VYPR
AI Brief2026-06-16· generated Jun 16, 2026

Microsoft Patch Tuesday Leads June Wave

Microsoft flags a critical VS Code privilege escalation as Patch Tuesday leads, while Apache ActiveMQ Artemis, Adobe ColdFusion, and Netty ship emergency patches.

CVE-2026-47281 in Microsoft Visual Studio Code tops Patch Tuesday with a network-based privilege escalation rated critical, bundled among 200+ fixes that include six actively exploited zero-days (three reported publicly by Microsoft plus three additional zero-days noted by researchers). An unauthenticated attacker can trigger the improper input validation flaw remotely over the network to elevate privileges, making it a priority for enterprise environments where VS Code is widely deployed for development. As BleepingComputer reported, Microsoft classified the bug as "Exploitation More Likely" in its Security Response Center assessment. The Rapid7 analysis (June 2026 Patch Tuesday) flags this alongside several other critical-rated issues as needing immediate attention across Azure, Office, and Windows components.

CVE-2026-27446 is a critical unauthenticated remote code execution flaw in Apache ActiveMQ Artemis (formerly Apache Artemis) affecting the Core federation protocol — an attacker can force a target broker to establish an outbound connection to an attacker-controlled broker without any authentication, enabling message interception, broker compromise, and lateral movement within messaging infrastructures. The vulnerability carries a CVSS 9.8 with EPSS 0.08 (moderate exploitation likelihood). The flaw was also highlighted in a CISA ICS advisory affecting Siemens Opcenter RDnL, which embeds ActiveMQ Artemis, indicating industrial control system exposure. Organizations running ActiveMQ or Artemis in DMZs or internet-facing topologies should prioritize patching immediately.

Adobe ColdFusion shipped a batch of four high-severity fixes (CVE-2026-47928, CVE-2026-47929, CVE-2026-47931, CVE-2026-47932) that collectively enable unauthenticated and authenticated remote code execution, path traversal leading to security feature bypass, and authorization bypass — all impacting ColdFusion 2023.19, 2025.8, and earlier. CVE-2026-47928 (CVSS 9.6) and CVE-2026-47931 require no user interaction, making them wormable in web-facing ColdFusion deployments. CVE-2026-47932 (path traversal) and CVE-2026-47929 (incorrect authorization for high-privileged attackers) broaden the attack surface. As Vypr Intelligence noted, these were part of a 25-vulnerability Adobe disclosure across multiple products. ColdFusion servers are a frequent ransomware target — any internet-exposed instance should be patched urgently.

Netty disclosed a cluster of high-severity vulnerabilities spanning DNS bailiwick bypass, IPv6 subnet rule circumvention, and memory leaks across Redis, HAProxy, and HTTP/2 codecs. CVE-2026-47691 and CVE-2026-45674 (both CVSS 8.7) allow an attacker to inject forged DNS records that bypass Netty's origin validation for NS and CNAME records respectively, enabling DNS cache poisoning in any application using Netty's DNS resolver. CVE-2026-44249 (CVSS 8.1) lets an attacker bypass IPv6 subnet access control rules via incorrect masking. As Vypr Intelligence reported, these were part of 12 security fixes released together in Netty versions 4.1.135.Final and 4.2.15.Final. Netty underpins countless Java and Kotlin frameworks (Spring, Play, Finagle, etc.) — teams should audit their dependency trees and upgrade to the patched releases.

GitLab EE patched CVE-2026-10087 (CVSS 8.7), an issue where an authenticated developer-role user could gain unauthorized access under certain conditions, as part of a broader 12-CVE security release across versions 19.0.2, 18.11.5, and 18.10.8. The official GitLab release notes and Vypr Intelligence's coverage indicate two critical account takeover bugs were among the dozen fixes, alongside service desk impersonation vulnerabilities and authentication bypasses. Self-managed GitLab instances are especially at risk given the delay between disclosure and admin-applied upgrades — teams should prioritize patching within the maintenance window.

Router firmware and OT/IoT vulnerabilities round out the day's high-severity landscape. CVE-2026-31195 and CVE-2026-31196 (both CVSS 8.8) are unauthenticated OS command injection flaws in the ping and traceroute diagnostic handlers of the ALTICE LABS / SFR France GR140DG Fibre Router (firmware versions 3GN8020801R13 through 3GN8020803R0A) — the router's /bin/httpd_clientside binary passes unsanitized user input directly to a shell. Separately, the unmaintained Trippo Responsive FileManager (CVE-2026-5482, CVSS pending but Critical) allows unauthenticated arbitrary file upload via dialog.php, enabling full remote code execution with no patch available. The OTRS SQL injection (CVE-2026-48188, CVSS 9.1) targets MySQL/MariaDB-backed installations. The jmespath.rb flaw (CVE-2022-32511, CVSS 9.8) allows unsafe JSON deserialization — old but still unpatched in many Ruby environments.

Critical infrastructure and embedded flaws include CVE-2026-54410 (nanoMODBUS v1.23.0, CVSS 8.6), an off-by-one buffer overflow in recv_msg_header() that lets an unauthenticated attacker corrupt the Modbus/TCP server heap; CVE-2026-54413 (iso14229 v0.9.0, CVSS 8.2), an integer underflow and OOB read in the UDS SecurityAccess handler; and CVE-2026-54412 (MQTT-C v1.1.6, CVSS 8.2), a heap OOB read and integer underflow via malicious broker responses. These three libraries are widely embedded in automotive ECU diagnostics, industrial PLCs, and IoT sensor gateways — patching will require firmware updates from OEMs rather than end-user fixes. CVE-2026-41157 (Chrome GPU GLES OOB write, CVSS 9.8) and CVE-2024-39011 (ChargeOver redoc prototype pollution, CVSS 9.8) round out the list, with the Chrome GPU driver bug enabling full browser compromise through crafted WebGPU content.

Synthesized by Vypr AI
Microsoft Patch Tuesday Leads June Wave · VYPR