INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

July 2026 Patch Tuesday fixes 622 Microsoft CVEs

| 2026-07-15 12:21 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The latest patch Tuesday has fixed 622 Microsoft CVEs, including three zero-days. These vulnerabilities have been exploited by attackers to bypass security features and access data even with encryption in place like BitLocker. The most recent exploits are for the Windows BitLocker security feature bypass vulnerability (CVE-2026-50661) and the Active Directory Federation Services elevation of privilege (ADFS) vulnerability (CVE-2026-56155). These vulnerabilities have been added to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities Catalog, urging organizations using SharePoint Server to implement hardening measures. The update includes 59 critical vulnerabilities as well as three publicly disclosed zero-days, making it a significant security patch for Microsoft products.
Technical Mitigations AI-generated
* Use a reputable antivirus software and keep it up to date to protect against known vulnerabilities. * Regularly update your operating system, browser, and other applications to ensure you have the latest security patches. * Implement a firewall on your computer or network to block unauthorized access from external sources. * Be cautious when clicking on links or downloading attachments from unknown sources, as they may contain malware that can compromise your device's security.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-57092CVE-2026-57092 CVE-2026-56190CVE-2026-56190 CVE-2026-55008CVE-2026-55008 CVE-2026-56155CVE-2026-56155 CVE-2026-58644CVE-2026-58644 CVE-2026-50522CVE-2026-50522 CVE-2026-50518CVE-2026-50518 CVE-2026-56164CVE-2026-56164 CVE-2026-50661CVE-2026-50661
Target & Sectors
Global Scope
Incident Timeline
‎June 2026
Threat actors exploited an ADFS elevation of privilege vulnerability in Microsoft Office SharePoint.
infrastructure Windows
organisation Windows Update
organisation Next
organisation an Active Directory Federation Services
organisation Microsoft SharePoint
infrastructure Microsoft Office
organisation Microsoft Office SharePoint
organisation BitLocker
organisation ADFS
organisation CNET
‎2026/07/15
Threat actors used a crafted email to exploit an elevation of privilege flaw in Active Directory Federation Services.
infrastructure Windows
organisation Office
organisation Active Directory Federation Services
infrastructure 5.3
organisation CVE-2026-55008
organisation Microsoft
organisation CVE-2026
organisation Chromium
organisation Microsoft Edge
organisation Critical
organisation CVE
organisation CVSS
organisation VMSwitch
organisation Outlook Web Access
organisation DHCP
‎July 2026
Microsoft fixed 621 vulnerabilities, including two zero-day exploits and several critical flaws in July's Patch Tuesday.
organisation Microsoft
organisation SharePoint
organisation RDP
organisation Microsoft’s
general_metric 2 CVEs
organisation SecurityAffairs
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
‎5.3
Software Version