Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days

Microsoft’s July Patch Tuesday Brings Record-Breaking Fixes for 570 Flaws, Including Three Zero-Day Vulnerabilities

In a massive effort to plug security holes in its products, Microsoft has released patches for an astonishing 570 flaws, including three zero-day vulnerabilities that have been exploited by attackers. The update is part of the company’s monthly Patch Tuesday cycle, which aims to address critical issues and prevent cyber threats.

The severity of these vulnerabilities cannot be overstated. Among the 570 flaws fixed this month are 59 classified as “Critical,” a designation given to weaknesses that can allow an attacker to remotely take control of a system or steal sensitive data. The majority of these critical vulnerabilities, 48 in total, are remote code execution (RCE) flaws, which enable attackers to run malicious code on a target device.

The sheer number of vulnerabilities addressed this month is a testament to Microsoft’s efforts to stay ahead of cyber threats. As part of its recent update to its vulnerability discovery system, the company has begun using artificial intelligence (AI) to identify security weaknesses in its Windows codebase before they can be exploited by attackers. This proactive approach aims to reduce the number of zero-day vulnerabilities that make it into the wild.

Three of these zero-day flaws have been addressed this month: CVE-2026-56155, an elevation of privilege vulnerability in Active Directory Federation Services (AD FS); CVE-2026-56164, a similar flaw in Microsoft SharePoint Server; and CVE-2026-50661, a security feature bypass vulnerability in Windows BitLocker. Two of these vulnerabilities have been actively exploited by attackers, while the third was publicly disclosed.

The first two zero-day flaws are particularly concerning. The AD FS vulnerability allows an authorized attacker to elevate privileges locally, essentially giving them unrestricted access to a system. Microsoft has credited its detection and response team with uncovering this flaw, which was likely discovered during an investigation into active attacks.

In contrast, the SharePoint Server flaw is more complex, requiring a remote attacker to exploit missing authentication for critical functions in order to gain elevated privileges. Microsoft has provided guidance on mitigating this vulnerability, including enabling the Antimalware Scan Interface (AMSI) and setting the Request Body Scan mode to Full.

The publicly disclosed BitLocker bypass vulnerability is equally concerning. If exploited, it could allow attackers to access encrypted data, even if they have physical access to a system’s storage device.

While Microsoft has taken significant steps to address these vulnerabilities, users should remain vigilant. With so many flaws fixed in a single update, there’s a risk that some of these vulnerabilities may still be actively exploited by attackers who haven’t yet received the patch. To stay secure, it’s essential to install all available updates as soon as possible and ensure that your systems are properly configured to prevent exploitation.

In addition to Microsoft’s Patch Tuesday update, other companies have also released security patches this month. Adobe, for example, has patched seven max-severity ColdFusion and Campaign flaws, including a critical vulnerability in its ColdFusion product.


Source: Bleeping Computer — 2026-07-14