Microsoft Releases July 2026 Security Patches Addressing 622 Vulnerabilities Microsoft has released its monthly security update for July 2026, addressing 622 vulnerabilities across its products. Among these, 57 are classified as "critical," with two of the vulnerabilities already exploited in the wild. The update includes detailed information on the nature of these flaws, their potential impact, and the systems they affect. Two critical vulnerabilities, CVE-2026-56155 and CVE-2026-56164, have been exploited in real-world attacks. CVE-2026-56155 is an elevation of privilege flaw in Active Directory Federation Services (AD FS), allowing an authorized attacker to escalate privileges locally due to insufficient access control. CVE-2026-56164 is a spoofing vulnerability in Microsoft SharePoint Server, enabling an unauthorized attacker to impersonate users over a network due to missing authentication for critical functions. The 57 critical vulnerabilities are categorized into four types: 48 remote code execution (RCE) flaws, seven elevation of privilege (EoP) issues, one spoofing vulnerability, and one security feature bypass. The RCE vulnerabilities span a wide range of Microsoft products, including Windows services, Office applications, SharePoint, SQL Server, and cloud services. Notably, 11 of the critical RCE vulnerabilities are rated "more likely" to be exploited. Among the most significant RCE vulnerabilities are several heap-based buffer overflows in the Windows DHCP Server service, such as CVE-2026-50370 and CVE-2026-50518, which allow unauthorized attackers to execute code remotely. CVE-2026-54128 is a use-after-free vulnerability in the Windows DHCP client, enabling local code execution.#microsoft #cve_2026_56155 #cve_2026_56164 #active_directory_federation_services #microsoft_sharepoint_server