< Back to all clusters
[TECHNOLOGY] · United States · 39 sources

started · updated

Microsoft releases record July 2026 Patch Tuesday fixing over 600 vulnerabilities

Microsoft’s July 2026 Patch Tuesday set a new record, delivering fixes for 622 security vulnerabilities across its product portfolio—including Windows, Office, Edge, Azure, Exchange, SharePoint, AD FS and many others. The unusually large number is attributed to the company’s expanded use of artificial‑intelligence‑driven scanning tools, which have accelerated discovery of both long‑standing and newly introduced flaws.

Two of the patched flaws were already being exploited in the wild: CVE‑2026‑56155 in Active Directory Federation Services and CVE‑2026‑56164 in SharePoint Server, both allowing privilege‑escalation without prior authentication. A third zero‑day, CVE‑2026‑50661, bypasses Windows BitLocker but has not yet seen active attacks. Microsoft classifies dozens of the fixes as critical, many enabling remote‑code execution or privilege escalation.

The update package (KB5101650 for Windows 11 25H2/24H2 and KB5099414 for 23H2) also includes non‑security enhancements such as point‑in‑time system restore, accessibility improvements and Bluetooth updates. An incompatibility discovered on select Dell PCs with Intel CPUs caused Microsoft to temporarily suspend the July update for those models until a driver conflict is resolved.

Overall, the massive patch cycle reflects both the growing complexity of Microsoft’s software ecosystem and the accelerating role of AI in both offensive and defensive cybersecurity operations.

Sources

about 2 months ago
about 2 months ago
about 2 months ago
about 2 months ago
about 2 months ago
about 2 months ago
about 2 months ago
about 2 months ago
about 2 months ago