Microsoft’s July Patch Tuesday brings record-breaking 570 fixes, including three zero-day vulnerabilities that have been exploited in attacks. This month’s update is one of the largest ever released by Microsoft, with 59 critical vulnerabilities addressed.
The patch covers a wide range of software, including Windows, Office, and other products, fixing issues such as remote code execution, elevation of privilege, security bypass, and spoofing. Among the most severe flaws are two zero-day vulnerabilities that have been actively exploited in attacks: CVE-2026-56155, which affects Active Directory Federation Services (AD FS) and allows an attacker to elevate privileges locally, and CVE-2026-56164, a vulnerability in Microsoft SharePoint Server that enables a remote attacker to gain elevated privileges. Both of these flaws were likely discovered through active attack investigation.
The third zero-day fixed this month is CVE-2026-50661, a publicly disclosed Windows BitLocker security feature bypass vulnerability that could allow attackers to access encrypted data with physical access to the target system. This flaw was attributed to an anonymous researcher.
Microsoft’s use of AI-powered vulnerability discovery has led to an increase in Patch Tuesday updates as it identifies more security flaws across its Windows codebase before they can be exploited by attackers. In June, Google fixed 360 vulnerabilities that were later ported to Microsoft Edge, while this month, Google released patches for a massive 468 Microsoft Edge/Chromium flaws.
The sheer number of vulnerabilities addressed in this update highlights the ongoing need for users to keep their software up-to-date and for organizations to stay vigilant about security threats. While some of these fixes may not be immediately apparent, they are all crucial in protecting against potential attacks.
As a practical takeaway from this month’s Patch Tuesday, we advise readers to prioritize updating their systems as soon as possible, especially if they use Microsoft products. It is also essential for organizations to regularly review and apply security patches to prevent potential exploits. By doing so, users can reduce the risk of falling victim to attacks that target these vulnerabilities.
Source: Bleeping Computer — 2026-07-14