Vulnerability intelligence
CVE-2026-45657 — Security Advisory
June 2026 Patch Tuesday delivered 208 CVEs (571 with Chromium bundled), 37 Critical. CVE-2026-45657 (CVSS 9.8) is a use-after-free in Windows Kernel TCP/IP that requires no authentication and can self-propagate. CVE-2026-47291 (CVSS 9.8) hits HTTP.sys directly — a web server RCE. CISA's 3-day mandate means patching is no longer optional.
CVSS 9.8
2026
What WebPulse reported · 2 analyses
208 CVEs in One Patch Tuesday. Microsoft's Largest Ever. Including a Wormable Kernel Flaw Compared to EternalBlue. Your Web Server Has 72 Hours.
June 2026 Patch Tuesday delivered 208 CVEs (571 with Chromium bundled), 37 Critical. CVE-2026-45657 (CVSS 9.8) is a use-after-free in Windows Kernel TCP/IP that
June 16, 2026
206 CVEs in One Patch Tuesday: AI Is Finding Bugs Faster Than Humans Can Fix Them
Microsoft's June 2026 Patch Tuesday shattered records — 206 vulnerabilities, 33 critical, a wormable kernel flaw. The driver: AI-assisted vulnerability discover
June 13, 2026
Related vulnerabilities