Microsoft released KB5094127 on June 11, 2026, the June Patch Tuesday security update for Windows 10 Version 22H2. The update patches four CVEs, including CVE-2026-0234, a kernel privilege escalation flaw actively exploited in targeted attacks, and CVE-2026-0235, a remote code execution vulnerability in Remote Desktop Services.
The active exploitation of the kernel flaw combined with an RDP RCE makes this update especially urgent for enterprises. Systems with Remote Desktop exposed to networks should be patched within 72 hours, per Microsoft's recommendation.
Key takeaways
- CVE-2026-0234: kernel privilege escalation to SYSTEM, actively exploited in targeted attacks (CVSS 7.8).
- CVE-2026-0235: Remote Desktop Services RCE exploitable without authentication in some configs (CVSS 8.1).
- CVE-2026-0236: graphics component leaks memory contents, useful for ASLR bypass chaining (CVSS 5.5).
- CVE-2026-0237: WebView2 sandbox escape lets malicious content reach local resources (CVSS 6.5).
- Covers all Windows 10 22H2 editions on x64, ARM64, and 32-bit. Build 19045.4412.
Affected
KB5094127 Patches Kernel EoP and RDP RCE in Windows 10 22H2
Microsoft released KB5094127 on June 11, 2026, the June Patch Tuesday security update for Windows 10 Version 22H2. The update brings the OS to Build 19045.4412 and patches four named CVEs across the Windows Kernel, Remote Desktop Services, Windows Graphics, and Microsoft Edge WebView2, per the official Microsoft support article.
CVE-2026-0234 is a kernel privilege escalation (CVSS 7.8) actively exploited in targeted attacks. CVE-2026-0235 enables remote code execution in Remote Desktop Services (CVSS 8.1) without authentication in certain configurations. CVE-2026-0236 discloses sensitive memory via the graphics component (CVSS 5.5), useful for ASLR bypass chaining. CVE-2026-0237 lets malicious web content escape WebView2 sandbox restrictions (CVSS 6.5).
Actively Exploited Kernel Flaw and Network-Accessible RDP RCE
CVE-2026-0234 has been actively exploited. Local attackers can escalate from standard user to SYSTEM through a flaw in kernel-mode driver handling. Combined with CVE-2026-0235, which targets RDP protocol handling, attackers have both local and remote paths to full system compromise.
CVE-2026-0236 in the graphics component can leak credentials and help bypass ASLR, making it a useful building block for exploit chains. The WebView2 bypass (CVE-2026-0237) affects any application embedding WebView2 controls, expanding the attack surface beyond the browser. Systems with RDP exposed to the internet are at highest risk.
Affected Systems and Known Issues
All Windows 10 22H2 editions (Home, Pro, Enterprise, Education, IoT Enterprise) on x64, ARM64, and 32-bit architectures are affected. Prerequisite: KB5034441 (January 2026 SSU). File sizes: 847 MB (x64), 623 MB (ARM64), 592 MB (32-bit). Restart required. Supersedes KB5093845 (May 2026).
Known issues
Third-party antivirus may flag updated system files. RDP sessions may briefly disconnect during the first post-update restart. WDAG policies may need reapplication. Legacy WebView2 apps may show compatibility warnings.
Timeline
Impact & actions
Four security vulnerabilities in Windows 10 22H2 including an actively exploited kernel EoP, an RDP RCE, a graphics info disclosure useful for ASLR bypass, and a WebView2 sandbox escape.
Security: CVE-2026-0234 (CVSS 7.8) is actively exploited for SYSTEM-level escalation. CVE-2026-0235 (CVSS 8.1) enables unauthenticated RDP-based RCE in certain configurations.
Recommended actions · Immediate urgency
- 1Install KB5094127 within 72 hours due to active exploitation.
- 2Verify Build 19045.4412 after installation.
- 3Review and restrict RDP exposure on all Windows 10 systems.
- 4Update applications using WebView2 to the latest runtime.
Technical details
- CVEs
- CVE-2026-0234, CVE-2026-0235, CVE-2026-0236, CVE-2026-0237
- CVSS
- 8.1
- Exploitation
- Exploited in the wild
- Attack vector
- Local (CVE-2026-0234), Network (CVE-2026-0235)
- Affected versions
- Windows 10 22H2 Build 19045.x (all builds before 19045.4412)
- Patched versions
- Windows 10 22H2 Build 19045.4412
Mitigations
- Install KB5094127 immediately.
- Restrict RDP access via firewall or VPN for internet-facing systems.
- Update WebView2 runtime in applications using embedded controls.
Response
Vendor
FAQ
What does KB5094127 fix?
KB5094127 patches CVE-2026-0234 (kernel privilege escalation, CVSS 7.8, actively exploited), CVE-2026-0235 (RDP RCE, CVSS 8.1), CVE-2026-0236 (graphics info disclosure, CVSS 5.5), and CVE-2026-0237 (WebView2 sandbox bypass, CVSS 6.5). It also improves WDAG container security.
Which systems need KB5094127?
All Windows 10 Version 22H2 editions (Home, Pro, Enterprise, Education, IoT Enterprise) on x64, ARM64, and 32-bit architectures. Build 19045 systems running any previous cumulative update.
Is any vulnerability actively exploited?
Yes. Microsoft confirms CVE-2026-0234 (kernel privilege escalation) has been observed in targeted attacks. This makes immediate deployment critical.
Are there known issues?
Known issues: antivirus false positives on updated files, brief RDP disconnection during first restart, WDAG policy reapplication needed, and compatibility warnings in legacy WebView2 apps.
The bottom line
KB5094127 patches four CVEs in Windows 10 22H2: an actively exploited kernel privilege escalation, an RDP remote code execution flaw, a graphics info disclosure, and a WebView2 sandbox escape. It updates the OS to Build 19045.4412.
What happens next
What to do






