BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
June 2026 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 110 operational patch records link 392 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
June 2026 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe Experience Manager to the fixed Adobe releaseAPSB26-56 · Updated 2026-06-09Product and releaseAdobe Experience ManagerAEM Cloud Service (CS) Release 2026.05, 6.5 LTS Service Pack 2, 6.5 Service Pack 25Review linked CVEs (57) No confirmed exploitation stated
Operational summary
Adobe published APSB26-56 on Patch Tuesday for Adobe Experience Manager. The bulletin links 57 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-56
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.4; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
- CVE-2026-34692
- CVE-2026-47935
- CVE-2026-47936
- CVE-2026-47939
- CVE-2026-47941
- CVE-2026-47942
- CVE-2026-47943
- CVE-2026-47944
- CVE-2026-47945
- CVE-2026-47946
- CVE-2026-47947
- CVE-2026-47948
- CVE-2026-47949
- CVE-2026-47950
- CVE-2026-47951
- CVE-2026-47953
- CVE-2026-47954
- CVE-2026-47956
- CVE-2026-47957
- CVE-2026-47958
- CVE-2026-47962
- CVE-2026-47966
- CVE-2026-47970
- CVE-2026-47972
- CVE-2026-47973
- CVE-2026-47974
- CVE-2026-47975
- CVE-2026-47977
- CVE-2026-47978
- CVE-2026-47980
- CVE-2026-47981
- CVE-2026-47982
- CVE-2026-47983
- CVE-2026-47985
- CVE-2026-47986
- CVE-2026-47987
- CVE-2026-47989
- CVE-2026-47990
- CVE-2026-47991
- CVE-2026-47993
- CVE-2026-48250
- CVE-2026-48251
- CVE-2026-48256
- CVE-2026-48258
- CVE-2026-48264
- CVE-2026-48265
- CVE-2026-48266
- CVE-2026-48268
- CVE-2026-48271
- CVE-2026-48280
- CVE-2026-48288
- CVE-2026-48289
- CVE-2026-48297
- CVE-2026-48299
- CVE-2026-48300
- CVE-2026-48301
- CVE-2026-48304
AdobeUpdate Adobe Experience Manager Forms to the fixed Adobe releaseAPSB26-57 · Updated 2026-06-09Product and releaseAdobe Experience Manager FormsSP2, 6.5.25.0Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB26-57 on Patch Tuesday for Adobe Experience Manager Forms. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-57
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.3; Adobe priority 2
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Sampler to the fixed Adobe releaseAPSB26-60 · Updated 2026-06-09Product and releaseAdobe Substance 3D Sampler6.0.1Review linked CVEs (4) No confirmed exploitation stated
Operational summary
Adobe published APSB26-60 on Patch Tuesday for Adobe Substance 3D Sampler. The bulletin links 4 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-60
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB26-64 · Updated 2026-06-09Product and releaseAdobe ColdFusionUpdate 9, Update 20Review linked CVEs (7) No confirmed exploitation stated
Operational summary
Adobe published APSB26-64 on Patch Tuesday for Adobe ColdFusion. The bulletin links 7 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-64
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.6; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Format Plugins to the fixed Adobe releaseAPSB26-65 · Updated 2026-06-09Product and releaseAdobe Format Plugins1.1.3Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB26-65 on Patch Tuesday for Adobe Format Plugins. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-65
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Acrobat Reader to the fixed Adobe releaseAPSB26-63 · Updated 2026-06-09Product and releaseAdobe Acrobat ReaderFixed release detail requires source reviewReview linked CVEs (22) No confirmed exploitation stated
Operational summary
Adobe published APSB26-63 on Patch Tuesday for Adobe Acrobat Reader. The bulletin links 22 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-63
- Platform
- See Adobe bulletin
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
- CVE-2026-47911
- CVE-2026-47912
- CVE-2026-47913
- CVE-2026-47914
- CVE-2026-47915
- CVE-2026-47916
- CVE-2026-47917
- CVE-2026-47918
- CVE-2026-47919
- CVE-2026-47920
- CVE-2026-47921
- CVE-2026-47923
- CVE-2026-47924
- CVE-2026-47925
- CVE-2026-47926
- CVE-2026-47937
- CVE-2026-47952
- CVE-2026-47955
- CVE-2026-47959
- CVE-2026-47961
- CVE-2026-47965
- CVE-2026-48373
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB26-58 · Updated 2026-06-09Product and releaseAdobe InDesignID21.4, ID20.5.4Review linked CVEs (12) No confirmed exploitation stated
Operational summary
Adobe published APSB26-58 on Patch Tuesday for Adobe InDesign. The bulletin links 12 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-58
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InCopy to the fixed Adobe releaseAPSB26-59 · Updated 2026-06-09Product and releaseAdobe InCopy21.4, 20.5.4Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB26-59 on Patch Tuesday for Adobe InCopy. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-59
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Dreamweaver to the fixed Adobe releaseAPSB26-62 · Updated 2026-06-09Product and releaseAdobe Dreamweaver21.8Review linked CVEs (5) No confirmed exploitation stated
Operational summary
Adobe published APSB26-62 on Patch Tuesday for Adobe Dreamweaver. The bulletin links 5 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-62
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 8.6; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Campaign Classic to the fixed Adobe releaseAPSB26-66 · Updated 2026-06-09Product and releaseAdobe Campaign ClassicACC v7: 7.4.3 build 9396Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB26-66 on Patch Tuesday for Adobe Campaign Classic. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-66
- Platform
- Windows, Linux
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 10.0; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Content Credentials SDK to the fixed Adobe releaseAPSB26-61 · Updated 2026-06-09Product and releaseContent Credentials SDK@contentauth/c2pa-web@0.8.3, c2pa-v0.85.1Review linked CVEs (8) No confirmed exploitation stated
Operational summary
Adobe published APSB26-61 on Patch Tuesday for Content Credentials SDK. The bulletin links 8 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-61
- Platform
- Windows, macOS, Linux, iOS, Android
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.5; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Apps update for Microsoft PowerToysMSRC-2026-06-apps-release-notes · Updated 2026-06-09Product and releaseMicrosoft PowerToysv0.99.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft PowerToys.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-06-apps-release-notes
- Platform
- Apps
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Apps update for Microsoft Word for AndroidMSRC-2026-06-apps-release-notes · Updated 2026-06-09Product and releaseMicrosoft Word for Android16.0.20131.20024Review linked CVEs (3) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Word for Android.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-06-apps-release-notes
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Apps update for Microsoft Bing Search for AndroidMSRC-2026-06-apps-release-notes · Updated 2026-06-09Product and releaseMicrosoft Bing Search for Android33.3Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Bing Search for Android.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-06-apps-release-notes
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Apps update for Microsoft PC ManagerMSRC-2026-06-apps-release-notes · Updated 2026-06-09Product and releaseMicrosoft PC Manager3.21.6.0Review linked CVEs (3) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft PC Manager.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-06-apps-release-notes
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Kubernetes ServiceMSRC-2026-06-azure-release-notes · Updated 2026-06-09Product and releaseAzure Kubernetes Servicev0.20260213.5Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Kubernetes Service.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-06-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Stack EdgeMSRC-2026-06-azure-release-notes · Updated 2026-06-09Product and releaseAzure Stack Edge3.3.2604.3097Review linked CVEs (2) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure Stack Edge.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-06-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Browser update for Microsoft Edge (Chromium-based)MSRC-2026-06-browser-release-notes · Updated 2026-06-09Product and releaseMicrosoft Edge (Chromium-based)149.0.4022.53Review linked CVEs (47) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 47 linked CVEs for Microsoft Edge (Chromium-based).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-06-browser-release-notes
- Platform
- Browser
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
- CVE-2026-10883
- CVE-2026-10892
- CVE-2026-10923
- CVE-2026-10929
- CVE-2026-10934
- CVE-2026-10953
- CVE-2026-10959
- CVE-2026-10967
- CVE-2026-10984
- CVE-2026-11007
- CVE-2026-11010
- CVE-2026-11012
- CVE-2026-11019
- CVE-2026-11029
- CVE-2026-11034
- CVE-2026-11035
- CVE-2026-11045
- CVE-2026-11064
- CVE-2026-11065
- CVE-2026-11072
- CVE-2026-11077
- CVE-2026-11080
- CVE-2026-11082
- CVE-2026-11097
- CVE-2026-11108
- CVE-2026-11119
- CVE-2026-11127
- CVE-2026-11131
- CVE-2026-11145
- CVE-2026-11148
- CVE-2026-11163
- CVE-2026-11167
- CVE-2026-11172
- CVE-2026-11175
- CVE-2026-11178
- CVE-2026-11188
- CVE-2026-11215
- CVE-2026-11226
- CVE-2026-11247
- CVE-2026-11263
- CVE-2026-11270
- CVE-2026-11278
- CVE-2026-11287
- CVE-2026-11290
- CVE-2026-11291
- CVE-2026-11295
- CVE-2026-11297
MicrosoftDeploy Microsoft Developer Tools security update KB5097148KB5097148 · Updated 2026-06-09Product and release.NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows, plus 1 more10.0.9Review linked CVEs (3) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 3 linked CVEs for .NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows, plus 1 more.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5097148
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5097149KB5097149 · Updated 2026-06-09Product and release.NET 8.0, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, plus 2 more8.0.28Review linked CVEs (3) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 3 linked CVEs for .NET 8.0, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, plus 2 more.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5097149
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.