{"id":18394,"date":"2026-08-13T01:06:27","date_gmt":"2026-08-12T18:06:27","guid":{"rendered":"https:\/\/droneth.or.th\/?p=18394"},"modified":"2026-08-13T01:06:27","modified_gmt":"2026-08-12T18:06:27","slug":"microsoft-june-2026-patch-tuesday-200-vulnerabilities-zero-day","status":"publish","type":"post","link":"https:\/\/droneth.or.th\/zh\/microsoft-june-2026-patch-tuesday-200-vulnerabilities-zero-day\/","title":{"rendered":"Microsoft Patch Tuesday \u0e21\u0e34\u0e16\u0e38\u0e19\u0e32\u0e22\u0e19 2026: \u0e27\u0e34\u0e40\u0e04\u0e23\u0e32\u0e30\u0e2b\u0e4c 200 \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e41\u0e25\u0e30 6 Zero-Day"},"content":{"rendered":"<p>\u0e27\u0e31\u0e19\u0e17\u0e35\u0e48 9 \u0e21\u0e34\u0e16\u0e38\u0e19\u0e32\u0e22\u0e19 2026 Microsoft \u0e1b\u0e25\u0e48\u0e2d\u0e22 security update \u0e02\u0e19\u0e32\u0e14\u0e43\u0e2b\u0e0d\u0e48\u0e17\u0e35\u0e48\u0e41\u0e01\u0e49\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 <strong>200 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23<\/strong> \u0e15\u0e32\u0e21\u0e27\u0e34\u0e18\u0e35\u0e19\u0e31\u0e1a\u0e02\u0e2d\u0e07 BleepingComputer \u0e1e\u0e23\u0e49\u0e2d\u0e21 Zero-Day 6 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23 \u0e43\u0e19\u0e08\u0e33\u0e19\u0e27\u0e19\u0e19\u0e35\u0e49 5 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e16\u0e39\u0e01\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e15\u0e48\u0e2d\u0e2a\u0e32\u0e18\u0e32\u0e23\u0e13\u0e30\u0e01\u0e48\u0e2d\u0e19\u0e21\u0e35\u0e41\u0e1e\u0e15\u0e0a\u0e4c \u0e41\u0e25\u0e30\u0e2d\u0e35\u0e01 1 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e21\u0e35\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e27\u0e48\u0e32\u0e16\u0e39\u0e01\u0e43\u0e0a\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e08\u0e23\u0e34\u0e07<\/p>\n<p>\u0e08\u0e33\u0e19\u0e27\u0e19 200 \u0e17\u0e33\u0e43\u0e2b\u0e49\u0e23\u0e2d\u0e1a\u0e19\u0e35\u0e49\u0e16\u0e39\u0e01\u0e40\u0e23\u0e35\u0e22\u0e01\u0e27\u0e48\u0e32 Patch Tuesday \u0e17\u0e35\u0e48\u0e43\u0e2b\u0e0d\u0e48\u0e17\u0e35\u0e48\u0e2a\u0e38\u0e14\u0e04\u0e23\u0e31\u0e49\u0e07\u0e2b\u0e19\u0e36\u0e48\u0e07\u0e02\u0e2d\u0e07 Microsoft \u0e41\u0e15\u0e48\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e17\u0e35\u0e21 Security \u0e41\u0e25\u0e30 IT Operations \u0e04\u0e33\u0e16\u0e32\u0e21\u0e2a\u0e33\u0e04\u0e31\u0e0d\u0e01\u0e27\u0e48\u0e32\u0e15\u0e31\u0e27\u0e40\u0e25\u0e02\u0e04\u0e37\u0e2d <strong>\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e43\u0e14\u0e15\u0e49\u0e2d\u0e07\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e01\u0e48\u0e2d\u0e19 \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e43\u0e14\u0e40\u0e1b\u0e34\u0e14\u0e17\u0e32\u0e07\u0e08\u0e32\u0e01 internet \u0e41\u0e25\u0e30\u0e08\u0e30\u0e23\u0e39\u0e49\u0e44\u0e14\u0e49\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e44\u0e23\u0e27\u0e48\u0e32\u0e23\u0e30\u0e1a\u0e1a\u0e16\u0e39\u0e01\u0e42\u0e08\u0e21\u0e15\u0e35\u0e01\u0e48\u0e2d\u0e19\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/strong><\/p>\n<p>\u0e1a\u0e17\u0e04\u0e27\u0e32\u0e21\u0e19\u0e35\u0e49\u0e08\u0e36\u0e07\u0e44\u0e21\u0e48\u0e40\u0e1e\u0e35\u0e22\u0e07\u0e2a\u0e23\u0e38\u0e1b\u0e08\u0e33\u0e19\u0e27\u0e19 CVE \u0e41\u0e15\u0e48\u0e41\u0e1b\u0e25\u0e07\u0e02\u0e48\u0e32\u0e27\u0e43\u0e2b\u0e49\u0e40\u0e1b\u0e47\u0e19\u0e41\u0e1c\u0e19 vulnerability management \u0e17\u0e35\u0e48\u0e19\u0e33\u0e44\u0e1b\u0e43\u0e0a\u0e49\u0e44\u0e14\u0e49 \u0e15\u0e31\u0e49\u0e07\u0e41\u0e15\u0e48 asset mapping, risk-based prioritization, validation \u0e44\u0e1b\u0e08\u0e19\u0e16\u0e36\u0e07 post-patch threat hunting<\/p>\n<h2>\u0e17\u0e33\u0e44\u0e21\u0e08\u0e33\u0e19\u0e27\u0e19\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e08\u0e36\u0e07\u0e15\u0e48\u0e32\u0e07\u0e01\u0e31\u0e19\u0e23\u0e30\u0e2b\u0e27\u0e48\u0e32\u0e07\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e02\u0e48\u0e32\u0e27<\/h2>\n<p>BleepingComputer \u0e19\u0e31\u0e1a\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e43\u0e2b\u0e21\u0e48\u0e43\u0e19\u0e23\u0e2d\u0e1a\u0e40\u0e14\u0e37\u0e2d\u0e19\u0e19\u0e35\u0e49\u0e44\u0e14\u0e49 200 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23 \u0e02\u0e13\u0e30\u0e17\u0e35\u0e48 Zero Day Initiative (ZDI) \u0e23\u0e32\u0e22\u0e07\u0e32\u0e19 208 CVE \u0e04\u0e27\u0e32\u0e21\u0e41\u0e15\u0e01\u0e15\u0e48\u0e32\u0e07\u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e41\u0e1b\u0e25\u0e27\u0e48\u0e32\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e2b\u0e19\u0e36\u0e48\u0e07\u0e1c\u0e34\u0e14 \u0e41\u0e15\u0e48\u0e2d\u0e32\u0e08\u0e40\u0e01\u0e34\u0e14\u0e08\u0e32\u0e01\u0e2b\u0e25\u0e31\u0e01\u0e40\u0e01\u0e13\u0e11\u0e4c\u0e19\u0e31\u0e1a\u0e17\u0e35\u0e48\u0e15\u0e48\u0e32\u0e07\u0e01\u0e31\u0e19 \u0e40\u0e0a\u0e48\u0e19:<\/p>\n<ul>\n<li>\u0e19\u0e31\u0e1a\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48\u0e19\u0e31\u0e1a\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e02\u0e2d\u0e07\u0e1c\u0e25\u0e34\u0e15\u0e20\u0e31\u0e13\u0e11\u0e4c third-party \u0e17\u0e35\u0e48\u0e21\u0e32\u0e01\u0e31\u0e1a update<\/li>\n<li>\u0e23\u0e27\u0e21 CVE \u0e1a\u0e32\u0e07\u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e17\u0e35\u0e48\u0e16\u0e39\u0e01\u0e2d\u0e49\u0e32\u0e07\u0e0b\u0e49\u0e33\u0e43\u0e19\u0e1c\u0e25\u0e34\u0e15\u0e20\u0e31\u0e13\u0e11\u0e4c\u0e2b\u0e25\u0e32\u0e22\u0e23\u0e38\u0e48\u0e19\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/li>\n<li>\u0e01\u0e33\u0e2b\u0e19\u0e14 cutoff time \u0e02\u0e2d\u0e07\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e04\u0e19\u0e25\u0e30\u0e40\u0e27\u0e25\u0e32<\/li>\n<li>\u0e23\u0e27\u0e21 advisory \u0e17\u0e35\u0e48\u0e2d\u0e2d\u0e01\u0e19\u0e2d\u0e01 release train \u0e2b\u0e25\u0e31\u0e01\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/li>\n<\/ul>\n<p>\u0e40\u0e21\u0e37\u0e48\u0e2d\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19\u0e15\u0e48\u0e2d\u0e1c\u0e39\u0e49\u0e1a\u0e23\u0e34\u0e2b\u0e32\u0e23 \u0e04\u0e27\u0e23\u0e23\u0e30\u0e1a\u0e38\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e41\u0e25\u0e30\u0e27\u0e34\u0e18\u0e35\u0e19\u0e31\u0e1a \u0e41\u0e17\u0e19\u0e01\u0e32\u0e23\u0e40\u0e02\u0e35\u0e22\u0e19\u0e27\u0e48\u0e32 \u201cMicrosoft \u0e41\u0e01\u0e49 200 \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u201d \u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e21\u0e35\u0e1a\u0e23\u0e34\u0e1a\u0e17 \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e01\u0e32\u0e23\u0e1b\u0e0f\u0e34\u0e1a\u0e31\u0e15\u0e34\u0e07\u0e32\u0e19\u0e43\u0e2b\u0e49\u0e43\u0e0a\u0e49 Microsoft Security Update Guide \u0e41\u0e25\u0e30 catalog \u0e02\u0e2d\u0e07\u0e23\u0e30\u0e1a\u0e1a patch management \u0e40\u0e1b\u0e47\u0e19 source of truth \u0e02\u0e2d\u0e07 asset \u0e41\u0e15\u0e48\u0e25\u0e30\u0e01\u0e25\u0e38\u0e48\u0e21<\/p>\n<h2>\u0e20\u0e32\u0e1e\u0e23\u0e27\u0e21 Patch Tuesday \u0e40\u0e14\u0e37\u0e2d\u0e19\u0e21\u0e34\u0e16\u0e38\u0e19\u0e32\u0e22\u0e19 2026<\/h2>\n<p>\u0e01\u0e32\u0e23\u0e08\u0e31\u0e14\u0e2b\u0e21\u0e27\u0e14\u0e2b\u0e21\u0e39\u0e48\u0e15\u0e32\u0e21\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e17\u0e35\u0e48\u0e23\u0e27\u0e1a\u0e23\u0e27\u0e21\u0e42\u0e14\u0e22 BleepingComputer \u0e21\u0e35\u0e14\u0e31\u0e07\u0e19\u0e35\u0e49:<\/p>\n<div style=\"overflow-x:auto;margin:1.5em 0;\">\n<table style=\"width:100%;border-collapse:collapse;\">\n<thead>\n<tr>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e1b\u0e23\u0e30\u0e40\u0e20\u0e17\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48<\/th>\n<th style=\"text-align: right;\">\u0e08\u0e33\u0e19\u0e27\u0e19<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Elevation of Privilege<\/td>\n<td style=\"text-align: right;\">65<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Security Feature Bypass<\/td>\n<td style=\"text-align: right;\">19<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Remote Code Execution<\/td>\n<td style=\"text-align: right;\">55<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Information Disclosure<\/td>\n<td style=\"text-align: right;\">30<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Denial of Service<\/td>\n<td style=\"text-align: right;\">7<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Spoofing<\/td>\n<td style=\"text-align: right;\">27<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>Microsoft \u0e08\u0e31\u0e14 33 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e40\u0e1b\u0e47\u0e19\u0e23\u0e30\u0e14\u0e31\u0e1a Critical \u0e1b\u0e23\u0e30\u0e01\u0e2d\u0e1a\u0e14\u0e49\u0e27\u0e22 Remote Code Execution 28 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23, Elevation of Privilege 4 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23 \u0e41\u0e25\u0e30 Information Disclosure 1 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23<\/p>\n<p>\u0e15\u0e31\u0e27\u0e40\u0e25\u0e02\u0e43\u0e19\u0e41\u0e15\u0e48\u0e25\u0e30\u0e2b\u0e21\u0e27\u0e14\u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e19\u0e33\u0e21\u0e32\u0e1a\u0e27\u0e01\u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e2a\u0e23\u0e38\u0e1b\u0e41\u0e17\u0e19 inventory \u0e2d\u0e22\u0e48\u0e32\u0e07\u0e40\u0e1b\u0e47\u0e19\u0e17\u0e32\u0e07\u0e01\u0e32\u0e23\u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e15\u0e23\u0e27\u0e08 methodology \u0e40\u0e1e\u0e23\u0e32\u0e30 CVE \u0e1a\u0e32\u0e07\u0e01\u0e23\u0e13\u0e35\u0e2d\u0e32\u0e08\u0e21\u0e35\u0e01\u0e32\u0e23\u0e08\u0e31\u0e14\u0e01\u0e25\u0e38\u0e48\u0e21\u0e15\u0e48\u0e32\u0e07\u0e01\u0e31\u0e19\u0e15\u0e32\u0e21\u0e41\u0e2b\u0e25\u0e48\u0e07 \u0e2a\u0e34\u0e48\u0e07\u0e17\u0e35\u0e48\u0e2a\u0e33\u0e04\u0e31\u0e0d\u0e04\u0e37\u0e2d\u0e23\u0e2d\u0e1a\u0e19\u0e35\u0e49\u0e21\u0e35\u0e17\u0e31\u0e49\u0e07\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e17\u0e35\u0e48\u0e43\u0e0a\u0e49\u0e40\u0e1b\u0e47\u0e19 initial access, privilege escalation \u0e41\u0e25\u0e30 lateral movement \u0e0b\u0e36\u0e48\u0e07\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e1b\u0e23\u0e30\u0e01\u0e2d\u0e1a\u0e40\u0e1b\u0e47\u0e19 attack chain \u0e44\u0e14\u0e49<\/p>\n<h2>Zero-Day 6 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e2b\u0e21\u0e32\u0e22\u0e04\u0e27\u0e32\u0e21\u0e27\u0e48\u0e32\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e44\u0e23<\/h2>\n<p>\u0e43\u0e19\u0e1a\u0e23\u0e34\u0e1a\u0e17\u0e02\u0e2d\u0e07\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19\u0e23\u0e2d\u0e1a\u0e19\u0e35\u0e49 Zero-Day \u0e04\u0e23\u0e2d\u0e1a\u0e04\u0e25\u0e38\u0e21\u0e2a\u0e2d\u0e07\u0e2a\u0e16\u0e32\u0e19\u0e30\u0e17\u0e35\u0e48\u0e15\u0e48\u0e32\u0e07\u0e01\u0e31\u0e19:<\/p>\n<ol>\n<li><strong>Publicly disclosed<\/strong> \u2014 \u0e23\u0e32\u0e22\u0e25\u0e30\u0e40\u0e2d\u0e35\u0e22\u0e14\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e40\u0e1b\u0e47\u0e19\u0e17\u0e35\u0e48\u0e23\u0e39\u0e49\u0e08\u0e31\u0e01\u0e15\u0e48\u0e2d\u0e2a\u0e32\u0e18\u0e32\u0e23\u0e13\u0e30\u0e01\u0e48\u0e2d\u0e19\u0e21\u0e35 official update \u0e41\u0e15\u0e48\u0e2d\u0e32\u0e08\u0e22\u0e31\u0e07\u0e44\u0e21\u0e48\u0e21\u0e35\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e27\u0e48\u0e32\u0e42\u0e08\u0e21\u0e15\u0e35\u0e08\u0e23\u0e34\u0e07<\/li>\n<li><strong>Exploited in the wild<\/strong> \u2014 \u0e21\u0e35\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e27\u0e48\u0e32\u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e43\u0e0a\u0e49\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e01\u0e31\u0e1a\u0e40\u0e1b\u0e49\u0e32\u0e2b\u0e21\u0e32\u0e22\u0e08\u0e23\u0e34\u0e07\u0e01\u0e48\u0e2d\u0e19\u0e2b\u0e23\u0e37\u0e2d\u0e02\u0e13\u0e30\u0e2d\u0e2d\u0e01\u0e41\u0e1e\u0e15\u0e0a\u0e4c<\/li>\n<\/ol>\n<p>\u0e2a\u0e16\u0e32\u0e19\u0e30\u0e17\u0e35\u0e48\u0e2a\u0e2d\u0e07\u0e04\u0e27\u0e23\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a priority \u0e2a\u0e39\u0e07\u0e2a\u0e38\u0e14 \u0e41\u0e15\u0e48\u0e2a\u0e16\u0e32\u0e19\u0e30\u0e41\u0e23\u0e01\u0e01\u0e47\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07 \u0e40\u0e1e\u0e23\u0e32\u0e30\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e2a\u0e32\u0e18\u0e32\u0e23\u0e13\u0e30\u0e25\u0e14\u0e40\u0e27\u0e25\u0e32\u0e17\u0e35\u0e48\u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e15\u0e49\u0e2d\u0e07\u0e43\u0e0a\u0e49\u0e43\u0e19\u0e01\u0e32\u0e23\u0e2a\u0e23\u0e49\u0e32\u0e07 exploit \u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e43\u0e2b\u0e49\u0e04\u0e30\u0e41\u0e19\u0e19\u0e15\u0e32\u0e21 CVSS \u0e2d\u0e22\u0e48\u0e32\u0e07\u0e40\u0e14\u0e35\u0e22\u0e27 \u0e15\u0e49\u0e2d\u0e07\u0e23\u0e27\u0e21 exploit status, internet exposure, asset criticality \u0e41\u0e25\u0e30 compensating control<\/p>\n<p>\u0e2a\u0e39\u0e15\u0e23\u0e40\u0e0a\u0e34\u0e07\u0e41\u0e19\u0e27\u0e04\u0e34\u0e14\u0e17\u0e35\u0e48\u0e43\u0e0a\u0e49\u0e2a\u0e37\u0e48\u0e2d\u0e2a\u0e32\u0e23\u0e20\u0e32\u0e22\u0e43\u0e19\u0e44\u0e14\u0e49\u0e04\u0e37\u0e2d:<\/p>\n<blockquote>\n<p>Priority = Exploit activity \u00d7 Exposure \u00d7 Business impact \u00f7 Control effectiveness<\/p>\n<\/blockquote>\n<p>\u0e2a\u0e39\u0e15\u0e23\u0e19\u0e35\u0e49\u0e44\u0e21\u0e48\u0e08\u0e33\u0e40\u0e1b\u0e47\u0e19\u0e15\u0e49\u0e2d\u0e07\u0e04\u0e33\u0e19\u0e27\u0e13\u0e40\u0e1b\u0e47\u0e19\u0e40\u0e25\u0e02\u0e15\u0e32\u0e22\u0e15\u0e31\u0e27 \u0e08\u0e38\u0e14\u0e1b\u0e23\u0e30\u0e2a\u0e07\u0e04\u0e4c\u0e04\u0e37\u0e2d\u0e1a\u0e31\u0e07\u0e04\u0e31\u0e1a\u0e43\u0e2b\u0e49\u0e17\u0e35\u0e21\u0e21\u0e2d\u0e07\u0e1a\u0e23\u0e34\u0e1a\u0e17\u0e02\u0e2d\u0e07\u0e17\u0e23\u0e31\u0e1e\u0e22\u0e4c\u0e2a\u0e34\u0e19\u0e08\u0e23\u0e34\u0e07<\/p>\n<h2>\u0e17\u0e33\u0e44\u0e21 Patch Tuesday \u0e23\u0e2d\u0e1a\u0e19\u0e35\u0e49\u0e21\u0e35\u0e1c\u0e25\u0e15\u0e48\u0e2d Penetration Testing<\/h2>\n<p>\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19 penetration testing \u0e21\u0e31\u0e01\u0e1e\u0e1a\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e2b\u0e19\u0e36\u0e48\u0e07\u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e41\u0e25\u0e49\u0e27\u0e43\u0e2b\u0e49\u0e04\u0e30\u0e41\u0e19\u0e19\u0e40\u0e1b\u0e47\u0e19\u0e23\u0e32\u0e22\u0e08\u0e38\u0e14 \u0e41\u0e15\u0e48\u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e08\u0e23\u0e34\u0e07\u0e08\u0e30\u0e15\u0e48\u0e2d\u0e2b\u0e25\u0e32\u0e22\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e40\u0e02\u0e49\u0e32\u0e14\u0e49\u0e27\u0e22\u0e01\u0e31\u0e19 \u0e40\u0e0a\u0e48\u0e19:<\/p>\n<ol>\n<li>\u0e43\u0e0a\u0e49 RCE \u0e2b\u0e23\u0e37\u0e2d security feature bypass \u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e23\u0e31\u0e19\u0e42\u0e04\u0e49\u0e14\u0e40\u0e23\u0e34\u0e48\u0e21\u0e15\u0e49\u0e19<\/li>\n<li>\u0e43\u0e0a\u0e49 local privilege escalation \u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e02\u0e36\u0e49\u0e19\u0e40\u0e1b\u0e47\u0e19 SYSTEM<\/li>\n<li>\u0e14\u0e36\u0e07 credential \u0e2b\u0e23\u0e37\u0e2d token \u0e08\u0e32\u0e01\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07<\/li>\n<li>\u0e40\u0e04\u0e25\u0e37\u0e48\u0e2d\u0e19\u0e17\u0e35\u0e48\u0e44\u0e1b\u0e22\u0e31\u0e07 server \u0e2d\u0e37\u0e48\u0e19<\/li>\n<li>\u0e40\u0e02\u0e49\u0e32\u0e16\u0e36\u0e07\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e2a\u0e33\u0e04\u0e31\u0e0d\u0e2b\u0e23\u0e37\u0e2d deploy ransomware<\/li>\n<\/ol>\n<p>\u0e14\u0e31\u0e07\u0e19\u0e31\u0e49\u0e19 pentest \u0e2b\u0e25\u0e31\u0e07 Patch Tuesday \u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e16\u0e32\u0e21\u0e40\u0e1e\u0e35\u0e22\u0e07 \u201c\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e2b\u0e23\u0e37\u0e2d\u0e22\u0e31\u0e07\u201d \u0e41\u0e15\u0e48\u0e04\u0e27\u0e23\u0e15\u0e23\u0e27\u0e08\u0e27\u0e48\u0e32 control \u0e23\u0e2d\u0e1a\u0e02\u0e49\u0e32\u0e07\u0e2b\u0e22\u0e38\u0e14 attack chain \u0e44\u0e14\u0e49\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48 \u0e40\u0e0a\u0e48\u0e19 application allowlisting, endpoint detection, least privilege, credential isolation \u0e41\u0e25\u0e30 network segmentation<\/p>\n<h2>\u0e27\u0e34\u0e18\u0e35\u0e08\u0e31\u0e14\u0e25\u0e33\u0e14\u0e31\u0e1a\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e41\u0e1a\u0e1a Risk-Based<\/h2>\n<h3>Priority 0: \u0e21\u0e35 exploitation \u0e41\u0e25\u0e30\u0e40\u0e1b\u0e34\u0e14\u0e08\u0e32\u0e01\u0e20\u0e32\u0e22\u0e19\u0e2d\u0e01<\/h3>\n<p>\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e2b\u0e23\u0e37\u0e2d isolate \u0e17\u0e31\u0e19\u0e17\u0e35\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e23\u0e30\u0e1a\u0e1a\u0e17\u0e35\u0e48:<\/p>\n<ul>\n<li>\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e16\u0e39\u0e01\u0e43\u0e0a\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e08\u0e23\u0e34\u0e07<\/li>\n<li>\u0e40\u0e1b\u0e34\u0e14 service \u0e15\u0e48\u0e2d internet \u0e2b\u0e23\u0e37\u0e2d partner network<\/li>\n<li>\u0e40\u0e1b\u0e47\u0e19 identity, remote access \u0e2b\u0e23\u0e37\u0e2d management plane<\/li>\n<li>\u0e44\u0e21\u0e48\u0e21\u0e35 EDR \u0e2b\u0e23\u0e37\u0e2d compensating control \u0e17\u0e35\u0e48\u0e15\u0e23\u0e27\u0e08\u0e08\u0e31\u0e1a\u0e44\u0e14\u0e49<\/li>\n<\/ul>\n<h3>Priority 1: Critical RCE \u0e1a\u0e19\u0e23\u0e30\u0e1a\u0e1a\u0e2a\u0e33\u0e04\u0e31\u0e0d<\/h3>\n<p>\u0e23\u0e27\u0e21 domain controller, file server, virtualization host, build server, workstation \u0e02\u0e2d\u0e07 administrator \u0e41\u0e25\u0e30 server \u0e17\u0e35\u0e48\u0e40\u0e01\u0e47\u0e1a\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25 regulated \u0e41\u0e21\u0e49\u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e40\u0e1b\u0e34\u0e14 internet \u0e42\u0e14\u0e22\u0e15\u0e23\u0e07\u0e01\u0e47\u0e21\u0e35\u0e04\u0e27\u0e32\u0e21\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07\u0e08\u0e32\u0e01 lateral movement<\/p>\n<h3>Priority 2: Privilege Escalation \u0e41\u0e25\u0e30 Security Bypass<\/h3>\n<p>\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e40\u0e2b\u0e25\u0e48\u0e32\u0e19\u0e35\u0e49\u0e2d\u0e32\u0e08\u0e14\u0e39\u0e23\u0e38\u0e19\u0e41\u0e23\u0e07\u0e19\u0e49\u0e2d\u0e22\u0e01\u0e27\u0e48\u0e32 RCE \u0e40\u0e1e\u0e23\u0e32\u0e30\u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35 foothold \u0e01\u0e48\u0e2d\u0e19 \u0e41\u0e15\u0e48\u0e40\u0e1b\u0e47\u0e19\u0e2a\u0e48\u0e27\u0e19\u0e2a\u0e33\u0e04\u0e31\u0e0d\u0e02\u0e2d\u0e07 attack chain \u0e42\u0e14\u0e22\u0e40\u0e09\u0e1e\u0e32\u0e30\u0e1a\u0e19 endpoint \u0e17\u0e35\u0e48\u0e21\u0e35\u0e1c\u0e39\u0e49\u0e43\u0e0a\u0e49\u0e17\u0e31\u0e48\u0e27\u0e44\u0e1b\u0e41\u0e25\u0e30 local service \u0e08\u0e33\u0e19\u0e27\u0e19\u0e21\u0e32\u0e01<\/p>\n<h3>Priority 3: \u0e23\u0e30\u0e1a\u0e1a\u0e17\u0e35\u0e48\u0e21\u0e35 control \u0e41\u0e02\u0e47\u0e07\u0e41\u0e23\u0e07\u0e2b\u0e23\u0e37\u0e2d exposure \u0e15\u0e48\u0e33<\/h3>\n<p>\u0e22\u0e31\u0e07\u0e15\u0e49\u0e2d\u0e07\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e20\u0e32\u0e22\u0e43\u0e19 SLA \u0e41\u0e15\u0e48\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e23\u0e2d\u0e23\u0e2d\u0e1a\u0e17\u0e14\u0e2a\u0e2d\u0e1a\u0e1b\u0e01\u0e15\u0e34\u0e44\u0e14\u0e49 \u0e2b\u0e32\u0e01\u0e21\u0e35 segmentation, application control \u0e41\u0e25\u0e30 monitoring \u0e17\u0e35\u0e48\u0e1e\u0e34\u0e2a\u0e39\u0e08\u0e19\u0e4c\u0e41\u0e25\u0e49\u0e27<\/p>\n<h2>Playbook \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23<\/h2>\n<h3>1. \u0e17\u0e33 Asset-to-CVE Mapping<\/h3>\n<p>\u0e14\u0e36\u0e07\u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e08\u0e32\u0e01 CMDB, endpoint management, vulnerability scanner \u0e41\u0e25\u0e30 cloud inventory \u0e41\u0e25\u0e49\u0e27\u0e15\u0e2d\u0e1a\u0e43\u0e2b\u0e49\u0e44\u0e14\u0e49\u0e27\u0e48\u0e32:<\/p>\n<ul>\n<li>\u0e21\u0e35 Windows edition\/build \u0e43\u0e14\u0e1a\u0e49\u0e32\u0e07<\/li>\n<li>\u0e21\u0e35 server role \u0e2b\u0e23\u0e37\u0e2d Microsoft product \u0e43\u0e14\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07\u0e2d\u0e22\u0e39\u0e48<\/li>\n<li>\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e43\u0e14\u0e40\u0e1b\u0e47\u0e19 internet-facing<\/li>\n<li>\u0e43\u0e04\u0e23\u0e40\u0e1b\u0e47\u0e19 business owner<\/li>\n<li>\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e2b\u0e23\u0e37\u0e2d process \u0e43\u0e14\u0e08\u0e30\u0e2b\u0e22\u0e38\u0e14\u0e2b\u0e32\u0e01 restart<\/li>\n<\/ul>\n<p>\u0e01\u0e32\u0e23\u0e21\u0e35 CVE list \u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e21\u0e35 asset owner \u0e17\u0e33\u0e43\u0e2b\u0e49\u0e01\u0e32\u0e23 patch \u0e04\u0e49\u0e32\u0e07\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19 ticket queue<\/p>\n<h3>2. \u0e41\u0e1a\u0e48\u0e07 Deployment Ring<\/h3>\n<p>\u0e43\u0e0a\u0e49 deployment ring \u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e25\u0e14\u0e04\u0e27\u0e32\u0e21\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07 operational:<\/p>\n<div style=\"overflow-x:auto;margin:1.5em 0;\">\n<table style=\"width:100%;border-collapse:collapse;\">\n<thead>\n<tr>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Ring<\/th>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e15\u0e31\u0e27\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e23\u0e30\u0e1a\u0e1a<\/th>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e40\u0e1b\u0e49\u0e32\u0e2b\u0e21\u0e32\u0e22<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Ring 0<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Lab\/automated test<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e15\u0e23\u0e27\u0e08 boot, service \u0e41\u0e25\u0e30 regression<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Ring 1<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">IT\/Security canary<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e1e\u0e1a\u0e1b\u0e31\u0e0d\u0e2b\u0e32\u0e1a\u0e19 workload \u0e08\u0e23\u0e34\u0e07\u0e02\u0e19\u0e32\u0e14\u0e40\u0e25\u0e47\u0e01<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Ring 2<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e1c\u0e39\u0e49\u0e43\u0e0a\u0e49\u0e17\u0e31\u0e48\u0e27\u0e44\u0e1b\/\u0e23\u0e30\u0e1a\u0e1a\u0e04\u0e27\u0e32\u0e21\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07\u0e01\u0e25\u0e32\u0e07<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e01\u0e23\u0e30\u0e08\u0e32\u0e22\u0e2b\u0e25\u0e31\u0e07 canary \u0e1c\u0e48\u0e32\u0e19<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Ring 3<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Mission-critical<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">deploy \u0e15\u0e32\u0e21 change window \u0e1e\u0e23\u0e49\u0e2d\u0e21 rollback<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>\u0e23\u0e30\u0e1a\u0e1a\u0e17\u0e35\u0e48\u0e21\u0e35 active exploitation \u0e2d\u0e32\u0e08\u0e15\u0e49\u0e2d\u0e07\u0e02\u0e49\u0e32\u0e21\u0e25\u0e33\u0e14\u0e31\u0e1a\u0e1b\u0e01\u0e15\u0e34 \u0e41\u0e15\u0e48\u0e22\u0e31\u0e07\u0e04\u0e27\u0e23\u0e17\u0e33 smoke test \u0e17\u0e35\u0e48\u0e08\u0e33\u0e40\u0e1b\u0e47\u0e19\u0e41\u0e25\u0e30\u0e40\u0e15\u0e23\u0e35\u0e22\u0e21 rollback plan<\/p>\n<h3>3. \u0e15\u0e23\u0e27\u0e08\u0e01\u0e32\u0e23\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07 \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e41\u0e04\u0e48\u0e2a\u0e31\u0e48\u0e07 Deploy<\/h3>\n<p>\u0e2a\u0e16\u0e32\u0e19\u0e30 \u201ccommand sent\u201d \u0e44\u0e21\u0e48\u0e40\u0e17\u0e48\u0e32\u0e01\u0e31\u0e1a \u201cpatched\u201d \u0e04\u0e27\u0e23\u0e15\u0e23\u0e27\u0e08:<\/p>\n<ul>\n<li>update \u0e16\u0e39\u0e01\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07\u0e2a\u0e33\u0e40\u0e23\u0e47\u0e08<\/li>\n<li>reboot \u0e17\u0e35\u0e48\u0e08\u0e33\u0e40\u0e1b\u0e47\u0e19\u0e40\u0e01\u0e34\u0e14\u0e02\u0e36\u0e49\u0e19\u0e41\u0e25\u0e49\u0e27<\/li>\n<li>build\/KB \u0e15\u0e23\u0e07\u0e01\u0e31\u0e1a baseline<\/li>\n<li>service \u0e2a\u0e33\u0e04\u0e31\u0e0d\u0e01\u0e25\u0e31\u0e1a\u0e21\u0e32\u0e17\u0e33\u0e07\u0e32\u0e19<\/li>\n<li>vulnerability scanner \u0e44\u0e21\u0e48\u0e1e\u0e1a\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e40\u0e14\u0e34\u0e21<\/li>\n<li>EDR agent \u0e41\u0e25\u0e30 logging \u0e22\u0e31\u0e07\u0e17\u0e33\u0e07\u0e32\u0e19\u0e2b\u0e25\u0e31\u0e07 reboot<\/li>\n<\/ul>\n<h3>4. Hunt \u0e22\u0e49\u0e2d\u0e19\u0e2b\u0e25\u0e31\u0e07\u0e01\u0e48\u0e2d\u0e19\u0e41\u0e25\u0e30\u0e2b\u0e25\u0e31\u0e07\u0e41\u0e1e\u0e15\u0e0a\u0e4c<\/h3>\n<p>\u0e01\u0e32\u0e23\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e1b\u0e34\u0e14\u0e0a\u0e48\u0e2d\u0e07\u0e17\u0e32\u0e07\u0e42\u0e08\u0e21\u0e15\u0e35\u0e43\u0e2b\u0e21\u0e48 \u0e41\u0e15\u0e48\u0e44\u0e21\u0e48\u0e25\u0e1a persistence \u0e17\u0e35\u0e48\u0e16\u0e39\u0e01\u0e2a\u0e23\u0e49\u0e32\u0e07\u0e44\u0e27\u0e49 \u0e43\u0e2b\u0e49\u0e17\u0e35\u0e21 threat hunting \u0e15\u0e23\u0e27\u0e08\u0e0a\u0e48\u0e27\u0e07\u0e01\u0e48\u0e2d\u0e19\u0e27\u0e31\u0e19\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e15\u0e32\u0e21 exposure \u0e02\u0e2d\u0e07\u0e41\u0e15\u0e48\u0e25\u0e30 CVE \u0e42\u0e14\u0e22\u0e21\u0e2d\u0e07\u0e2b\u0e32:<\/p>\n<ul>\n<li>process tree \u0e1c\u0e34\u0e14\u0e1b\u0e01\u0e15\u0e34\u0e08\u0e32\u0e01 service \u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e1c\u0e25<\/li>\n<li>child process \u0e40\u0e0a\u0e48\u0e19 shell, script host \u0e2b\u0e23\u0e37\u0e2d LOLBin<\/li>\n<li>account creation \u0e41\u0e25\u0e30 privilege change<\/li>\n<li>scheduled task\/service \u0e43\u0e2b\u0e21\u0e48<\/li>\n<li>outbound connection \u0e44\u0e1b\u0e1b\u0e25\u0e32\u0e22\u0e17\u0e32\u0e07\u0e44\u0e21\u0e48\u0e04\u0e38\u0e49\u0e19\u0e40\u0e04\u0e22<\/li>\n<li>credential access \u0e2b\u0e23\u0e37\u0e2d remote administration tool<\/li>\n<\/ul>\n<p>\u0e01\u0e32\u0e23\u0e40\u0e25\u0e37\u0e2d\u0e01 log \u0e41\u0e25\u0e30 indicator \u0e15\u0e49\u0e2d\u0e07\u0e2d\u0e34\u0e07 advisory \u0e02\u0e2d\u0e07 CVE \u0e41\u0e15\u0e48\u0e25\u0e30\u0e23\u0e32\u0e22\u0e01\u0e32\u0e23 \u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e43\u0e0a\u0e49 query \u0e40\u0e14\u0e35\u0e22\u0e27\u0e04\u0e23\u0e2d\u0e1a\u0e04\u0e25\u0e38\u0e21 200 \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48<\/p>\n<h2>\u0e0a\u0e48\u0e2d\u0e07\u0e27\u0e48\u0e32\u0e07\u0e17\u0e35\u0e48 Vulnerability Scanner \u0e2d\u0e32\u0e08\u0e44\u0e21\u0e48\u0e1a\u0e2d\u0e01<\/h2>\n<p>Scanner \u0e0a\u0e48\u0e27\u0e22\u0e23\u0e30\u0e1a\u0e38 missing patch \u0e44\u0e14\u0e49\u0e14\u0e35 \u0e41\u0e15\u0e48\u0e21\u0e35\u0e02\u0e49\u0e2d\u0e08\u0e33\u0e01\u0e31\u0e14:<\/p>\n<ul>\n<li>credentialed scan \u0e2d\u0e32\u0e08\u0e25\u0e49\u0e21\u0e40\u0e2b\u0e25\u0e27\u0e41\u0e25\u0e49\u0e27\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19\u0e1c\u0e25\u0e44\u0e21\u0e48\u0e04\u0e23\u0e1a<\/li>\n<li>appliance \u0e2b\u0e23\u0e37\u0e2d golden image \u0e2d\u0e32\u0e08\u0e2d\u0e22\u0e39\u0e48\u0e19\u0e2d\u0e01 inventory<\/li>\n<li>\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07 offline \u0e23\u0e30\u0e2b\u0e27\u0e48\u0e32\u0e07 scan \u0e44\u0e21\u0e48\u0e16\u0e39\u0e01\u0e1b\u0e23\u0e30\u0e40\u0e21\u0e34\u0e19<\/li>\n<li>update \u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07\u0e41\u0e25\u0e49\u0e27\u0e41\u0e15\u0e48\u0e23\u0e2d reboot<\/li>\n<li>scanner \u0e44\u0e21\u0e48\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e27\u0e48\u0e32\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e40\u0e04\u0e22\u0e16\u0e39\u0e01\u0e40\u0e08\u0e32\u0e30\u0e01\u0e48\u0e2d\u0e19\u0e41\u0e1e\u0e15\u0e0a\u0e4c<\/li>\n<li>exploitability \u0e02\u0e36\u0e49\u0e19\u0e01\u0e31\u0e1a configuration \u0e17\u0e35\u0e48 scanner \u0e21\u0e2d\u0e07\u0e44\u0e21\u0e48\u0e40\u0e2b\u0e47\u0e19<\/li>\n<\/ul>\n<p>\u0e08\u0e36\u0e07\u0e04\u0e27\u0e23\u0e08\u0e31\u0e1a\u0e04\u0e39\u0e48 vulnerability data \u0e01\u0e31\u0e1a EDR, SIEM, exposure management \u0e41\u0e25\u0e30 asset ownership<\/p>\n<h2>\u0e21\u0e38\u0e21\u0e21\u0e2d\u0e07 Red Team: \u0e43\u0e0a\u0e49\u0e02\u0e48\u0e32\u0e27\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e1b\u0e25\u0e2d\u0e14\u0e20\u0e31\u0e22\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e44\u0e23<\/h2>\n<p>Red team \u0e41\u0e25\u0e30 penetration tester \u0e17\u0e35\u0e48\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e2d\u0e19\u0e38\u0e0d\u0e32\u0e15\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e43\u0e0a\u0e49 Patch Tuesday \u0e40\u0e1b\u0e47\u0e19 threat-informed exercise \u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e15\u0e49\u0e2d\u0e07 deploy exploit \u0e2d\u0e31\u0e19\u0e15\u0e23\u0e32\u0e22\u0e1a\u0e19 production \u0e40\u0e0a\u0e48\u0e19:<\/p>\n<ul>\n<li>\u0e15\u0e23\u0e27\u0e08 attack surface \u0e41\u0e25\u0e30 version \u0e1c\u0e48\u0e32\u0e19\u0e27\u0e34\u0e18\u0e35 non-destructive<\/li>\n<li>\u0e08\u0e33\u0e25\u0e2d\u0e07 post-exploitation \u0e08\u0e32\u0e01 assumed breach<\/li>\n<li>\u0e17\u0e14\u0e2a\u0e2d\u0e1a\u0e27\u0e48\u0e32 EDR \u0e15\u0e23\u0e27\u0e08 child process \u0e08\u0e32\u0e01 service \u0e2a\u0e33\u0e04\u0e31\u0e0d\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/li>\n<li>\u0e17\u0e14\u0e2a\u0e2d\u0e1a segmentation \u0e23\u0e30\u0e2b\u0e27\u0e48\u0e32\u0e07 endpoint \u0e01\u0e31\u0e1a management network<\/li>\n<li>\u0e15\u0e23\u0e27\u0e08\u0e27\u0e48\u0e32 SOC \u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21 alert \u0e01\u0e31\u0e1a missing patch \u0e44\u0e14\u0e49\u0e40\u0e23\u0e47\u0e27\u0e40\u0e1e\u0e35\u0e22\u0e07\u0e43\u0e14<\/li>\n<li>\u0e27\u0e31\u0e14\u0e40\u0e27\u0e25\u0e32\u0e08\u0e32\u0e01 advisory \u0e16\u0e36\u0e07 asset owner acknowledgement<\/li>\n<\/ul>\n<p>Rules of Engagement \u0e15\u0e49\u0e2d\u0e07\u0e01\u0e33\u0e2b\u0e19\u0e14 target, \u0e40\u0e27\u0e25\u0e32, rate limit, stop condition \u0e41\u0e25\u0e30\u0e27\u0e34\u0e18\u0e35\u0e40\u0e01\u0e47\u0e1a\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e0a\u0e31\u0e14\u0e40\u0e08\u0e19<\/p>\n<h2>KPI \u0e17\u0e35\u0e48\u0e04\u0e27\u0e23\u0e43\u0e0a\u0e49\u0e41\u0e17\u0e19 \u201c\u0e40\u0e1b\u0e2d\u0e23\u0e4c\u0e40\u0e0b\u0e47\u0e19\u0e15\u0e4c\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e23\u0e27\u0e21\u201d<\/h2>\n<p>\u0e40\u0e1b\u0e2d\u0e23\u0e4c\u0e40\u0e0b\u0e47\u0e19\u0e15\u0e4c compliance \u0e23\u0e27\u0e21\u0e2d\u0e32\u0e08\u0e14\u0e39\u0e14\u0e35\u0e41\u0e21\u0e49 critical asset \u0e22\u0e31\u0e07\u0e44\u0e21\u0e48\u0e41\u0e1e\u0e15\u0e0a\u0e4c \u0e04\u0e27\u0e23\u0e40\u0e1e\u0e34\u0e48\u0e21\u0e15\u0e31\u0e27\u0e0a\u0e35\u0e49\u0e27\u0e31\u0e14\u0e40\u0e2b\u0e25\u0e48\u0e32\u0e19\u0e35\u0e49:<\/p>\n<ul>\n<li>Median time to remediate \u0e41\u0e22\u0e01\u0e15\u0e32\u0e21 exploited\/critical\/high<\/li>\n<li>\u0e40\u0e27\u0e25\u0e32 patch internet-facing asset<\/li>\n<li>\u0e08\u0e33\u0e19\u0e27\u0e19 asset \u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e21\u0e35 owner<\/li>\n<li>\u0e08\u0e33\u0e19\u0e27\u0e19\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e23\u0e2d reboot \u0e40\u0e01\u0e34\u0e19 SLA<\/li>\n<li>Coverage \u0e02\u0e2d\u0e07 authenticated vulnerability scan<\/li>\n<li>\u0e08\u0e33\u0e19\u0e27\u0e19 exception \u0e17\u0e35\u0e48\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38\u0e41\u0e15\u0e48\u0e22\u0e31\u0e07\u0e44\u0e21\u0e48\u0e1b\u0e34\u0e14<\/li>\n<li>\u0e40\u0e27\u0e25\u0e32\u0e08\u0e32\u0e01 patch deploy \u0e16\u0e36\u0e07 verification<\/li>\n<li>\u0e2d\u0e31\u0e15\u0e23\u0e32 regression \u0e41\u0e25\u0e30 rollback<\/li>\n<\/ul>\n<h2>\u0e04\u0e27\u0e32\u0e21\u0e2a\u0e31\u0e21\u0e1e\u0e31\u0e19\u0e18\u0e4c\u0e01\u0e31\u0e1a RoguePlanet<\/h2>\n<p>\u0e2b\u0e25\u0e31\u0e07 Patch Tuesday \u0e40\u0e1e\u0e35\u0e22\u0e07\u0e44\u0e21\u0e48\u0e01\u0e35\u0e48\u0e0a\u0e31\u0e48\u0e27\u0e42\u0e21\u0e07 \u0e21\u0e35\u0e01\u0e32\u0e23\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 Microsoft Defender \u0e0a\u0e37\u0e48\u0e2d <strong>RoguePlanet (CVE-2026-50656)<\/strong> \u0e0b\u0e36\u0e48\u0e07\u0e22\u0e31\u0e07\u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e40\u0e1b\u0e47\u0e19\u0e2b\u0e19\u0e36\u0e48\u0e07\u0e43\u0e19\u0e2b\u0e01 Zero-Day \u0e17\u0e35\u0e48\u0e16\u0e39\u0e01\u0e41\u0e01\u0e49\u0e43\u0e19\u0e27\u0e31\u0e19\u0e17\u0e35\u0e48 9 \u0e21\u0e34\u0e16\u0e38\u0e19\u0e32\u0e22\u0e19 \u0e40\u0e2b\u0e15\u0e38\u0e01\u0e32\u0e23\u0e13\u0e4c\u0e19\u0e35\u0e49\u0e40\u0e15\u0e37\u0e2d\u0e19\u0e27\u0e48\u0e32 \u201c\u0e15\u0e34\u0e14 Patch Tuesday \u0e04\u0e23\u0e1a\u201d \u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e41\u0e1b\u0e25\u0e27\u0e48\u0e32\u0e23\u0e30\u0e1a\u0e1a\u0e1b\u0e25\u0e2d\u0e14\u0e20\u0e31\u0e22\u0e08\u0e32\u0e01\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e17\u0e35\u0e48\u0e40\u0e1e\u0e34\u0e48\u0e07\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e17\u0e31\u0e49\u0e07\u0e2b\u0e21\u0e14<\/p>\n<p>RoguePlanet \u0e40\u0e1b\u0e47\u0e19 local privilege escalation \u0e43\u0e19 Microsoft Malware Protection Engine \u0e41\u0e25\u0e30\u0e16\u0e39\u0e01\u0e41\u0e01\u0e49\u0e20\u0e32\u0e22\u0e2b\u0e25\u0e31\u0e07\u0e1c\u0e48\u0e32\u0e19\u0e01\u0e32\u0e23\u0e2d\u0e31\u0e1b\u0e40\u0e14\u0e15 engine \u0e2d\u0e48\u0e32\u0e19\u0e23\u0e32\u0e22\u0e25\u0e30\u0e40\u0e2d\u0e35\u0e22\u0e14\u0e44\u0e14\u0e49\u0e43\u0e19 <a href=\"https:\/\/droneth.or.th\/zh\/microsoft-defender-rogueplanet-cve-2026-50656-zero-day\/\">RoguePlanet Zero-Day \u0e43\u0e19 Microsoft Defender<\/a><\/p>\n<h2>Checklist \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e17\u0e35\u0e21 IT \u0e41\u0e25\u0e30 Security<\/h2>\n<ul>\n<li>\u0e15\u0e23\u0e27\u0e08 Microsoft Security Update Guide \u0e41\u0e25\u0e30 vendor advisory \u0e25\u0e48\u0e32\u0e2a\u0e38\u0e14<\/li>\n<li>map CVE \u0e01\u0e31\u0e1a asset\/version\/configuration \u0e08\u0e23\u0e34\u0e07<\/li>\n<li>\u0e40\u0e23\u0e48\u0e07\u0e23\u0e30\u0e1a\u0e1a\u0e17\u0e35\u0e48 exploited, public-facing \u0e41\u0e25\u0e30 business-critical<\/li>\n<li>\u0e17\u0e14\u0e2a\u0e2d\u0e1a canary \u0e41\u0e25\u0e30\u0e40\u0e15\u0e23\u0e35\u0e22\u0e21 rollback<\/li>\n<li>\u0e1a\u0e31\u0e07\u0e04\u0e31\u0e1a reboot \u0e40\u0e21\u0e37\u0e48\u0e2d update \u0e15\u0e49\u0e2d\u0e07\u0e01\u0e32\u0e23<\/li>\n<li>verify \u0e14\u0e49\u0e27\u0e22 build\/KB \u0e41\u0e25\u0e30 authenticated scan<\/li>\n<li>hunt \u0e22\u0e49\u0e2d\u0e19\u0e2b\u0e25\u0e31\u0e07\u0e1a\u0e19 asset \u0e17\u0e35\u0e48\u0e21\u0e35 exposure \u0e01\u0e48\u0e2d\u0e19\u0e41\u0e1e\u0e15\u0e0a\u0e4c<\/li>\n<li>\u0e2d\u0e31\u0e1b\u0e40\u0e14\u0e15 golden image, template \u0e41\u0e25\u0e30 recovery image<\/li>\n<li>\u0e1b\u0e34\u0e14 exception \u0e17\u0e35\u0e48\u0e2b\u0e21\u0e14\u0e2d\u0e32\u0e22\u0e38<\/li>\n<li>\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19 coverage \u0e15\u0e32\u0e21 criticality \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e08\u0e33\u0e19\u0e27\u0e19\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e23\u0e27\u0e21<\/li>\n<\/ul>\n<h2>\u5e38\u89c1\u95ee\u9898<\/h2>\n<h3>Microsoft \u0e41\u0e01\u0e49 200 \u0e2b\u0e23\u0e37\u0e2d 208 \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e01\u0e31\u0e19\u0e41\u0e19\u0e48<\/h3>\n<p>\u0e17\u0e31\u0e49\u0e07\u0e2a\u0e2d\u0e07\u0e15\u0e31\u0e27\u0e40\u0e25\u0e02\u0e1b\u0e23\u0e32\u0e01\u0e0f\u0e08\u0e32\u0e01\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e17\u0e35\u0e48\u0e43\u0e0a\u0e49\u0e27\u0e34\u0e18\u0e35\u0e19\u0e31\u0e1a\u0e15\u0e48\u0e32\u0e07\u0e01\u0e31\u0e19 BleepingComputer \u0e23\u0e32\u0e22\u0e07\u0e32\u0e19 200 \u0e2a\u0e48\u0e27\u0e19 ZDI \u0e23\u0e32\u0e22\u0e07\u0e32\u0e19 208 \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e01\u0e32\u0e23\u0e1b\u0e0f\u0e34\u0e1a\u0e31\u0e15\u0e34\u0e07\u0e32\u0e19\u0e04\u0e27\u0e23\u0e43\u0e0a\u0e49 Microsoft Security Update Guide \u0e41\u0e25\u0e30 catalog \u0e02\u0e2d\u0e07\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e21\u0e37\u0e2d patch \u0e40\u0e1e\u0e37\u0e48\u0e2d map \u0e01\u0e31\u0e1a\u0e1c\u0e25\u0e34\u0e15\u0e20\u0e31\u0e13\u0e11\u0e4c\u0e08\u0e23\u0e34\u0e07<\/p>\n<h3>\u0e21\u0e35 Zero-Day \u0e01\u0e35\u0e48\u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e43\u0e19 Patch Tuesday \u0e21\u0e34\u0e16\u0e38\u0e19\u0e32\u0e22\u0e19 2026<\/h3>\n<p>\u0e21\u0e35 6 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e15\u0e32\u0e21\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19\u0e2b\u0e25\u0e31\u0e01 \u0e42\u0e14\u0e22 5 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e16\u0e39\u0e01\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e15\u0e48\u0e2d\u0e2a\u0e32\u0e18\u0e32\u0e23\u0e13\u0e30\u0e01\u0e48\u0e2d\u0e19\u0e41\u0e1e\u0e15\u0e0a\u0e4c \u0e41\u0e25\u0e30 1 \u0e23\u0e32\u0e22\u0e01\u0e32\u0e23\u0e16\u0e39\u0e01\u0e43\u0e0a\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e08\u0e23\u0e34\u0e07 \u0e2a\u0e16\u0e32\u0e19\u0e30\u0e2d\u0e32\u0e08\u0e40\u0e1b\u0e25\u0e35\u0e48\u0e22\u0e19\u0e40\u0e21\u0e37\u0e48\u0e2d Microsoft \u0e2b\u0e23\u0e37\u0e2d CISA \u0e2d\u0e31\u0e1b\u0e40\u0e14\u0e15\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25 \u0e08\u0e36\u0e07\u0e04\u0e27\u0e23\u0e15\u0e23\u0e27\u0e08 advisory \u0e25\u0e48\u0e32\u0e2a\u0e38\u0e14<\/p>\n<h3>\u0e04\u0e27\u0e23\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07\u0e17\u0e38\u0e01\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e17\u0e31\u0e19\u0e17\u0e35\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e17\u0e38\u0e01\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e04\u0e27\u0e23\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19 SLA \u0e41\u0e15\u0e48\u0e25\u0e33\u0e14\u0e31\u0e1a\u0e41\u0e25\u0e30\u0e27\u0e34\u0e18\u0e35 deploy \u0e15\u0e49\u0e2d\u0e07\u0e2d\u0e34\u0e07\u0e04\u0e27\u0e32\u0e21\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07 \u0e23\u0e30\u0e1a\u0e1a\u0e17\u0e35\u0e48\u0e16\u0e39\u0e01 exploit \u0e2b\u0e23\u0e37\u0e2d\u0e40\u0e1b\u0e34\u0e14 internet \u0e04\u0e27\u0e23\u0e40\u0e23\u0e48\u0e07\u0e01\u0e27\u0e48\u0e32\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e17\u0e35\u0e48 isolated \u0e02\u0e13\u0e30\u0e40\u0e14\u0e35\u0e22\u0e27\u0e01\u0e31\u0e19 mission-critical system \u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35 canary, backup \u0e41\u0e25\u0e30 rollback plan<\/p>\n<h3>\u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e41\u0e25\u0e49\u0e27\u0e15\u0e49\u0e2d\u0e07\u0e17\u0e33 Incident Response \u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e16\u0e49\u0e32\u0e23\u0e30\u0e1a\u0e1a\u0e40\u0e04\u0e22\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19\u0e2a\u0e20\u0e32\u0e1e\u0e17\u0e35\u0e48 exploit \u0e44\u0e14\u0e49\u0e01\u0e48\u0e2d\u0e19\u0e41\u0e1e\u0e15\u0e0a\u0e4c \u0e42\u0e14\u0e22\u0e40\u0e09\u0e1e\u0e32\u0e30 internet-facing \u0e2b\u0e23\u0e37\u0e2d CVE \u0e17\u0e35\u0e48\u0e16\u0e39\u0e01\u0e43\u0e0a\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e08\u0e23\u0e34\u0e07 \u0e04\u0e27\u0e23\u0e17\u0e33 compromise assessment \u0e40\u0e1e\u0e23\u0e32\u0e30\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e44\u0e21\u0e48\u0e25\u0e1a webshell, account \u0e2b\u0e23\u0e37\u0e2d persistence \u0e40\u0e14\u0e34\u0e21<\/p>\n<h3>Penetration Testing \u0e41\u0e17\u0e19 Patch Management \u0e44\u0e14\u0e49\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e44\u0e21\u0e48\u0e44\u0e14\u0e49 Pentest \u0e40\u0e1b\u0e47\u0e19\u0e01\u0e32\u0e23\u0e17\u0e14\u0e2a\u0e2d\u0e1a\u0e40\u0e0a\u0e34\u0e07\u0e15\u0e31\u0e27\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e20\u0e32\u0e22\u0e43\u0e15\u0e49\u0e40\u0e27\u0e25\u0e32\u0e41\u0e25\u0e30\u0e02\u0e2d\u0e1a\u0e40\u0e02\u0e15 \u0e2a\u0e48\u0e27\u0e19 patch management \u0e25\u0e14 known vulnerability \u0e2d\u0e22\u0e48\u0e32\u0e07\u0e15\u0e48\u0e2d\u0e40\u0e19\u0e37\u0e48\u0e2d\u0e07 \u0e17\u0e31\u0e49\u0e07\u0e2a\u0e2d\u0e07\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e40\u0e2a\u0e23\u0e34\u0e21\u0e01\u0e31\u0e19\u0e41\u0e15\u0e48\u0e44\u0e21\u0e48\u0e17\u0e14\u0e41\u0e17\u0e19\u0e01\u0e31\u0e19<\/p>\n<h2>\u603b\u7ed3<\/h2>\n<p>Microsoft Patch Tuesday \u0e21\u0e34\u0e16\u0e38\u0e19\u0e32\u0e22\u0e19 2026 \u0e41\u0e2a\u0e14\u0e07\u0e43\u0e2b\u0e49\u0e40\u0e2b\u0e47\u0e19\u0e27\u0e48\u0e32\u0e1b\u0e23\u0e34\u0e21\u0e32\u0e13\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e01\u0e33\u0e25\u0e31\u0e07\u0e17\u0e49\u0e32\u0e17\u0e32\u0e22\u0e27\u0e34\u0e18\u0e35\u0e17\u0e33\u0e07\u0e32\u0e19\u0e41\u0e1a\u0e1a\u0e40\u0e23\u0e35\u0e22\u0e07\u0e15\u0e32\u0e21 CVSS \u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e17\u0e35\u0e48\u0e21\u0e35\u0e1b\u0e23\u0e30\u0e2a\u0e34\u0e17\u0e18\u0e34\u0e20\u0e32\u0e1e\u0e15\u0e49\u0e2d\u0e07\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21 exploit intelligence, exposure, criticality \u0e41\u0e25\u0e30 control strength \u0e40\u0e02\u0e49\u0e32\u0e01\u0e31\u0e1a asset owner \u0e41\u0e25\u0e30 verification \u0e17\u0e35\u0e48\u0e27\u0e31\u0e14\u0e44\u0e14\u0e49<\/p>\n<p>\u0e40\u0e1b\u0e49\u0e32\u0e2b\u0e21\u0e32\u0e22\u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e01\u0e32\u0e23\u0e1b\u0e23\u0e30\u0e01\u0e32\u0e28\u0e27\u0e48\u0e32 \u201cdeploy 100%\u201d \u0e41\u0e15\u0e48\u0e04\u0e37\u0e2d\u0e01\u0e32\u0e23\u0e1e\u0e34\u0e2a\u0e39\u0e08\u0e19\u0e4c\u0e27\u0e48\u0e32\u0e23\u0e30\u0e1a\u0e1a\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07\u0e2a\u0e39\u0e07\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e01\u0e32\u0e23\u0e1b\u0e34\u0e14\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e08\u0e23\u0e34\u0e07 \u0e44\u0e21\u0e48\u0e21\u0e35\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e15\u0e01\u0e2b\u0e25\u0e48\u0e19 \u0e41\u0e25\u0e30\u0e17\u0e35\u0e21\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e15\u0e23\u0e27\u0e08\u0e01\u0e32\u0e23\u0e42\u0e08\u0e21\u0e15\u0e35\u0e01\u0e48\u0e2d\u0e19\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e44\u0e14\u0e49\u0e17\u0e31\u0e19\u0e40\u0e27\u0e25\u0e32<\/p>\n<h2>\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e2d\u0e49\u0e32\u0e07\u0e2d\u0e34\u0e07<\/h2>\n<ol>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws\/\" target=\"_blank\" rel=\"noopener\">BleepingComputer \u2014 Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws<\/a><\/li>\n<li><a href=\"https:\/\/www.thezdi.com\/blog\/2026\/6\/9\/the-june-2026-security-update-review\" target=\"_blank\" rel=\"noopener\">Zero Day Initiative \u2014 The June 2026 Security Update Review<\/a><\/li>\n<li><a href=\"https:\/\/www.rapid7.com\/blog\/post\/em-patch-tuesday-june-2026\/\" target=\"_blank\" rel=\"noopener\">Rapid7 \u2014 Patch Tuesday June 2026<\/a><\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/\" target=\"_blank\" rel=\"noopener\">Microsoft Security Update Guide<\/a><\/li>\n<\/ol>","protected":false},"excerpt":{"rendered":"<p>\u0e2a\u0e23\u0e38\u0e1b Microsoft Patch Tuesday \u0e40\u0e14\u0e37\u0e2d\u0e19\u0e21\u0e34\u0e16\u0e38\u0e19\u0e32\u0e22\u0e19 2026 \u0e0b\u0e36\u0e48\u0e07\u0e41\u0e01\u0e49 200 \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 \u0e23\u0e27\u0e21 6 Zero-Day \u0e1e\u0e23\u0e49\u0e2d\u0e21\u0e27\u0e34\u0e18\u0e35\u0e08\u0e31\u0e14\u0e25\u0e33\u0e14\u0e31\u0e1a\u0e41\u0e1e\u0e15\u0e0a\u0e4c \u0e15\u0e23\u0e27\u0e08 exposure \u0e41\u0e25\u0e30\u0e17\u0e14\u0e2a\u0e2d\u0e1a\u0e01\u0e48\u0e2d\u0e19 deploy \u0e43\u0e19\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23<\/p>","protected":false},"author":0,"featured_media":18426,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[264,265],"tags":[308,304,309,305,306,307,289],"class_list":["post-18394","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-zero-day-vulnerability","tag-cve","tag-microsoft","tag-patch-management","tag-patch-tuesday","tag-vulnerability","tag-windows","tag-zero-day"],"acf":[],"rttpg_featured_image_url":{"full":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07.jpg",1200,630,false],"landscape":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07.jpg",1200,630,false],"portraits":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07.jpg",1200,630,false],"thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07-150x150.jpg",150,150,true],"medium":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07-300x158.jpg",300,158,true],"large":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07-1024x538.jpg",1024,538,true],"1536x1536":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07.jpg",1200,630,false],"2048x2048":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07.jpg",1200,630,false],"trp-custom-language-flag":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07-18x9.jpg",18,9,true],"woocommerce_thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07-300x300.jpg",300,300,true],"woocommerce_single":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07-600x315.jpg",600,315,true],"woocommerce_gallery_thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/07-100x100.jpg",100,100,true]},"rttpg_author":{"display_name":"","author_link":"https:\/\/droneth.or.th\/zh\/author\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/droneth.or.th\/zh\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/droneth.or.th\/zh\/category\/cybersecurity\/zero-day-vulnerability\/\" rel=\"category tag\">Zero-Day \u0e41\u0e25\u0e30\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48<\/a>","rttpg_excerpt":"\u0e2a\u0e23\u0e38\u0e1b Microsoft Patch Tuesday \u0e40\u0e14\u0e37\u0e2d\u0e19\u0e21\u0e34\u0e16\u0e38\u0e19\u0e32\u0e22\u0e19 2026 \u0e0b\u0e36\u0e48\u0e07\u0e41\u0e01\u0e49 200 \u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 \u0e23\u0e27\u0e21 6 Zero-Day \u0e1e\u0e23\u0e49\u0e2d\u0e21\u0e27\u0e34\u0e18\u0e35\u0e08\u0e31\u0e14\u0e25\u0e33\u0e14\u0e31\u0e1a\u0e41\u0e1e\u0e15\u0e0a\u0e4c \u0e15\u0e23\u0e27\u0e08 exposure \u0e41\u0e25\u0e30\u0e17\u0e14\u0e2a\u0e2d\u0e1a\u0e01\u0e48\u0e2d\u0e19 deploy \u0e43\u0e19\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23","_links":{"self":[{"href":"https:\/\/droneth.or.th\/zh\/wp-json\/wp\/v2\/posts\/18394","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/droneth.or.th\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/droneth.or.th\/zh\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/droneth.or.th\/zh\/wp-json\/wp\/v2\/comments?post=18394"}],"version-history":[{"count":1,"href":"https:\/\/droneth.or.th\/zh\/wp-json\/wp\/v2\/posts\/18394\/revisions"}],"predecessor-version":[{"id":18401,"href":"https:\/\/droneth.or.th\/zh\/wp-json\/wp\/v2\/posts\/18394\/revisions\/18401"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/droneth.or.th\/zh\/wp-json\/wp\/v2\/media\/18426"}],"wp:attachment":[{"href":"https:\/\/droneth.or.th\/zh\/wp-json\/wp\/v2\/media?parent=18394"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/droneth.or.th\/zh\/wp-json\/wp\/v2\/categories?post=18394"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/droneth.or.th\/zh\/wp-json\/wp\/v2\/tags?post=18394"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}