Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Microsoft July 2026 Patch Tuesday Fixes Record 570 Flaws Including Three Zero-Days

Дата публикации: 15-07-2026 10:51:56

Microsoft has released the July 2026 Patch Tuesday security updates, addressing a record 570 vulnerabilities.
Thank you for being a Ghacks reader. The post Microsoft July 2026 Patch Tuesday Fixes Record 570 Flaws Including Three Zero-Days appeared first on gHacks.


Основное содержимое страницы с новостью.

Microsoft has released the July 2026 Patch Tuesday security updates, addressing a record 570 vulnerabilities. This includes two zero-day exploits used in attacks and one zero-day vulnerability that has been publicly disclosed.

The update fixes 59 vulnerabilities rated as Critical. These include 48 issues related to remote code execution, nine privileges elevation flaws, one security bypass, and one spoofing vulnerability. Users are advised to install the update promptly through Windows Update.

Microsoft has linked the increase in patched vulnerabilities to an AI-powered vulnerability discovery system that has identified more security flaws across the Windows codebase.

Vulnerability Breakdown and Three Zero-Days Fixed

The 570 vulnerabilities are categorized as follows:

  • 254 are Elevation of Privilege issues,
  • 145 are Remote Code Execution problems,
  • 102 involve Information Disclosure, 35 are related to Denial of Service,
  • 17 are Security Feature Bypass vulnerabilities, and
  • 16 pertain to Spoofing.

This count does not include individual fixes for Mariner, Azure OpenAI, Azure Synapse, M365 Copilot, Microsoft Exchange Online, Microsoft Edge for Android, and Microsoft Entra Provisioning Service, which were addressed earlier this month.

It also excludes 468 flaws in Microsoft Edge and Chromium that were fixed by Google and later ported to Edge.

CVE-2026-56155: Active Directory Federation Services Elevation of Privilege

An actively exploited vulnerability in Active Directory Federation Services allows attackers to gain administrative privileges. Microsoft explains that the issue involves insufficient granularity of access control in Active Directory Federation Services (AD FS), which enables an authorized attacker to elevate privileges locally.

The flaw was identified by Jeremy Kingston and Scott Clark of Microsoft's Detection and Response Team (DART), the company's incident response unit.

The attribution to DART suggests the vulnerability was discovered during active attack investigations. Microsoft has not released specific details on how the flaw was exploited.

CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege

A vulnerability in Microsoft SharePoint Server is actively being exploited and allows attackers to remote into systems and gain elevated privileges. Microsoft states that the issue involves missing authentication for a critical function in SharePoint, which could let an unauthorized attacker elevate privileges over a network.

To mitigate the problem, Microsoft recommends enabling the Antimalware Scan Interface (AMSI) on the server and setting the Request Body Scan mode to Full.

The flaw was credited to Jayson Frost from Mandiant Incident Response, Genwei Jiang from Google Cloud, FLARE OTF, and an anonymous researcher. Microsoft has not disclosed how the flaw was exploited.

CVE-2026-50661: Windows BitLocker Security Feature Bypass

A publicly known vulnerability in BitLocker could allow attackers with physical access to bypass the encryption and access encrypted data. Microsoft states that a successful attacker could bypass the BitLocker Device Encryption feature on the system storage device. An attacker with physical access could exploit this vulnerability to gain access to encrypted data. The flaw was credited to an anonymous researcher.

Critical Flaws Across Windows, Office, SharePoint, and More

Notable critical-severity vulnerabilities include:

  • CVE-2026-49164: Active Directory Domain Services Remote Code Execution
  • CVE-2026-54121: Active Directory Certificate Services Elevation of Privilege
  • CVE-2026-48561: Microsoft Copilot Remote Code Execution
  • CVE-2026-55012 and CVE-2026-55011: Microsoft Defender Remote Code Execution
  • CVE-2026-55129: Microsoft Office Remote Code Execution
  • Multiple Microsoft SharePoint, Office, Word, PowerPoint, and Excel Critical RCE vulnerabilities
  • Multiple Windows Media Foundation Critical RCE vulnerabilities
  • CVE-2026-54118 and CVE-2026-54117: Microsoft SQL Server Remote Code Execution
  • CVE-2026-58608: Windows Print Spooler Remote Code Execution
  • CVE-2026-49796 and CVE-2026-50380: Windows GDI+ Remote Code Execution
  • CVE-2026-54999: Windows TCP/IP Remote Code Execution
  • CVE-2026-50444: Windows Server Update Service (WSUS) Elevation of Privilege
  • CVE-2026-58542 and CVE-2026-50327: Windows Media Remote Code Execution
  • CVE-2026-50694: Windows Secure Socket Tunneling Protocol Remote Code Execution
  • CVE-2026-50392 and CVE-2026-42982: Windows Secure Kernel Mode Elevation of Privilege
  • CVE-2026-57092: Windows VMSwitch Elevation of Privilege

The scope of the patched vulnerabilities affects Windows client and server, Office applications, SharePoint, Exchange, SQL Server, .NET Framework, Visual Studio, Copilot, and other components.

How AI Drove This Record Patch and What Users Should Do

Microsoft announced last week that Patch Tuesday updates would be larger this month, thanks to a new AI-powered vulnerability discovery system that identifies security flaws across the Windows codebase before attackers can exploit them. The July update reflects this shift.

This trend is also evident across the industry. For example, Anthropic's Mythos model found vulnerabilities in classified US government systems during testing, and Nebula Security's VEGA AI agent recently uncovered an old GhostLock Linux kernel flaw from 15 years ago. AI-assisted vulnerability detection is now yielding more findings across major software platforms.

For Windows 11 and Windows 10 users:

  1. Open Settings, then go to Windows Update.
  2. Click Check for updates.
  3. Install the available July Patch Tuesday updates.
  4. Restart your device when prompted.

On Windows 11, the update is delivered through the cumulative updates KB5101650 and KB5099414. Windows 10 users receiving Extended Security Updates will get it via KB5099539.

For SharePoint Server administrators:

  • Install the latest SharePoint updates as soon as possible, especially given the active exploitation of CVE-2026-56164.
  • Enable the Antimalware Scan Interface on SharePoint servers.
  • Set Request Body Scan mode to Full to improve mitigation.
  • Check SharePoint access logs for any signs of past exploitation.

For Active Directory Federation Services administrators:

  • Install updates for CVE-2026-56155, which is actively exploited.
  • Review administrative access logs for any unusual privilege escalation.
  • Verify the configuration of AD FS federation trust settings.

For BitLocker users:

  • Install the latest update to address the publicly disclosed CVE-2026-50661 bypass.
  • Make sure recovery keys are stored securely, either in a Microsoft account or in Active Directory.
  • Consider whether additional physical security measures are needed for devices with encrypted sensitive data.
Non-Security Updates and Availability

Additional non-security updates for Windows 11 and Windows 10 are included in the same Patch Tuesday cumulative updates. Users interested in non-security fixes can find details in Microsoft's release notes associated with the relevant KB articles for their Windows version.

The July 2026 Patch Tuesday updates are now available through Windows Update, Microsoft Update Catalog, and WSUS. Enterprise administrators using SCCM, Intune, or other management tools should synchronize their update repositories to ensure the fixes are distributed.

Users running Windows 10 who are not enrolled in the Extended Security Updates program will not receive these updates. Enrollment for Windows 10 ESU is available through four methods documented by Microsoft, with coverage extended through October 12, 2027, as announced in June.

It is advised that users install these updates promptly. Since two actively exploited zero-day vulnerabilities are addressed in this release, delaying the patching process could increase the risk of exploitation, as attackers are already leveraging some of the vulnerabilities.

Add Ghacks as a preferred source on Google

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Windows 11 Version 26H2 Ships as an Enablement Package With No New Features Over 25H206.8820-07-2026
2Microsoft Extends Windows Server 2022 Hotpatching Through October 20270530-06-2026
3Microsoft Blocks Windows 11 KB5101650 Update on Some Dell Devices Over Shutdown Issue09.6116-07-2026
4Microsoft Weekly: Patch Tuesday updates, Microsoft accounts drama, Fallout 5 news, and more0518-07-2026
52026 Game Release Schedule: GTA 6, Halo Campaign Evolved, and Forza Horizon 6 Headline the Year011.2619-07-2026
6Adobe Patches Acrobat Chrome Extension Flaw That Exposed WhatsApp Web Chats to Any Website03.9323-07-2026
7Microsoft Confirms Windows 11 Bug That Can Consume Over 500GB of Storage Through Permission Log File-2608-07-2026
8Microsoft Tests Cloud Rebuild Recovery Option in Windows 11 Insider Builds0507-07-2026
9Opera Reports 66% Android Growth in UK and 40% in US Year Over Year for Q208.2415-07-2026
10 Microsoft confirms Windows 11 26H2 is another boring update that does nothing — but here's why I'm happy about that 1322-06-2026

Классификация: Общество. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 13.29. Источник: www.ghacks.net.