. The Arista EOS bug stems from incomplete comparison checks, allowing switches configured as tunnel endpoints to decapsulate and forward unexpected tunneled packets, processing non-configured tunnel traffic. Arista notes that the vulnerability has been reported as exploited in the wild and affects specific 7020R, 7280R/R2, and 7500R/R2 series products with tunnel decapsulation configured. While Google has delivered a patch for the Chrome zero-day CVE, Arista indicates no traditional patch is planned, making configuration review and architectural controls essential for network teams.

Microsoft and Google Ship Record Patches as Attackers Target Unpatched Systems

Enterprise Priorities: SAP, Fortinet, Ivanti and the New Patch Race

Beyond Microsoft and Chrome, enterprise vendors released their own critical vulnerabilities patch bundles. SAP’s June Security Patch Day shipped four critical fixes across NetWeaver AS ABAP, ABAP Platform, NetWeaver Java, SAP Commerce Cloud, and SAP Data Hub. CVE-2026-44748, rated 9.9, addresses an XML Signature Wrapping issue in SAML authentication that can allow tampered identities to be accepted, while CVE-2026-27671, rated 9.8, fixes a memory corruption flaw in the ABAP kernel with no workaround beyond applying the kernel update. Security advisories also highlight critical vulnerabilities from Fortinet and Ivanti, with CVSS scores reaching up to 10.0, affecting network security appliances and endpoint or remote access platforms. Patch Tuesday now represents a race between defenders applying fixes and attackers scanning for lagging systems; organizations should rank updates by exposure, starting with internet-facing SAP, Fortinet, Ivanti, Windows, and browser components.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!