Microsoft July 2026 Patch Tuesday Fixes Record 570 Flaws Including Three Zero-Days | Free Download

Microsoft has released the July 2026 Patch Tuesday security update addressing a record 570 vulnerabilities. This includes two zero-day exploits used in the attacks and one zero-day vulnerability that has been publicly disclosed.

The update fixes 59 vulnerabilities rated as critical. These include 48 issues related to remote code execution, nine privilege elevation flaws, one security bypass, and one spoofing vulnerability. Users are advised to immediately install the update via Windows Update.

Microsoft linked the increase in patched vulnerabilities to an AI-powered vulnerability discovery system that identified more security flaws in the Windows codebase.

Vulnerability analysis and three zero-day fixes

The 570 vulnerabilities are classified as:

  • There are 254 privilege elevation issues,
  • There are 145 remote code execution issues,
  • 102 involve information disclosure, 35 relate to denial of service.
  • There are 17 security feature bypass vulnerabilities, and
  • 16 are related to spoofing.

This count does not include individual fixes for Mariner, Azure OpenAI, Azure Synapse, M365 Copilot, Microsoft Exchange Online, Microsoft Edge for Android, and Microsoft Entra Provisioning Service, which were addressed earlier this month.

This also does not include the 468 flaws in Microsoft Edge and Chromium that were fixed by Google and later ported to Edge.

CVE-2026-56155: Active Directory Federation Services elevation of privilege

Actively exploited vulnerability in Active Directory Federation Services allows attackers to gain administrative privileges. Microsoft states that the issue involves insufficient granularity of access controls in Active Directory Federation Services (AD FS), which could enable an authenticated attacker to escalate privileges locally.

The flaw was identified by Jeremy Kingston and Scott Clark of Microsoft’s Detection and Response Team (DART), the company’s incident response unit.

Attribution to DART indicates that the vulnerability was discovered during active attack investigation. Microsoft has not released specific details about how the flaw was exploited.

CVE-2026-56164: Microsoft SharePoint Server elevation of privilege

A vulnerability in Microsoft SharePoint Server is being actively exploited and allows attackers to remote into the system and gain elevated privileges. Microsoft says the issue involves a lack of authentication for a critical function in SharePoint, which could allow an unauthenticated attacker to escalate privileges on the network.

To mitigate the problem, Microsoft recommends enabling the Antimalware Scan Interface (AMSI) on the server and setting the Request Body Scan mode to Full.

The flaw was attributed to Jason Frost of Mandiant Incident Response, Zhenwei Jiang of Google Cloud, Flare OTF, and an anonymous researcher. Microsoft has not disclosed how this flaw was exploited.

CVE-2026-50661: Windows BitLocker Security Feature Bypass

A publicly known vulnerability in BitLocker could allow attackers with physical access to bypass encryption and access encrypted data. Microsoft says a successful attacker could bypass the BitLocker device encryption feature on a system storage device. An attacker with physical access could exploit this vulnerability to gain access to encrypted data. This flaw was attributed to an unknown researcher.

Critical flaws in Windows, Office, SharePoint and more

Notable critical-severity vulnerabilities include:

  • CVE-2026-49164: Active Directory Domain Services Remote Code Execution
  • CVE-2026-54121: Active Directory Certificate Services elevation of privilege
  • CVE-2026-48561: Microsoft CoPilot Remote Code Execution
  • CVE-2026-55012 and CVE-2026-55011: Microsoft Defender Remote Code Execution
  • CVE-2026-55129: Microsoft Office Remote Code Execution
  • Multiple Microsoft SharePoint, Office, Word, PowerPoint and Excel Critical RCE Vulnerabilities
  • Multiple Windows Media Foundation critical RCE vulnerabilities
  • CVE-2026-54118 and CVE-2026-54117: Microsoft SQL Server Remote Code Execution
  • CVE-2026-58608: Windows Print Spooler Remote Code Execution
  • CVE-2026-49796 and CVE-2026-50380: Windows GDI+ Remote Code Execution
  • CVE-2026-54999: Windows TCP/IP Remote Code Execution
  • CVE-2026-50444: Windows Server Update Service (WSUS) elevation of privilege
  • CVE-2026-58542 and CVE-2026-50327: Windows Media Remote Code Execution
  • CVE-2026-50694: Windows Secure Socket Tunneling Protocol Remote Code Execution
  • CVE-2026-50392 and CVE-2026-42982: Windows Secure Kernel Mode elevation of privilege
  • CVE-2026-57092: Windows VMSwitch elevation of privilege

The scope of the patched vulnerabilities affects Windows Client and Server, Office applications, SharePoint, Exchange, SQL Server, .NET Framework, Visual Studio, Copilot, and other components.

How AI drove this record patch and what users should do

Microsoft announced last week that Patch Tuesday updates will be bigger this month, thanks to a new AI-powered vulnerability detection system that identifies security flaws in the Windows codebase before attackers can exploit them. The July update reflects this change.

This trend is also evident throughout the industry. For example, Anthropic’s Mythos model found vulnerabilities in classified US government systems during testing, and Nebula Security’s Vega AI agent recently exposed an old Ghostlock Linux kernel flaw from 15 years ago. AI-assisted vulnerability detection is now yielding more findings across major software platforms.

For Windows 11 and Windows 10 users:

  1. Open Settings, then go to Windows Update.
  2. Click Check for Updates.
  3. Install the available July Patch Tuesday update.
  4. Restart your device when prompted.

On Windows 11, the update is distributed through cumulative updates KB5101650 and KB5099414. Windows 10 users who received the Extended Security Update will get it through KB5099539.

For SharePoint Server Administrators:

  • Install the latest SharePoint updates as soon as possible, especially given the active use of CVE-2026-56164.
  • Enable the antimalware scan interface on the SharePoint server.
  • Set request body scan mode to full to improve mitigation.
  • Check the SharePoint access logs for any signs of previous exploitation.

For Active Directory Federation Service administrators:

  • Install the update for CVE-2026-56155, which is actively used.
  • Review the administrative access logs for any unusual privilege escalations.
  • Verify the configuration of AD FS federation trust settings.

For BitLocker users:

  • Install the latest update to address the publicly disclosed CVE-2026-50661 bypass.
  • Make sure the recovery keys are stored securely in a Microsoft account or in Active Directory.
  • Consider whether additional physical security measures are needed for devices containing encrypted sensitive data.

Non-security updates and availability

Additional non-security updates for Windows 11 and Windows 10 are included in the same Patch Tuesday cumulative updates. Users interested in non-security fixes can find details in Microsoft’s release notes linked to the relevant KB articles for their Windows version.

The July 2026 Patch Tuesday updates are now available through Windows Update, Microsoft Update Catalog, and WSUS. Enterprise administrators using SCCM, Intune, or other management tools should synchronize their update repositories to ensure fixes are distributed.

Users running Windows 10 who are not enrolled in the Extended Security Updates program will not receive these updates. Enrollment for Windows 10 ESU is available through four methods documented by Microsoft, as announced in June, with coverage extended through October 12, 2027.

It is advised that users install these updates immediately. Since this release addresses two actively used zero-day vulnerabilities, delaying the patching process may increase the risk of exploitation, as attackers are already exploiting some of the vulnerabilities.

Thanks for being a Ghax reader. The post Microsoft July 2026 Patch Tuesday fixes a record 570 flaws, including three zero-days, appeared first on gHacks.

Source:Ghacks

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top