June 2026 was by far the most active month observed in our dataset to date. During the month, 1,302 unique vulnerabilities were identified across 83 applications, while vendors released 161 patched versions to address these issues. This represents a substantial increase from May, which saw 645 vulnerabilities across 80 applications and 124 released versions. Looking at the historical trend data, June stands out as a clear outlier, with the number of newly disclosed vulnerabilities more than doubling month over month while the number of affected applications remained relatively stable.
The dramatic increase in June’s vulnerability count can largely be attributed to an exceptionally active month for Chromium-based browsers and related projects. According to Google’s June security releases, Chrome 149 included 429 security fixes, while Chrome 150 included another 433 security fixes. In addition, other Chrome for Business releases in the same data set accounted for further fixes, bringing the reviewed Chrome-related total to 967 security fixes. Because Chromium fixes are inherited by multiple downstream browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, a single upstream disclosure cycle can result in hundreds of vulnerabilities being remediated across multiple products and release channels.
One notable pattern in this Chrome release is that the overwhelming majority of disclosed vulnerabilities were reported internally by Google rather than by external researchers. In this dataset of 967, more than 80% of CVEs were attributed to Google. This may indicate that Google’s internal security discovery processes are becoming significantly more effective. Given public reports that Google was among the organizations participating in Anthropic’s Mythos-related Project Glasswing initiative, AI-assisted vulnerability discovery is a plausible contributing factor. Still, the release notes do not explicitly state that Mythos was used for these findings, so this should be treated as an informed hypothesis rather than a confirmed fact. Meanwhile, Mozilla has shared concrete evidence that harnessing Claude Mythos in its pipelines has greatly increased the number of security bugs found. See the blog written by its Tech Lead and Principal Engineer. It would be a surprise if Google wasn’t doing the same.

Notable vulnerabilities in June third-party patches
While this month included hundreds of disclosed vulnerabilities, three stand out due to the combination of exploit availability and elevated Exploit Prediction Scoring System (EPSS) values.
CVE-2026-20253 is a critical Splunk Enterprise vulnerability that allows an unauthenticated attacker to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint that lacks authentication controls. The vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, and Splunk has confirmed limited real-world exploitation. It also has an elevated EPSS score of 88.17%. Organizations running vulnerable Splunk Enterprise versions should prioritize remediation immediately. More information can be found in the advisory from Splunk.
CVE-2025-6965 (EPSS: 73.50%) is a high-severity memory corruption vulnerability in SQLite that affects versions prior to 3.50.2. The flaw can occur when the number of aggregate terms exceeds the available column count, leading to a numeric truncation issue and potential memory corruption. Notably, the vulnerability was discovered by Google’s Threat Analysis Group with assistance from Google’s Big Sleep project, highlighting the growing role of AI-assisted vulnerability discovery. The vulnerability has now been fixed in various versions of Microsoft Visual Studio.
CVE-2026-11645 is a high-severity Chrome zero-day vulnerability involving an out-of-bounds read/write issue in the V8 JavaScript engine. Successful exploitation can enable arbitrary code execution through a crafted web page. Google acknowledged that an exploit exists in the wild, and the vulnerability was added to CISA’s KEV catalog. The vulnerability affects Google Chrome versions prior to 149.0.7827.103 and has been fixed in version 149.0.7827.103 and later. More information can be found on Chrome Releases.

Browser Security Updates in June 2026
Browser updates were the dominant driver of vulnerability activity during the month. Google Chrome alone accounted for 967 security fixes across seven releases, making Chromium the largest single source of disclosed vulnerabilities during the reporting period. The most significant updates were Chrome 149 and Chrome 150, which together addressed 862 security issues. Because Chromium serves as the foundation for multiple browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, many of these vulnerabilities also appeared in downstream browser releases. As a result, the vulnerability counts reported by individual Chromium-based browsers should not be treated as unique findings, but rather as evidence of how a single upstream security release can drive remediation activity across the broader browser ecosystem. Mozilla products remained comparatively stable, with Firefox releases accounting for a much smaller share of browser-related vulnerability activity.
| Browser | Vulnerabilities | Updates |
| Google Chrome | 967 | 7 |
| Microsoft Edge | 472 | 6 |
| Brave Browser | 585 | 6 |
| Mozilla Firefox | 43 | 3 |
| Mozilla Firefox 115 | 29 | 1 |
| Mozilla Firefox 140 | 29 | 1 |
| Opera One | 1 | 1 |
| Vivaldi | 163 | 4 |
| Waterfox | 29 | 1 |
Microsoft product updates included in June 2026 third-party patches
Microsoft issued security updates for several other products:
- Microsoft .NET Runtime 10.0
- Microsoft .NET Runtime 8.0
- Microsoft .NET Runtime 9.0
- Microsoft .NET SDK 10.0
- Microsoft .NET SDK 8.0
- Microsoft .NET SDK 9.0
- Microsoft 365 Apps
- Microsoft ASP.NET Core Runtime 10.0
- Microsoft ASP.NET Core Runtime 8.0
- Microsoft ASP.NET Core Runtime 9.0
- Microsoft ASP.NET Core Runtime Hosting Bundle 10.0
- Microsoft ASP.NET Core Runtime Hosting Bundle 8.0
- Microsoft ASP.NET Core Runtime Hosting Bundle 9.0
- Microsoft Edge Beta
- Microsoft Edge for Business
- Microsoft Remote Desktop
- Microsoft Visio
- Microsoft Visual Studio 2019 Enterprise
- Microsoft Visual Studio 2019 Professional
- Microsoft Visual Studio 2022 Enterprise
- Microsoft Visual Studio 2022 Professional
- Microsoft Windows Desktop Runtime 10.0
- Microsoft Windows Desktop Runtime 8.0
- Microsoft Windows Desktop Runtime 9.0
Detailed list of June third-party patches
| Product Name | Version Name | Vulnerabilities remediated |
| Adobe Acrobat DC | 26.001.21662 | 20 |
| Adobe Acrobat Reader DC | 26.001.21662 | 21 |
| Adobe Acrobat Reader DC | 26.001.21662 | 20 |
| Adobe Acrobat Reader DC – Multilingual (MUI) | 26.001.21662 | 20 |
| Apache Tomcat 10 | 10.1.56 | 6 |
| Apache Tomcat 11 | 11.0.23 | 6 |
| Apache Tomcat 9 | 9.0.119 | 6 |
| Autodesk Revit 2022 | 2022.1.8 | 1 |
| Brave Browser | 1.91.178 | 18 |
| Brave Browser | 1.91.180 | 3 |
| Brave Browser | 1.91.175 | 33 |
| Brave Browser | 1.91.171 | 74 |
| Brave Browser | 1.91.172 | 28 |
| Brave Browser | 1.91.168 | 429 |
| Brave Origin | 1.91.178 | 18 |
| Brave Origin | 1.91.180 | 3 |
| Brave Origin | 1.91.175 | 33 |
| Brave Origin | 1.91.172 | 28 |
| Brave Origin | 1.91.171 | 74 |
| Brave Origin | 1.91.168 | 429 |
| Brave Origin | 1.91.172 | 27 |
| Datadog Agent | 7.79.2 | 1 |
| Datadog Agent | 7.80.0 | 2 |
| Docker Desktop | 4.76.0.228118 | 1 |
| Docker Desktop | 4.76.0 | 1 |
| Electron | 40.10.3 | 15 |
| Electron | 41.7.2 | 12 |
| Electron | 42.4.0 | 2 |
| EnterpriseDB Corporation PostgreSQL 14 | 14.23.2 | 8 |
| EnterpriseDB Corporation PostgreSQL 15 | 15.18.2 | 8 |
| EnterpriseDB Corporation PostgreSQL 16 | 16.14.2 | 9 |
| EnterpriseDB Corporation PostgreSQL 17 | 17.10.2 | 10 |
| EnterpriseDB Corporation PostgreSQL 17 | 17.10 | 10 |
| EnterpriseDB Corporation PostgreSQL 18 | 18.4.2 | 11 |
| Erlang OTP | 29.0.2.0 | 6 |
| Erlang OTP | 28.5.0.2 | 7 |
| GoLand | 2026.1.3 | 1 |
| Google Chrome | 149.0.7827.155 | 33 |
| Google Chrome | 149.0.7827.196 | 18 |
| Google Chrome | 149.0.7827.200 | 3 |
| Google Chrome | 150.0.7871.46 | 433 |
| Google Chrome | 149.0.7827.53 | 429 |
| Google Chrome | 149.0.7827.115 | 28 |
| Google Chrome | 149.0.7827.102 | 74 |
| Google Chrome | 150.0.7871.46 | 382 |
| Google Chrome | 149.0.7827.156 | 33 |
| Google Chrome | 149.0.7827.197 | 18 |
| Google Chrome | 149.0.7827.201 | 3 |
| Google Chrome | 149.0.7827.54 | 429 |
| Google Chrome | 149.0.7827.103 | 74 |
| Google Chrome for Business | 149.0.7827.156 | 33 |
| Google Chrome for Business | 149.0.7827.197 | 18 |
| Google Chrome for Business | 149.0.7827.201 | 3 |
| Google Chrome for Business | 150.0.7871.47 | 382 |
| Google Chrome for Business | 149.0.7827.54 | 429 |
| Google Chrome for Business | 149.0.7827.115 | 28 |
| Google Chrome for Business | 149.0.7827.103 | 74 |
| Google Chrome for Consumers | 149.0.7827.156 | 33 |
| Google Chrome for Consumers | 149.0.7827.197 | 18 |
| Google Chrome for Consumers | 149.0.7827.201 | 3 |
| Google Chrome for Consumers | 150.0.7871.47 | 382 |
| Google Chrome for Consumers | 149.0.7827.115 | 28 |
| Google Chrome for Education | 149.0.7827.156 | 33 |
| Google Chrome for Education | 149.0.7827.201 | 3 |
| Google Chrome for Education | 149.0.7827.197 | 18 |
| Google Chrome for Education | 150.0.7871.47 | 382 |
| Google Chrome for Education | 149.0.7827.54 | 429 |
| Google Chrome for Education | 149.0.7827.115 | 28 |
| Google Chrome for Education | 149.0.7827.103 | 74 |
| Google Chrome for Education | 149.0.7827.54 | 428 |
| Google Go Programming Language | 1.25.11 | 3 |
| Google Go Programming Language | 1.26.4 | 3 |
| HeidiSQL | 12.18.0.7304 | 1 |
| ImageMagick | 7.1.2.26 | 9 |
| ImageMagick | 7.1.2.25 | 6 |
| Microsoft .NET Runtime 10.0 | 10.0.9 | 3 |
| Microsoft .NET Runtime 8.0 | 8.0.28.36114 | 3 |
| Microsoft .NET Runtime 8.0 | 8.0.28 | 3 |
| Microsoft .NET Runtime 9.0 | 9.0.17 | 3 |
| Microsoft .NET SDK 10.0 | 10.0.301 | 3 |
| Microsoft .NET SDK 8.0 | 8.4.2226.27003 | 3 |
| Microsoft .NET SDK 8.0 | 8.0.422 | 3 |
| Microsoft .NET SDK 9.0 | 9.0.315 | 3 |
| Microsoft 365 Apps | 2508 (Build 16.0.19127.20678) | 29 |
| Microsoft ASP.NET Core Runtime 10.0 | 10.0.9 | 3 |
| Microsoft ASP.NET Core Runtime 8.0 | 8.0.28.26269 | 3 |
| Microsoft ASP.NET Core Runtime 8.0 | 8.0.28 | 3 |
| Microsoft ASP.NET Core Runtime 9.0 | 9.0.17 | 3 |
| Microsoft ASP.NET Core Runtime Hosting Bundle 10.0 | 10.0.9 | 3 |
| Microsoft ASP.NET Core Runtime Hosting Bundle 8.0 | 8.0.28.26269 | 3 |
| Microsoft ASP.NET Core Runtime Hosting Bundle 9.0 | 9.0.17 | 3 |
| Microsoft Edge Beta | 149.0.4022.52 | 360 |
| Microsoft Edge Beta | 149.0.4022.62 | 49 |
| Microsoft Edge Beta | 149.0.4022.62 | 53 |
| Microsoft Edge for Business | 149.0.4022.96 | 13 |
| Microsoft Edge for Business | 149.0.4022.98 | 1 |
| Microsoft Edge for Business | 149.0.4022.80 | 28 |
| Microsoft Edge for Business | 149.0.4022.52 | 360 |
| Microsoft Edge for Business | 149.0.4022.62 | 49 |
| Microsoft Edge for Business | 149.0.4022.69 | 21 |
| Microsoft Edge for Business | 149.0.4022.96 | 12 |
| Microsoft Edge for Business | 149.0.4022.69 | 20 |
| Microsoft Edge for Business | 149.0.4022.62 | 53 |
| Microsoft Remote Desktop | 1.2.7214.0 | 9 |
| Microsoft Visio | 2605 (Build 16.0.20026.20166) | 29 |
| Microsoft Visual Studio 2019 Enterprise | 16.11.37327.17 | 1 |
| Microsoft Visual Studio 2019 Professional | 16.11.37327.17 | 1 |
| Microsoft Visual Studio 2022 Enterprise | 17.14.37328.6 | 4 |
| Microsoft Visual Studio 2022 Enterprise | 17.12.37328.8 | 4 |
| Microsoft Visual Studio 2022 Professional | 17.14.37328.6 | 4 |
| Microsoft Visual Studio 2022 Professional | 17.12.37328.8 | 4 |
| Microsoft Windows Desktop Runtime 10.0 | 10.0.9 | 3 |
| Microsoft Windows Desktop Runtime 8.0 | 8.0.28.36119 | 3 |
| Microsoft Windows Desktop Runtime 9.0 | 9.0.17 | 3 |
| MongoDB Community Edition | 8.2.11 | 1 |
| MongoDB Community Edition | 8.3.4 | 1 |
| MongoDB Community Edition 7.0 | 7.0.35 | 10 |
| MongoDB Community Edition 7.0 | 7.0.37 | 1 |
| MongoDB Community Edition 8.0 | 8.0.24 | 11 |
| MongoDB Community Edition 8.0 | 8.0.26 | 1 |
| MongoDB Enterprise Edition | 8.2.11 | 1 |
| MongoDB Enterprise Edition | 8.3.4 | 1 |
| MongoDB Enterprise Edition 7.0 | 7.0.35 | 10 |
| MongoDB Enterprise Edition 7.0 | 7.0.37 | 1 |
| MongoDB Enterprise Edition 8.0 | 8.0.24 | 11 |
| MongoDB Enterprise Edition 8.0 | 8.0.26 | 1 |
| Mozilla Firefox | 152.0 | 40 |
| Mozilla Firefox | 152.0.4 | 1 |
| Mozilla Firefox | 151.0.3 | 2 |
| Mozilla Firefox ESR 115 | 115.37.0 | 29 |
| Mozilla Firefox ESR 140 | 140.12.0 | 29 |
| Mozilla Thunderbird | 152.0 | 40 |
| Mozilla Thunderbird ESR 140 | 140.12.0 | 29 |
| nginx | 1.31.2 | 3 |
| nginx | 1.30.3 | 2 |
| Node.js | 26.3.1 | 11 |
| Node.js 22 LTS | 22.23.0 | 11 |
| Node.js 24 | 24.17.0 | 11 |
| Notepad++ | 8.9.6.4 | 1 |
| OpenSSL | 3.0.21 | 10 |
| OpenSSL | 3.4.6 | 14 |
| OpenSSL | 3.5.7 | 15 |
| OpenSSL | 3.6.3 | 17 |
| OpenSSL | 4.0.1 | 18 |
| OpenSSL Light | 3.0.21 | 10 |
| OpenSSL Light | 3.4.6 | 14 |
| OpenSSL Light | 3.5.7 | 15 |
| OpenSSL Light | 3.6.3 | 17 |
| OpenSSL Light | 4.0.1 | 18 |
| Opera One | 132.0.5905.37 | 1 |
| Pale Moon | 34.3.1 | 3 |
| pgAdmin 4 | 9.16 | 8 |
| Podman Desktop | 1.28.2 | 11 |
| Python 3.13 | 3.13.14 | 3 |
| Python 3.14 | 3.14.6 | 2 |
| Rancher Desktop | 1.23.0 | 5 |
| Rancher Desktop | 1.23.1 | 5 |
| Splunk Enterprise | 10.0.7 | 2 |
| Splunk Enterprise | 10.2.4 | 32 |
| Splunk Enterprise 9.3 | 9.3.13 | 2 |
| Splunk Enterprise 9.4 | 9.4.12 | 2 |
| TeamCity | 2026.1.2 | 4 |
| TortoiseGit | 2.19.0.0 | 1 |
| Vivaldi | 8.0.4033.50 | 33 |
| Vivaldi | 8.0.4033.54 | 18 |
| Vivaldi | 8.0.4033.48 | 28 |
| Vivaldi | 8.0.4033.46 | 74 |
| Waterfox | 6.6.15 | 29 |
Improve your patching and application delivery
Modernize how you manage patches and applications across your environment with Right Click Tools Patching and Application Workspace.