INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
July 2026 Patch Tuesday fixes 622 Microsoft CVEs
| 2026-07-15 12:21 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The latest patch Tuesday has fixed 622 Microsoft CVEs, including three zero-days. These vulnerabilities have been exploited by attackers to bypass security features and access data even with encryption in place like BitLocker. The most recent exploits are for the Windows BitLocker security feature bypass vulnerability (CVE-2026-50661) and the Active Directory Federation Services elevation of privilege (ADFS) vulnerability (CVE-2026-56155). These vulnerabilities have been added to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities Catalog, urging organizations using SharePoint Server to implement hardening measures. The update includes 59 critical vulnerabilities as well as three publicly disclosed zero-days, making it a significant security patch for Microsoft products.
Technical Mitigations AI-generated
* Use a reputable antivirus software and keep it up to date to protect against known vulnerabilities.
* Regularly update your operating system, browser, and other applications to ensure you have the latest security patches.
* Implement a firewall on your computer or network to block unauthorized access from external sources.
* Be cautious when clicking on links or downloading attachments from unknown sources, as they may contain malware that can compromise your device's security.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-57092CVE-2026-57092
CVE-2026-56190CVE-2026-56190
CVE-2026-55008CVE-2026-55008
CVE-2026-56155CVE-2026-56155
CVE-2026-58644CVE-2026-58644
CVE-2026-50522CVE-2026-50522
CVE-2026-50518CVE-2026-50518
CVE-2026-56164CVE-2026-56164
CVE-2026-50661CVE-2026-50661
Target & Sectors
Global Scope
Incident Timeline
June 2026
Threat actors exploited an ADFS elevation of privilege vulnerability in Microsoft Office SharePoint.
Click on any entity below to view its context and source!
infrastructure
Windows
How to apply patches and check if you’re protected
These updates fix security problems and keep your Windows PC protected.
Windows will search for the latest security updates.
5. Double-check you’re up to date
After restarting, go back to
Windows Update
and check again.
First is a Windows BitLocker security feature bypass vulnerability, tracked as
CVE-2026-50661
.
Microsoft
describes
it as:
“Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.”
organisation
Windows Update
5. Double-check you’re up to date
After restarting, go back to
Windows Update
and check again.
organisation
Next
Next is the actively exploited
CVE-2026-56155
, an Active Directory Federation Services (ADFS) elevation of privilege (EoP) vulnerability.
organisation
an Active Directory Federation Services
Next is the actively exploited
CVE-2026-56155
, an Active Directory Federation Services (ADFS) elevation of privilege (EoP) vulnerability.
organisation
Microsoft SharePoint
Last but not least is
CVE-2026-56164
, a Microsoft SharePoint Server elevation of privilege vulnerability.
infrastructure
Microsoft Office
A missing authentication check in Microsoft Office SharePoint could allow an attacker to elevate privileges over a network.
organisation
Microsoft Office SharePoint
A missing authentication check in Microsoft Office SharePoint could allow an attacker to elevate privileges over a network.
organisation
BitLocker
In other words, even if you’ve encrypted your machine with BitLocker, an attacker could exploit this vulnerability to access your data if they have physical access to your computer.
organisation
ADFS
ADFS is a Microsoft software component that provides single sign-on (SSO) and federated access.
organisation
CNET
According to CNET.
2026/07/15
Threat actors used a crafted email to exploit an elevation of privilege flaw in Active Directory Federation Services.
Click on any entity below to view its context and source!
infrastructure
Windows
Patches this month cover Windows and Windows components, Office, Microsoft Edge, Azure, .NET, Visual Studio, GitHub Copilot, Defender, Exchange Server, Hyper-V, and, at the more unexpected end of the list, Ages of Empire II and Minecraft Server.
The highest-severity bug this month is a critical Microsoft Windows VMSwitch Elevation of Privilege Vulnerability tracked as CVE-2026-57092, which received a CVSS score of 9.9.
CVE-2026-50518 covers a heap-based buffer overflow in Windows DHCP Server, scored CVSS 9.8, unauthenticated and network-reachable.
organisation
Office
Patches this month cover Windows and Windows components, Office, Microsoft Edge, Azure, .NET, Visual Studio, GitHub Copilot, Defender, Exchange Server, Hyper-V, and, at the more unexpected end of the list, Ages of Empire II and Minecraft Server.
organisation
Active Directory Federation Services
The following two bugs are being actively exploited:
CVE-2026-56155 is an elevation of privilege flaw in Active Directory Federation Services.
infrastructure
5.3
CVE-2026-56164 is a SharePoint Server elevation of privilege vulnerability rated only CVSS 5.3, which is Moderate, and that score has probably caused some organizations to deprioritize it.
organisation
CVE-2026-55008
CVE-2026-55008 in Exchange Server is listed as a spoofing vulnerability, but ZDI recommends treating it as what it actually is: a stored cross-site scripting flaw in Outlook Web Access with a CVSS of 9.6.
organisation
Microsoft
Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days.
organisation
CVE-2026
Below are other interesting issues addressed by Microsoft this month:
CVE-2026-50522 and CVE-2026-58644 are a matched pair of SharePoint remote code execution bugs, both scored CVSS 9.8, both reachable without authentication or user interaction, both stemming from the deserialization of untrusted data.
organisation
Chromium
That’s before counting the roughly 480 additional bugs in Chromium and Microsoft Edge that ZDI didn’t cover separately.
organisation
Microsoft Edge
That’s before counting the roughly 480 additional bugs in Chromium and Microsoft Edge that ZDI didn’t cover separately.
organisation
Critical
Of the Microsoft-specific fixes, 63 are rated Critical, six Moderate, one Low, and the rest Important.
organisation
CVE
“The CVE count year-to-date exceeds all other years’ totals.
organisation
CVSS
Active exploitation makes immediate patching essential, regardless of CVSS score.
organisation
VMSwitch
If your Hyper-V deployments use VMSwitch, which they almost certainly do, this is an immediate priority.
organisation
Outlook Web Access
A crafted email opened in Outlook Web Access can execute JavaScript in the victim’s browser session without attachments or user interaction beyond viewing it.
organisation
DHCP
DHCP servers shouldn’t be internet-facing, but if yours somehow are, these jump to the very top of the list.
July 2026
Microsoft fixed 621 vulnerabilities, including two zero-day exploits and several critical flaws in July's Patch Tuesday.
Click on any entity below to view its context and source!
organisation
Microsoft
621 CVEs in one month
Patch Tuesday:
Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS.
Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company’s history.
organisation
SharePoint
621 CVEs in one month
Patch Tuesday:
Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS.
Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company’s history.
organisation
RDP
621 CVEs in one month
Patch Tuesday:
Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS.
Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company’s history.
organisation
Microsoft’s
621 CVEs in one month
Patch Tuesday:
Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS.
Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company’s history.
general_metric
2 CVEs
621 CVEs in one month
Patch Tuesday:
Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS.
Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company’s history.
organisation
SecurityAffairs
The full list of vulnerabilities addressed by Microsoft in July 2026 is available
here
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Patch Tuesday)
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
How to apply patches and check if you’re protected
These updates fix security problems and keep your Windows PC protected.
Windows will search for the latest security updates.
5. Double-check you’re up to date
After restarting, go back to
Windows Update
and check again.
First is a Windows BitLocker security feature bypass vulnerability, tracked as
CVE-2026-50661
.
Microsoft
describes
it as:
“Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.”
Patches this month cover Windows and Windows components, Office, Microsoft Edge, Azure, .NET, Visual Studio, GitHub Copilot, Defender, Exchange Server, Hyper-V, and, at the more unexpected end of the list, Ages of Empire II and Minecraft Server.
The highest-severity bug this month is a critical Microsoft Windows VMSwitch Elevation of Privilege Vulnerability tracked as CVE-2026-57092, which received a CVSS score of 9.9.
CVE-2026-50518 covers a heap-based buffer overflow in Windows DHCP Server, scored CVSS 9.8, unauthenticated and network-reachable.
Metrics
infrastructure
Microsoft Office
Affected Product
A missing authentication check in Microsoft Office SharePoint could allow an attacker to elevate privileges over a network.
Metrics
infrastructure
5.3
Software Version
CVE-2026-56164 is a SharePoint Server elevation of privilege vulnerability rated only CVSS 5.3, which is Moderate, and that score has probably caused some organizations to deprioritize it.
Intelligence Sources
Malware Bytes
2026-07-15
Security Affairs
2026-07-14
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-16T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
26x
organisation
Identified Entity
Windows Update
entity
9x
vulnerability
Exploited CVE
CVE-2026-50661
cve
5x
attribution
Attributing Entity
the Cybersecurity and Infrastructure Security Agency
authority
4x
tactic
Cyber Operation Type
Ransomware
tactic
3x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
3x
vulnerability
CVSS Score
5
score
2x
infrastructure
Affected Product
Windows
software
2x
timeline
Temporal Reference
July 2026
date
Contextual Telemetry
Context Block
6 METRICS
general metric
Critical Vulnerabilities
59
critical vulnerabilities
infrastructure
Software Version
5.3
version
general metric
Cvss
10
cvss
general metric
Cves
2
cves
general metric
Additional Bugs
480
additional bugs
general metric
Fixes
63
fixes
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.