Patch-diff analysis of the June 2026 cumulative update (KB5094128)
| CVE | CVE-2026-45595 — Windows Mark of the Web Security Feature Bypass |
| Severity | Important, CVSS 5.4 (not actively exploited at release) |
| Fixed in | KB5094128 — Windows Server 2022 / 21H2, OS build 20348.5256 (released 2026-06-09) |
| Patched binary | windows.storage.dll (11.0/10.0.20348.5256) |