INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Microsoft Patches Record 622 Security Flaws
| 2026-07-15 11:56 CRITICAL MEDIUM EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The latest incident data reveals a critical vulnerability affecting multiple Microsoft products, including Windows and Office. This exploit has been identified as CVE-2026-56155 in AD FS systems and CVE-2026-56164 on SharePoint servers. Organizations must act swiftly to address this issue due to its high severity rating of 5.3 by the CVSS scoring system. The vulnerability allows attackers with local access and limited privileges to gain greater control over affected systems, while a separate zero-day exploit (CVE-2026-50661) poses an additional risk for users without BitLocker protection.
Technical Mitigations AI-generated
* Use least-privilege policies, controlled administrator sessions, and just-in-time access to limit lateral movement and unauthorized privilege gains on vulnerable systems.
* Implement Privileged Access Management controls to restrict how far a compromised account can proceed during patch testing and deployment.
* Limit the use of physical access to laptops and other devices exposed to theft, loss, or untrusted physical access by using least-privilege policies and controlled administrator sessions.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-54118CVE-2026-54118
CVE-2026-57092CVE-2026-57092
CVE-2026-54117CVE-2026-54117
CVE-2026-55040CVE-2026-55040
CVE-2026-55008CVE-2026-55008
CVE-2026-56155CVE-2026-56155
CVE-2026-50522CVE-2026-50522
CVE-2026-48561CVE-2026-48561
CVE-2026-56164CVE-2026-56164
CVE-2026-50661CVE-2026-50661
Target & Sectors
Global Scope
Incident Timeline
2026/06/14
Microsoft Corp released software updates to plug at least 570 security holes in its Windows operating systems.
Click on any entity below to view its context and source!
infrastructure
Windows
Microsoft Corp.
today released software updates to plug at least 570 security holes in its
Windows
operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month.
organisation
Microsoft Corp.
Microsoft Corp.
today released software updates to plug at least 570 security holes in its
Windows
operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month.
general_metric
570 security holes
Microsoft Corp.
today released software updates to plug at least 570 security holes in its
Windows
operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month.
June 2026
Google released more than 900 security patches in June 2026.
Click on any entity below to view its context and source!
organisation
Google
Cisco
,
Mozilla
and
Oracle
also are shipping updates more frequently, while Google’s patch batches in June 2026 totaled more than 900 security fixes, Goettl noted.
organisation
Mozilla
Cisco
,
Mozilla
and
Oracle
also are shipping updates more frequently, while Google’s patch batches in June 2026 totaled more than 900 security fixes, Goettl noted.
organisation
Oracle
Cisco
,
Mozilla
and
Oracle
also are shipping updates more frequently, while Google’s patch batches in June 2026 totaled more than 900 security fixes, Goettl noted.
general_metric
900 security fixes
Cisco
,
Mozilla
and
Oracle
also are shipping updates more frequently, while Google’s patch batches in June 2026 totaled more than 900 security fixes, Goettl noted.
July 1
Threat actors exploited a recently patched zero-day flaw in Microsoft's SharePoint software.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
For example, Microsoft originally gave this month’s SharePoint zero-day an exploitability rating of “less likely,” although the flaw was
added
to CISA’s Known Exploited Vulnerabilities list on July 1.
attribution
CISA’s Known Exploited
For example, Microsoft originally gave this month’s SharePoint zero-day an exploitability rating of “less likely,” although the flaw was
added
to CISA’s Known Exploited Vulnerabilities list on July 1.
July 9
Threat actors exploited zero-day vulnerabilities in Microsoft Windows to gain unauthorized access.
Click on any entity below to view its context and source!
infrastructure
Windows
In a blog post on July 9, Microsoft Executive Vice President
Pavan Davuluri
wrote that Windows users will notice “a higher volume of security updates included in each security release” as a result of AI aiding in the discovery of vulnerabilities.
organisation
Microsoft Executive
In a blog post on July 9, Microsoft Executive Vice President
Pavan Davuluri
wrote that Windows users will notice “a higher volume of security updates included in each security release” as a result of AI aiding in the discovery of vulnerabilities.
2026/07/14
Threat actors used Microsoft's patches to target vulnerable versions of Windows.
Click on any entity below to view its context and source!
tactic
T1584.004 - Server
If you run self-hosted SharePoint, this is the one to grab first, and there is a second clock on it: today is also the day SharePoint Server 2016 and 2019 reach the end of extended support.
organisation
SharePoint
If you run self-hosted SharePoint, this is the one to grab first, and there is a second clock on it: today is also the day SharePoint Server 2016 and 2019 reach the end of extended support.
industry
Defense
“What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.”
Chris Goettl
at
Ivanti
observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing their patch cadence, including Adobe which announced today it is moving to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month (Adobe also cited AI for accelerating their patch cycles).
organisation
Ivanti
“What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.”
Chris Goettl
at
Ivanti
observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing their patch cadence, including Adobe which announced today it is moving to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month (Adobe also cited AI for accelerating their patch cycles).
organisation
Patch Tuesday
“What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.”
Chris Goettl
at
Ivanti
observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing their patch cadence, including Adobe which announced today it is moving to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month (Adobe also cited AI for accelerating their patch cycles).
organisation
Adobe
“What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.”
Chris Goettl
at
Ivanti
observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing their patch cadence, including Adobe which announced today it is moving to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month (Adobe also cited AI for accelerating their patch cycles).
infrastructure
Windows
Microsoft Corp.
today released software updates to plug at least 570 security holes in its
Windows
operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month.
organisation
Microsoft Corp.
Microsoft Corp.
today released software updates to plug at least 570 security holes in its
Windows
operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month.
general_metric
570 security holes
Microsoft Corp.
today released software updates to plug at least 570 security holes in its
Windows
operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month.
2026/07/15
Microsoft patched 622 vulnerabilities in its products and services.
Click on any entity below to view its context and source!
infrastructure
Windows
The total is more than three times the roughly 200 vulnerabilities
addressed in June
and includes vulnerabilities affecting Windows, Office, SharePoint Server, SQL Server, Azure products and development tools.
The system uses several AI models, including third-party vulnerability research models, to inspect critical Windows binaries and test suspected bugs.
Unlike Windows Server or SQL Server, neither has a paid ESU program to fall back on.
The order matters: audit first, using the RC4 audit events Microsoft added in January, then rotate the passwords on flagged service accounts, so Windows generates AES keys for them, then patch.
Windows alone accounts for 416 of the 622, and ZDI counts 95 remote code execution bugs across the release.
Here is where the rest sits, and what is worth pulling out of each pile:
Product family
CVEs
Worth pulling out
Windows
416
Both the AD FS zero-day (
CVE-2026-56155
) and the disclosed BitLocker bypass (
CVE-2026-50661
) live here.
Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user.
Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include
CVE-2026-56155
— an
Active Directory Federation Services
bug — and
CVE-2026-56164
, a
Microsoft Sharepoint
vulnerability.
CVE-2026-50661
is a security feature bypass in
Windows BitLocker
that could allow attackers to gain access to encrypted data if they have physical access to the device.
Backing up your Windows system and/or data is always a good idea before applying operating system updates.
organisation
Windows, Office
The total is more than three times the roughly 200 vulnerabilities
addressed in June
and includes vulnerabilities affecting Windows, Office, SharePoint Server, SQL Server, Azure products and development tools.
organisation
ESU
Unlike Windows Server or SQL Server, neither has a paid ESU program to fall back on.
organisation
AES
The order matters: audit first, using the RC4 audit events Microsoft added in January, then rotate the passwords on flagged service accounts, so Windows generates AES keys for them, then patch.
organisation
Active Directory Federation Services
Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include
CVE-2026-56155
— an
Active Directory Federation Services
bug — and
CVE-2026-56164
, a
Microsoft Sharepoint
vulnerability.
Microsoft confirmed attacks involving Active Directory Federation Services and SharePoint Server, while information about a separate BitLocker bypass was already public.
Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Services.
organisation
CVE-2026
CVE-2026-50661
is a security feature bypass in
Windows BitLocker
that could allow attackers to gain access to encrypted data if they have physical access to the device.
On-premises SharePoint servers require the same urgency due to
CVE-2026-56164
.
organisation
BitLocker
Microsoft confirmed attacks involving Active Directory Federation Services and SharePoint Server, while information about a separate BitLocker bypass was already public.
A third bug, and a SharePoint chain landing in August
The third zero-day was publicly disclosed but is not under attack: CVE-2026-50661, another
BitLocker bypass
.
infrastructure
17 SharePoint Server
SharePoint Server
17
The exploited zero-day (
CVE-2026-56164
) and Rapid7's chain bypass (
CVE-2026-55040
), plus a Critical RCE pair including
CVE-2026-50522
at 9.8.
organisation
Outlook Web Access
Exchange Server
5
A stored XSS in Outlook Web Access,
CVE-2026-55008
, at 9.6.
organisation
an Active Directory Federation Services
CVE-2026-56155
, an Active Directory Federation Services flaw Microsoft also flags as exploited, lets an already-authenticated attacker elevate privileges locally through weak access controls.
organisation
SharePoint
On-premises SharePoint servers require the same urgency due to
CVE-2026-56164
.
organisation
CVSS
Microsoft gave it a CVSS score of 5.3, showing how a numerical score alone can be a poor guide when attacks are already underway.
It also guts CVSS-based triage.
organisation
Microsoft
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack.
Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.
organisation
Security Update Guide
The release covers 622 of Microsoft's own CVEs by its
Security Update Guide
count, more than triple
June's previous high of around 200
.
organisation
Keeper Security
Shane Barney
, Chief Information Security Officer at Keeper Security, said patch programs designed around a manageable monthly queue cannot process hundreds of fixes quickly without risk-based prioritization.
organisation
Privileged Access Management
During patch testing and deployment, Barney recommended using Privileged Access Management controls to restrict how far a compromised account can proceed.
organisation
RCE
Rapid7 chained it to a separate remote code execution bug to reach unauthenticated RCE against a vulnerable server, and the RCE half is not patched yet; Microsoft is slated to fix it in August.
organisation
Microsoft Copilot
Jack Bicer
, director of vulnerability research at
Action1
, called attention to
CVE-2026-48561
, a remote code execution flaw in Microsoft Copilot (with a 9.6 CVSS threat score) that allows an unauthorized attacker to execute code over the network.
organisation
JWT
Rapid7 Labs disclosed
CVE-2026-55040
, a JWT authentication bypass they built for their Pwn2Own Berlin entry.
infrastructure
5.3
The score depends on who you ask: Rapid7 puts it at 5.3 and says Microsoft assigned it medium severity, while ZDI
reads
the release as Critical at 9.1.
infrastructure
9.1
The score depends on who you ask: Rapid7 puts it at 5.3 and says Microsoft assigned it medium severity, while ZDI
reads
the release as Critical at 9.1.
organisation
Critical
The score depends on who you ask: Rapid7 puts it at 5.3 and says Microsoft assigned it medium severity, while ZDI
reads
the release as Critical at 9.1.
infrastructure
9.9
Top score of the release is a VMSwitch RCE,
CVE-2026-57092
at 9.9.
organisation
VMSwitch RCE
Top score of the release is a VMSwitch RCE,
CVE-2026-57092
at 9.9.
infrastructure
Vs Code
Developer Tools
27
Security feature bypasses across Visual Studio, VS Code, and GitHub Copilot, mostly injection and path traversal.
organisation
Visual Studio
Developer Tools
27
Security feature bypasses across Visual Studio, VS Code, and GitHub Copilot, mostly injection and path traversal.
organisation
GitHub Copilot
Developer Tools
27
Security feature bypasses across Visual Studio, VS Code, and GitHub Copilot, mostly injection and path traversal.
organisation
Mandiant
Microsoft credited it to Mandiant's incident responders and Google's FLARE team, which points to discovery inside active attacks, though Microsoft has not said how it was exploited or by whom.
organisation
Google
Microsoft credited it to Mandiant's incident responders and Google's FLARE team, which points to discovery inside active attacks, though Microsoft has not said how it was exploited or by whom.
organisation
DART
Microsoft's own DART incident-response unit gets the credit.
organisation
KEV
Do not wait for a KEV listing to make it official.
organisation
DHCP
Also five DHCP RCEs, and 21 NTFS and ReFS driver bugs that ZDI reads as one shared root cause.
organisation
NTFS
Also five DHCP RCEs, and 21 NTFS and ReFS driver bugs that ZDI reads as one shared root cause.
organisation
ReFS
Also five DHCP RCEs, and 21 NTFS and ReFS driver bugs that ZDI reads as one shared root cause.
organisation
Microsoft Edge
Microsoft Edge
46
ZDI counts 21 as Microsoft's own rather than Chromium re-listings.
Microsoft says an attacker could exploit this bug by hosting a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the site.
infrastructure
Android
Microsoft says an attacker could exploit this bug by hosting a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the site.
organisation
Copilot
Microsoft says an attacker could exploit this bug by hosting a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the site.
organisation
EPSS
Sort by what is being exploited, using KEV, EPSS, and Microsoft's exploited flag, not by score, and patch faster than you used to.
organisation
Microsoft Patches
Microsoft Patches a Record 570 Security Flaws.
data_breach
570 Record
Microsoft Patches a Record 570 Security Flaws.
organisation
Mythos Preview
“Anthropic’s Red Team’s own findings for known vulnerabilities (n-days) revealed how fragile this system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated ‘Exploitation Less Likely’ or ‘Exploitation Unlikely,'” Narang said.
organisation
Automox
Further reading:
Action1’s Patch Tuesday blog
Automox’s rundown
July 2026
Threat actors exploited two zero-day vulnerabilities in Microsoft's software.
Click on any entity below to view its context and source!
organisation
Microsoft
Microsoft’s July 2026 Patch Tuesday fixes 622 flaws and 2 exploited zero-days.
general_metric
622 flaws
Microsoft’s July 2026 Patch Tuesday fixes 622 flaws and 2 exploited zero-days.
general_metric
2 flaws
Microsoft’s July 2026 Patch Tuesday fixes 622 flaws and 2 exploited zero-days.
organisation
Security Update Guide
The full list of Microsoft’s July 2026 Security Update Guide is available
here
.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
The total is more than three times the roughly 200 vulnerabilities
addressed in June
and includes vulnerabilities affecting Windows, Office, SharePoint Server, SQL Server, Azure products and development tools.
The system uses several AI models, including third-party vulnerability research models, to inspect critical Windows binaries and test suspected bugs.
Unlike Windows Server or SQL Server, neither has a paid ESU program to fall back on.
The order matters: audit first, using the RC4 audit events Microsoft added in January, then rotate the passwords on flagged service accounts, so Windows generates AES keys for them, then patch.
Windows alone accounts for 416 of the 622, and ZDI counts 95 remote code execution bugs across the release.
Here is where the rest sits, and what is worth pulling out of each pile:
Product family
CVEs
Worth pulling out
Windows
416
Both the AD FS zero-day (
CVE-2026-56155
) and the disclosed BitLocker bypass (
CVE-2026-50661
) live here.
Microsoft Corp.
today released software updates to plug at least 570 security holes in its
Windows
operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday re…
Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user.
Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include
CVE-2026-56155
— an
Active Directory Federation Services…
CVE-2026-50661
is a security feature bypass in
Windows BitLocker
that could allow attackers to gain access to encrypted data if they have physical access to the device.
In a blog post on July 9, Microsoft Executive Vice President
Pavan Davuluri
wrote that Windows users will notice “a higher volume of security updates included in each security release” as a result of AI aiding in the discovery of vulnerabilities.
Backing up your Windows system and/or data is always a good idea before applying operating system updates.
Metrics
infrastructure
5.3
Software Version
The score depends on who you ask: Rapid7 puts it at 5.3 and says Microsoft assigned it medium severity, while ZDI
reads
the release as Critical at 9.1.
Metrics
infrastructure
9.1
Software Version
The score depends on who you ask: Rapid7 puts it at 5.3 and says Microsoft assigned it medium severity, while ZDI
reads
the release as Critical at 9.1.
Metrics
infrastructure
9.9
Software Version
Top score of the release is a VMSwitch RCE,
CVE-2026-57092
at 9.9.
Metrics
infrastructure
Vs Code
Affected Product
Developer Tools
27
Security feature bypasses across Visual Studio, VS Code, and GitHub Copilot, mostly injection and path traversal.
Metrics
infrastructure
17
Sharepoint Server
SharePoint Server
17
The exploited zero-day (
CVE-2026-56164
) and Rapid7's chain bypass (
CVE-2026-55040
), plus a Critical RCE pair including
CVE-2026-50522
at 9.8.
Metrics
infrastructure
Ivanti
Affected Product
…d humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.”
Chris Goettl
at
Ivanti
observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing…
Metrics
infrastructure
Android
Affected Product
Microsoft says an attacker could exploit this bug by hosting a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the site.
Metrics
data_breach
570
Record
Microsoft Patches a Record 570 Security Flaws.
Intelligence Sources
Krebs On Security
2026-07-14
Microsoft Patches a Record 570 Security Flaws
Krebs On Security
HackRead
2026-07-15
The Hacker News
2026-07-14
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-16T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
41x
organisation
Identified Entity
Windows, Office
entity
10x
vulnerability
Exploited CVE
CVE-2026-56155
cve
10x
timeline
Temporal Reference
July 2026
date
5x
attribution
Attributing Entity
CISA
authority
4x
infrastructure
Affected Product
Windows
software
3x
tactic
Cyber Operation Type
Lateral Movement
tactic
3x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
3x
general metric
Entities
8
entities
3x
infrastructure
Software Version
5.3
version
2x
general metric
Vulnerabilities
200
vulnerabilities
2x
general metric
Flaws
622
flaws
2x
general metric
Rce Pair
8
rce pair
2x
general metric
Office
82
office
Contextual Telemetry
Context Block
16 METRICS
vulnerability
CVSS Score
5
score
general metric
Remote Code Execution
95
remote code execution
general metric
Windows
416
windows
general metric
Security
27
security
infrastructure
Sharepoint Server
17
sharepoint server
general metric
Driver Bugs
21
driver bugs
general metric
Zdi
46
zdi
general metric
Outlets
164
outlets
general metric
System
16
system
general metric
Headline
10
headline
industry
Targeted Sector
Defense
sector
general metric
Security Holes
570
security holes
general metric
Other Elevation
250
other elevation
general metric
Cvss Threat
10
cvss threat
data breach
Record
570
record
general metric
Security Fixes
900
security fixes
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.