Skip to content
Vulnerability intelligence

CVE-2026-45657 — Security Advisory

June 2026 Patch Tuesday delivered 208 CVEs (571 with Chromium bundled), 37 Critical. CVE-2026-45657 (CVSS 9.8) is a use-after-free in Windows Kernel TCP/IP that requires no authentication and can self-propagate. CVE-2026-47291 (CVSS 9.8) hits HTTP.sys directly — a web server RCE. CISA's 3-day mandate means patching is no longer optional.

CVSS 9.8 2026