Microsoft has released the July 2026 Patch Tuesday security updates, addressing a record 570 vulnerabilities.
Thank you for being a Ghacks reader. The post Microsoft July 2026 Patch Tuesday Fixes Record 570 Flaws Including Three Zero-Days appeared first on gHacks.
Microsoft has released the July 2026 Patch Tuesday security updates, addressing a record 570 vulnerabilities. This includes two zero-day exploits used in attacks and one zero-day vulnerability that has been publicly disclosed.
The update fixes 59 vulnerabilities rated as Critical. These include 48 issues related to remote code execution, nine privileges elevation flaws, one security bypass, and one spoofing vulnerability. Users are advised to install the update promptly through Windows Update.
Microsoft has linked the increase in patched vulnerabilities to an AI-powered vulnerability discovery system that has identified more security flaws across the Windows codebase.
Vulnerability Breakdown and Three Zero-Days FixedThe 570 vulnerabilities are categorized as follows:
This count does not include individual fixes for Mariner, Azure OpenAI, Azure Synapse, M365 Copilot, Microsoft Exchange Online, Microsoft Edge for Android, and Microsoft Entra Provisioning Service, which were addressed earlier this month.
It also excludes 468 flaws in Microsoft Edge and Chromium that were fixed by Google and later ported to Edge.
CVE-2026-56155: Active Directory Federation Services Elevation of PrivilegeAn actively exploited vulnerability in Active Directory Federation Services allows attackers to gain administrative privileges. Microsoft explains that the issue involves insufficient granularity of access control in Active Directory Federation Services (AD FS), which enables an authorized attacker to elevate privileges locally.
The flaw was identified by Jeremy Kingston and Scott Clark of Microsoft's Detection and Response Team (DART), the company's incident response unit.
The attribution to DART suggests the vulnerability was discovered during active attack investigations. Microsoft has not released specific details on how the flaw was exploited.
CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege
A vulnerability in Microsoft SharePoint Server is actively being exploited and allows attackers to remote into systems and gain elevated privileges. Microsoft states that the issue involves missing authentication for a critical function in SharePoint, which could let an unauthorized attacker elevate privileges over a network.
To mitigate the problem, Microsoft recommends enabling the Antimalware Scan Interface (AMSI) on the server and setting the Request Body Scan mode to Full.
The flaw was credited to Jayson Frost from Mandiant Incident Response, Genwei Jiang from Google Cloud, FLARE OTF, and an anonymous researcher. Microsoft has not disclosed how the flaw was exploited.
CVE-2026-50661: Windows BitLocker Security Feature Bypass
A publicly known vulnerability in BitLocker could allow attackers with physical access to bypass the encryption and access encrypted data. Microsoft states that a successful attacker could bypass the BitLocker Device Encryption feature on the system storage device. An attacker with physical access could exploit this vulnerability to gain access to encrypted data. The flaw was credited to an anonymous researcher.
Critical Flaws Across Windows, Office, SharePoint, and MoreNotable critical-severity vulnerabilities include:
The scope of the patched vulnerabilities affects Windows client and server, Office applications, SharePoint, Exchange, SQL Server, .NET Framework, Visual Studio, Copilot, and other components.
How AI Drove This Record Patch and What Users Should DoMicrosoft announced last week that Patch Tuesday updates would be larger this month, thanks to a new AI-powered vulnerability discovery system that identifies security flaws across the Windows codebase before attackers can exploit them. The July update reflects this shift.
This trend is also evident across the industry. For example, Anthropic's Mythos model found vulnerabilities in classified US government systems during testing, and Nebula Security's VEGA AI agent recently uncovered an old GhostLock Linux kernel flaw from 15 years ago. AI-assisted vulnerability detection is now yielding more findings across major software platforms.
For Windows 11 and Windows 10 users:
On Windows 11, the update is delivered through the cumulative updates KB5101650 and KB5099414. Windows 10 users receiving Extended Security Updates will get it via KB5099539.
For SharePoint Server administrators:
For Active Directory Federation Services administrators:
For BitLocker users:
Additional non-security updates for Windows 11 and Windows 10 are included in the same Patch Tuesday cumulative updates. Users interested in non-security fixes can find details in Microsoft's release notes associated with the relevant KB articles for their Windows version.
The July 2026 Patch Tuesday updates are now available through Windows Update, Microsoft Update Catalog, and WSUS. Enterprise administrators using SCCM, Intune, or other management tools should synchronize their update repositories to ensure the fixes are distributed.
Users running Windows 10 who are not enrolled in the Extended Security Updates program will not receive these updates. Enrollment for Windows 10 ESU is available through four methods documented by Microsoft, with coverage extended through October 12, 2027, as announced in June.
It is advised that users install these updates promptly. Since two actively exploited zero-day vulnerabilities are addressed in this release, delaying the patching process could increase the risk of exploitation, as attackers are already leveraging some of the vulnerabilities.