Patch Tuesday: June 2026 (Expel’s version)
ID: 0a2236ef-f2ac-5993-bd04-f0da80a861c1
STIX ID: report--0a2236ef-f2ac-5993-bd04-f0da80a861c1
Feed Name: Expel Blog
This Patch Tuesday bulletin details 204 CVEs including multiple publicly disclosed zero-days (notably HTTP.sys DoS CVE-2026-49160, Remote Desktop Client RCE CVE-2026-42985, HTTP.sys RCE CVE-2026-47291, CTFMON EoP CVE-2026-45586, and a BitLocker bypass CVE-2026-50507) and emphasizes a cluster of Linux page-cache vulnerabilities—Copy Fail (CVE-2026-31431), Dirty Frag (CVE-2026-43284/CVE-2026-43500), and Fragnesia (CVE-2026-46300)—that affect many Linux systems, have public PoCs, and are confirmed exploited in the wild (including root compromises of EC2 hosts); the advisory urges immediate patching and prioritization of these issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
