Security advisoryView advisory
MicrosoftCriticalResolved

Microsoft June 2026 Patch Tuesday: KB5094127 Fixes Actively Exploited Kernel Flaw in Windows 10 22H2

The June 2026 Patch Tuesday update for Windows 10 22H2 patches a kernel privilege escalation (CVE-2026-0234), an RDP remote code execution flaw (CVE-2026-0235), a graphics info disclosure, and a WebView2 sandbox escape.

Emanuel De AlmeidaJun 12, 2026, 12:30 AM3 min read
Severity
Critical
Status
Resolved
Entity
Microsoft Windows 10 Version 22H2
Confirmed by
Microsoft Support (official KB article)

Microsoft released KB5094127 on June 11, 2026, the June Patch Tuesday security update for Windows 10 Version 22H2. The update patches four CVEs, including CVE-2026-0234, a kernel privilege escalation flaw actively exploited in targeted attacks, and CVE-2026-0235, a remote code execution vulnerability in Remote Desktop Services.

The active exploitation of the kernel flaw combined with an RDP RCE makes this update especially urgent for enterprises. Systems with Remote Desktop exposed to networks should be patched within 72 hours, per Microsoft's recommendation.

Key takeaways

  • CVE-2026-0234: kernel privilege escalation to SYSTEM, actively exploited in targeted attacks (CVSS 7.8).
  • CVE-2026-0235: Remote Desktop Services RCE exploitable without authentication in some configs (CVSS 8.1).
  • CVE-2026-0236: graphics component leaks memory contents, useful for ASLR bypass chaining (CVSS 5.5).
  • CVE-2026-0237: WebView2 sandbox escape lets malicious content reach local resources (CVSS 6.5).
  • Covers all Windows 10 22H2 editions on x64, ARM64, and 32-bit. Build 19045.4412.

Affected

Vendors
Microsoft
Products
Windows 10 Version 22H2
CVEs
CVE-2026-0234CVE-2026-0235CVE-2026-0236CVE-2026-0237

KB5094127 Patches Kernel EoP and RDP RCE in Windows 10 22H2

Microsoft released KB5094127 on June 11, 2026, the June Patch Tuesday security update for Windows 10 Version 22H2. The update brings the OS to Build 19045.4412 and patches four named CVEs across the Windows Kernel, Remote Desktop Services, Windows Graphics, and Microsoft Edge WebView2, per the official Microsoft support article.

CVE-2026-0234 is a kernel privilege escalation (CVSS 7.8) actively exploited in targeted attacks. CVE-2026-0235 enables remote code execution in Remote Desktop Services (CVSS 8.1) without authentication in certain configurations. CVE-2026-0236 discloses sensitive memory via the graphics component (CVSS 5.5), useful for ASLR bypass chaining. CVE-2026-0237 lets malicious web content escape WebView2 sandbox restrictions (CVSS 6.5).

Actively Exploited Kernel Flaw and Network-Accessible RDP RCE

CVE-2026-0234 has been actively exploited. Local attackers can escalate from standard user to SYSTEM through a flaw in kernel-mode driver handling. Combined with CVE-2026-0235, which targets RDP protocol handling, attackers have both local and remote paths to full system compromise.

CVE-2026-0236 in the graphics component can leak credentials and help bypass ASLR, making it a useful building block for exploit chains. The WebView2 bypass (CVE-2026-0237) affects any application embedding WebView2 controls, expanding the attack surface beyond the browser. Systems with RDP exposed to the internet are at highest risk.

Affected Systems and Known Issues

All Windows 10 22H2 editions (Home, Pro, Enterprise, Education, IoT Enterprise) on x64, ARM64, and 32-bit architectures are affected. Prerequisite: KB5034441 (January 2026 SSU). File sizes: 847 MB (x64), 623 MB (ARM64), 592 MB (32-bit). Restart required. Supersedes KB5093845 (May 2026).

Known issues

Third-party antivirus may flag updated system files. RDP sessions may briefly disconnect during the first post-update restart. WDAG policies may need reapplication. Legacy WebView2 apps may show compatibility warnings.

Timeline

Jun 11, 2026
KB5094127 released (Patch Tuesday)Microsoft releases KB5094127 as part of the June 2026 Patch Tuesday cycle for Windows 10 22H2, patching an actively exploited kernel flaw.

Impact & actions

Four security vulnerabilities in Windows 10 22H2 including an actively exploited kernel EoP, an RDP RCE, a graphics info disclosure useful for ASLR bypass, and a WebView2 sandbox escape.

Security: CVE-2026-0234 (CVSS 7.8) is actively exploited for SYSTEM-level escalation. CVE-2026-0235 (CVSS 8.1) enables unauthenticated RDP-based RCE in certain configurations.

Recommended actions · Immediate urgency

  1. 1Install KB5094127 within 72 hours due to active exploitation.
  2. 2Verify Build 19045.4412 after installation.
  3. 3Review and restrict RDP exposure on all Windows 10 systems.
  4. 4Update applications using WebView2 to the latest runtime.

Technical details

CVEs
CVE-2026-0234, CVE-2026-0235, CVE-2026-0236, CVE-2026-0237
CVSS
8.1
Exploitation
Exploited in the wild
Attack vector
Local (CVE-2026-0234), Network (CVE-2026-0235)
Affected versions
Windows 10 22H2 Build 19045.x (all builds before 19045.4412)
Patched versions
Windows 10 22H2 Build 19045.4412

Mitigations

  • Install KB5094127 immediately.
  • Restrict RDP access via firewall or VPN for internet-facing systems.
  • Update WebView2 runtime in applications using embedded controls.

Response

Vendor

Microsoft recommends deploying this update within 72 hours due to active exploitation of CVE-2026-0234. Systems with RDP exposed to networks should be prioritized.
Patch / advisory

FAQ

What does KB5094127 fix?

KB5094127 patches CVE-2026-0234 (kernel privilege escalation, CVSS 7.8, actively exploited), CVE-2026-0235 (RDP RCE, CVSS 8.1), CVE-2026-0236 (graphics info disclosure, CVSS 5.5), and CVE-2026-0237 (WebView2 sandbox bypass, CVSS 6.5). It also improves WDAG container security.

Which systems need KB5094127?

All Windows 10 Version 22H2 editions (Home, Pro, Enterprise, Education, IoT Enterprise) on x64, ARM64, and 32-bit architectures. Build 19045 systems running any previous cumulative update.

Is any vulnerability actively exploited?

Yes. Microsoft confirms CVE-2026-0234 (kernel privilege escalation) has been observed in targeted attacks. This makes immediate deployment critical.

Are there known issues?

Known issues: antivirus false positives on updated files, brief RDP disconnection during first restart, WDAG policy reapplication needed, and compatibility warnings in legacy WebView2 apps.

The bottom line

KB5094127 patches four CVEs in Windows 10 22H2: an actively exploited kernel privilege escalation, an RDP remote code execution flaw, a graphics info disclosure, and a WebView2 sandbox escape. It updates the OS to Build 19045.4412.

What happens next

The companion updates KB5094126 (Windows 11) and KB5094123 (Windows 10 1809) address related vulnerabilities from the same June 2026 Patch Tuesday cycle.

What to do

Install KB5094127, verify Build 19045.4412 with winver, and check RDP configuration on exposed systems.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles