Microsoft’s July 2026 Patch Tuesday fixes a record 570 bugs, including three zero days


microsoft has released July 2026 Patch Tuesday security updates, addressing a record 570 vulnerabilities. This includes two zero-day exploits used in attacks and one zero-day vulnerability that has been publicly disclosed.

The update fixes 59 vulnerabilities classified as critical. These include 48 issues related to remote code execution, nine elevation of privilege flaws, one security bypass, and one phishing vulnerability. Users are recommended to install the update as soon as possible through Windows Update.

Microsoft has linked the increase in patched vulnerabilities to an AI-powered vulnerability discovery system that has identified more security flaws across the Windows code base.

Vulnerability breakdown and three zero days fixed

The 570 vulnerabilities are classified as follows:

  • 254 are issues of elevation of privilege,
  • 145 are remote code execution issues,
  • 102 involve Disclosure of Information, 35 are related to Denial of Service,
  • 17 are security feature bypass vulnerabilities and
  • 16 belong to identity theft.

This count does not include individual fixes for Mariner, Azure OpenAI, Azure Synapse, M365 Copilot, Microsoft Exchange Online, Microsoft Edge for Android, and Microsoft Entra Provisioning Service, which were addressed earlier this month.

It also excludes 468 bugs in Microsoft Edge and Chromium that were fixed by Google and then ported to Edge.

CVE-2026-56155: Active Directory Federation Services Privilege Elevation

An actively exploited vulnerability in Active Directory Federation Services allows attackers to gain administrative privileges. Microsoft explains that the issue involves insufficient granularity of access control in Active Directory Federation Services (AD FS), which allows an authorized attacker to elevate privileges locally.

The flaw was identified by Jeremy Kingston and Scott Clark of the Microsoft Detection and Response Team (DART), the company’s incident response unit.

The attribution to DART suggests that the vulnerability was discovered during active attack investigations. Microsoft has not released specific details about how the flaw was exploited.

CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege

A vulnerability in Microsoft SharePoint Server is being actively exploited that allows attackers to remotely access systems and gain elevated privileges. Microsoft says the issue involves a lack of authentication for a critical feature in SharePoint, which could allow an unauthorized attacker to elevate privileges on a network.

To mitigate the issue, Microsoft recommends enabling the Anti-Malware Scanning Interface (AMSI) on the server and setting the Request Body Scan mode to Full.

The failure was attributed to Jayson Frost of Mandiant Incident Response, Genwei Jiang of Google Cloud, FLARE OTF, and an anonymous researcher. Microsoft has not revealed how the flaw was exploited.

CVE-2026-50661: Bypass of the Windows BitLocker security feature

A publicly known vulnerability in BitLocker could allow attackers with physical access to bypass encryption and access encrypted data. Microsoft claims that a successful attacker could bypass the BitLocker device encryption feature on the system storage device. An attacker with physical access could exploit this vulnerability to gain access to encrypted data. The failure was attributed to an anonymous researcher.

Critical flaws in Windows, Office, SharePoint and more

Notable critical severity vulnerabilities include:

  • CVE-2026-49164: Active Directory Domain Services Remote Code Execution
  • CVE-2026-54121: Active Directory Certificate Services Privilege Elevation
  • CVE-2026-48561: Microsoft Copilot Remote Code Execution
  • CVE-2026-55012 and CVE-2026-55011: Microsoft Defender Remote Code Execution
  • CVE-2026-55129: Microsoft Office Remote Code Execution
  • Multiple critical RCE vulnerabilities in Microsoft SharePoint, Office, Word, PowerPoint, and Excel
  • Multiple critical Windows Media Foundation RCE vulnerabilities
  • CVE-2026-54118 and CVE-2026-54117: Microsoft SQL Server Remote Code Execution
  • CVE-2026-58608: Windows Print Spooler Remote Code Execution
  • CVE-2026-49796 and CVE-2026-50380: Windows GDI+ Remote Code Execution
  • CVE-2026-54999: Windows TCP/IP Remote Code Execution
  • CVE-2026-50444: Windows Server Update Service (WSUS) Privilege Elevation
  • CVE-2026-58542 and CVE-2026-50327: Windows Media Remote Code Execution
  • CVE-2026-50694: Windows Secure Socket Tunneling Protocol Remote Code Execution
  • CVE-2026-50392 and CVE-2026-42982: Elevation of Privilege in Windows Secure Kernel Mode
  • CVE-2026-57092: Windows VMSwitch Privilege Elevation

The scope of the patched vulnerabilities affects the Windows client and server, Office applications, SharePoint, Exchange, SQL Server, .NET Framework, Visual Studio, Copilot, and other components.

How AI Powered This Record-Breaking Patch and What Users Should Do

Microsoft announced last week that Patch Tuesday updates would be larger this month, thanks to a new AI-powered vulnerability discovery system that identifies security flaws in the Windows code base before attackers can exploit them. The July update reflects this change.

This trend is also evident throughout the industry. For example, Anthropic’s Mythos model found vulnerabilities in classified US government systems during testing, and Nebula Security’s VEGA AI agent recently discovered an old flaw in the 15-year-old GhostLock Linux kernel. AI-assisted vulnerability detection is now yielding more findings across major software platforms.

For Windows 11 and Windows 10 users:

  1. Open Settings, then go to Windows Update.
  2. Click Check for updates.
  3. Install the updates available from July Patch Tuesday.
  4. Restart your device when prompted.

On Windows 11, the update is delivered via cumulative updates KB5101650 and KB5099414. Windows 10 users receiving extended security updates will get them through KB5099539.

For SharePoint Server administrators:

  • Install the latest SharePoint updates as soon as possible, especially given the active exploitation of CVE-2026-56164.
  • Enable the anti-malware scanning interface on SharePoint servers.
  • Set the Request Body Scan mode to Full for better mitigation.
  • Check SharePoint access logs for signs of past exploitation.

For Active Directory Federation Services administrators:

  • Install updates for CVE-2026-56155, which is actively exploited.
  • Review administrative access logs for any unusual privilege escalations.
  • Verify the AD FS federation trust configuration.

For BitLocker users:

  • Install the latest update to address the publicly disclosed CVE-2026-50661 bypass.
  • Make sure recovery keys are stored securely, either in a Microsoft account or in Active Directory.
  • Consider whether additional physical security measures are needed for devices with encrypted sensitive data.

Non-security updates and availability

Additional non-security updates for Windows 11 and Windows 10 are included in the same Patch Tuesday cumulative updates. Users interested in non-security fixes can find details in the Microsoft release notes associated with the KB articles relevant to their version of Windows.

The July 2026 Patch Tuesday updates are now available through Windows Update, Microsoft Update Catalog, and WSUS. Enterprise administrators using SCCM, Intune, or other management tools should synchronize their update repositories to ensure that fixes are distributed.

Users running Windows 10 who are not enrolled in the Extended Security Updates program will not receive these updates. Enrollment for Windows 10 ESU is available through four methods documented by Microsoft, with coverage extended through October 12, 2027, as announced in June.

It is recommended that users install these updates as soon as possible. Since two actively exploited zero-day vulnerabilities are addressed in this release, delaying the patching process could increase the risk of exploitation as attackers are already exploiting some of the vulnerabilities.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *