# Microsoft patches five CVEs in June updates

Published: 2026-06-22 · Severity: medium
Canonical: https://vorant.io/reports/42ab2311-bf48-582b-8e73-c3199366bfd7/microsoft-patches-five-cves-in-june-updates

> Microsoft released patches for five vulnerabilities affecting GitHub Copilot Chat, OpenSSL, and Perl-DBI components, enabling confidentiality breaches.

The French national cybersecurity agency CERT-FR has published an advisory detailing multiple vulnerabilities discovered in Microsoft products. The flaws affect GitHub Copilot Chat versions prior to 1.123.2, as well as azl3 openssl and perl-DBI packages in specific version ranges. The vulnerabilities enable attackers to compromise data confidentiality, with additional unspecified security impacts noted by the vendor.

Five CVE identifiers have been assigned to these vulnerabilities: CVE-2026-50519, CVE-2026-34183, CVE-2026-42768, CVE-2026-45446, and CVE-2026-9698. Microsoft issued security bulletins between June 9 and June 17, 2026, addressing these issues. Organizations are advised to consult the vendor's security bulletins and apply the available patches to mitigate the risks.

The advisory provides limited technical detail beyond the affected version ranges and impact categories. The presence of OpenSSL and Perl-DBI components suggests potential supply chain or dependency issues within Microsoft's ecosystem. Organizations using GitHub Copilot Chat or systems with the affected library versions should prioritize patching.

## Mentioned in this report

- Vulnerabilities: CVE-2026-34183, CVE-2026-42768, CVE-2026-45446, CVE-2026-50519, CVE-2026-9698

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0792

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/42ab2311-bf48-582b-8e73-c3199366bfd7/microsoft-patches-five-cves-in-june-updates.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
