Microsoft Releases July 2026 Security Patches Addressing 622 Vulnerabilities Microsoft has released its monthly security update for July 2026, addressing 622 vulnerabilities across its products. Among these, 57 are classified as "critical," with two of the vulnerabilities already exploited in the wild. The update includes detailed information on the nature of these flaws, their potential impact, and the systems they affect. Two critical vulnerabilities, CVE-2026-56155 and CVE-2026-56164, have been exploited in real-world attacks. CVE-2026-56155 is an elevation of privilege flaw in Active Directory Federation Services (AD FS), allowing an authorized attacker to escalate privileges locally due to insufficient access control. CVE-2026-56164 is a spoofing vulnerability in Microsoft SharePoint Server, enabling an unauthorized attacker to impersonate users over a network due to missing authentication for critical functions. The 57 critical vulnerabilities are categorized into four types: 48 remote code execution (RCE) flaws, seven elevation of privilege (EoP) issues, one spoofing vulnerability, and one security feature bypass. The RCE vulnerabilities span a wide range of Microsoft products, including Windows services, Office applications, SharePoint, SQL Server, and cloud services. Notably, 11 of the critical RCE vulnerabilities are rated "more likely" to be exploited. Among the most significant RCE vulnerabilities are several heap-based buffer overflows in the Windows DHCP Server service, such as CVE-2026-50370 and CVE-2026-50518, which allow unauthorized attackers to execute code remotely. CVE-2026-54128 is a use-after-free vulnerability in the Windows DHCP client, enabling local code execution.#microsoft #cve_2026_56155 #cve_2026_56164 #active_directory_federation_services #microsoft_sharepoint_server
Microsoft Addresses Record 570 Security Vulnerabilities in Latest Patch Tuesday Release Microsoft Corp. released a record-breaking 570 security patches on July 9, addressing vulnerabilities in its Windows operating systems and other software, nearly triple the number of fixes from its previous Patch Tuesday release. The company attributed the surge in vulnerabilities to advancements in artificial intelligence, which has accelerated the discovery of security flaws. This marks a significant shift in Microsoft’s approach to threat management, as AI tools now play a central role in identifying and mitigating risks. Among the 570 patches, 60 were labeled “critical,” meaning attackers could exploit them to gain remote control over Windows devices with minimal user interaction. Microsoft also addressed three zero-day vulnerabilities, two of which are already being exploited in the wild. These include two elevation-of-privilege flaws that allow attackers to escalate their access on Windows systems. Specific vulnerabilities fixed this month include CVE-2026-56155, a bug in Active Directory Federation Services, and CVE-2026-56164, a Microsoft SharePoint vulnerability. One of the zero-day flaws, CVE-2026-50661, is a security feature bypass in Windows BitLocker. This vulnerability could enable attackers to access encrypted data if they have physical access to the device. Microsoft noted that while the flaw has been publicly disclosed, there is no evidence of active exploitation. Microsoft’s Executive Vice President, Pavan Davuluri, highlighted in a July 9 blog post that the company will continue to increase the volume of security updates in future releases. He emphasized that AI has transformed vulnerability discovery, enabling faster identification of issues across larger codebases.#microsoft_corp #pavan_davuluri #cve_2026_56155 #cve_2026_56164 #cve_2026_50661