Patch Tuesday cycleJune 2026 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

June 2026 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 110 operational patch records link 392 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

110Patch recordsStable operational entries, not CVE duplicates
392Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
0Accelerated actionsNo accelerated action in this view
0Revised entriesCanonical history remains visible

June 2026 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
110 matching recordsPage 1 of 6
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Experience Manager to the fixed Adobe releaseAPSB26-56 · Updated 2026-06-09
Product and releaseAdobe Experience ManagerAEM Cloud Service (CS) Release 2026.05, 6.5 LTS Service Pack 2, 6.5 Service Pack 25
Review linked CVEs (57) No confirmed exploitation stated

Operational summary

Adobe published APSB26-56 on Patch Tuesday for Adobe Experience Manager. The bulletin links 57 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-56
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.4; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Experience Manager Forms to the fixed Adobe releaseAPSB26-57 · Updated 2026-06-09
Product and releaseAdobe Experience Manager FormsSP2, 6.5.25.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB26-57 on Patch Tuesday for Adobe Experience Manager Forms. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-57
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 9.3; Adobe priority 2

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.3
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Sampler to the fixed Adobe releaseAPSB26-60 · Updated 2026-06-09
Product and releaseAdobe Substance 3D Sampler6.0.1
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

Adobe published APSB26-60 on Patch Tuesday for Adobe Substance 3D Sampler. The bulletin links 4 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-60
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB26-64 · Updated 2026-06-09
Product and releaseAdobe ColdFusionUpdate 9, Update 20
Review linked CVEs (7) No confirmed exploitation stated

Operational summary

Adobe published APSB26-64 on Patch Tuesday for Adobe ColdFusion. The bulletin links 7 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-64
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 9.6; Adobe priority 1

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (7)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.6
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Format Plugins to the fixed Adobe releaseAPSB26-65 · Updated 2026-06-09
Product and releaseAdobe Format Plugins1.1.3
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-65 on Patch Tuesday for Adobe Format Plugins. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-65
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Acrobat Reader to the fixed Adobe releaseAPSB26-63 · Updated 2026-06-09
Product and releaseAdobe Acrobat ReaderFixed release detail requires source review
Review linked CVEs (22) No confirmed exploitation stated

Operational summary

Adobe published APSB26-63 on Patch Tuesday for Adobe Acrobat Reader. The bulletin links 22 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-63
Platform
See Adobe bulletin
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB26-58 · Updated 2026-06-09
Product and releaseAdobe InDesignID21.4, ID20.5.4
Review linked CVEs (12) No confirmed exploitation stated

Operational summary

Adobe published APSB26-58 on Patch Tuesday for Adobe InDesign. The bulletin links 12 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-58
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (12)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe InCopy to the fixed Adobe releaseAPSB26-59 · Updated 2026-06-09
Product and releaseAdobe InCopy21.4, 20.5.4
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB26-59 on Patch Tuesday for Adobe InCopy. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-59
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Dreamweaver to the fixed Adobe releaseAPSB26-62 · Updated 2026-06-09
Product and releaseAdobe Dreamweaver21.8
Review linked CVEs (5) No confirmed exploitation stated

Operational summary

Adobe published APSB26-62 on Patch Tuesday for Adobe Dreamweaver. The bulletin links 5 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-62
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.6; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (5)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.6
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Campaign Classic to the fixed Adobe releaseAPSB26-66 · Updated 2026-06-09
Product and releaseAdobe Campaign ClassicACC v7: 7.4.3 build 9396
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-66 on Patch Tuesday for Adobe Campaign Classic. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-66
Platform
Windows, Linux
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 10.0; Adobe priority 1

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 10.0
Confirmed exploitedCVSS above 9.0
AdobeUpdate Content Credentials SDK to the fixed Adobe releaseAPSB26-61 · Updated 2026-06-09
Product and releaseContent Credentials SDK@contentauth/c2pa-web@0.8.3, c2pa-v0.85.1
Review linked CVEs (8) No confirmed exploitation stated

Operational summary

Adobe published APSB26-61 on Patch Tuesday for Content Credentials SDK. The bulletin links 8 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-61
Platform
Windows, macOS, Linux, iOS, Android
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.5; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (8)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Microsoft PowerToysMSRC-2026-06-apps-release-notes · Updated 2026-06-09
Product and releaseMicrosoft PowerToysv0.99.1
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft PowerToys.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-06-apps-release-notes
Platform
Apps
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Microsoft Word for AndroidMSRC-2026-06-apps-release-notes · Updated 2026-06-09
Product and releaseMicrosoft Word for Android16.0.20131.20024
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Word for Android.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-06-apps-release-notes
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Microsoft Bing Search for AndroidMSRC-2026-06-apps-release-notes · Updated 2026-06-09
Product and releaseMicrosoft Bing Search for Android33.3
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Bing Search for Android.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-06-apps-release-notes
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 4.3
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Microsoft PC ManagerMSRC-2026-06-apps-release-notes · Updated 2026-06-09
Product and releaseMicrosoft PC Manager3.21.6.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft PC Manager.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-06-apps-release-notes
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Kubernetes ServiceMSRC-2026-06-azure-release-notes · Updated 2026-06-09
Product and releaseAzure Kubernetes Servicev0.20260213.5
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Kubernetes Service.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-06-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Stack EdgeMSRC-2026-06-azure-release-notes · Updated 2026-06-09
Product and releaseAzure Stack Edge3.3.2604.3097
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure Stack Edge.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-06-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Browser update for Microsoft Edge (Chromium-based)MSRC-2026-06-browser-release-notes · Updated 2026-06-09
Product and releaseMicrosoft Edge (Chromium-based)149.0.4022.53
Review linked CVEs (47) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 47 linked CVEs for Microsoft Edge (Chromium-based).

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-06-browser-release-notes
Platform
Browser
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools security update KB5097148KB5097148 · Updated 2026-06-09
Product and release.NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows, plus 1 more10.0.9
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for .NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5097148
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5097149KB5097149 · Updated 2026-06-09
Product and release.NET 8.0, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, plus 2 more8.0.28
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for .NET 8.0, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, plus 2 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5097149
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0