Microsoft patches record 570 security flaws in July 2026, two actively exploited

Microsoft released its July 2026 Patch Tuesday security updates on July 14, fixing a record-breaking 570 vulnerabilities across Windows and its product portfolio. The update includes three zero-day flaws — two of which are being actively exploited in attacks right now — making this one of the most urgent Patch Tuesday releases in recent memory.
The sheer scale of the July update is itself notable. Microsoft last week pre-announced an increase in patch volume, attributing it to a new AI-powered vulnerability discovery system that is finding flaws in Windows code before attackers can. The AI tooling is already paying dividends: the June Patch Tuesday covered 200 flaws, and July nearly triples that count.
The two zero-days under active attack
The most urgent fixes are two elevation-of-privilege flaws confirmed to be exploited in live attacks:
- Active Directory Federation Services (AD FS): An insufficient access-control vulnerability that lets an authorized local attacker escalate to administrative privileges. Microsoft's own Detection and Response Team (DART) — its incident response unit — discovered the flaw, which typically means it was found during active breach investigations.
- Microsoft SharePoint Server: A missing-authentication flaw that lets a remote, unauthenticated attacker elevate privileges over the network. Researchers from Mandiant Incident Response and Google Cloud's FLARE team co-credited the discovery, again suggesting the flaw was identified during real-world incident response work.
A third zero-day — a Windows BitLocker bypass that requires physical access — was publicly disclosed but is not yet known to be exploited.
Scale of the update
Of the 570 vulnerabilities patched, 59 are classified Critical. Within that Critical tier, 48 allow remote code execution, nine are elevation-of-privilege bugs, and two are a security bypass and spoofing issue respectively. The 570 count does not include the 468 Chromium-engine flaws Google fixed this month that also appear in Microsoft Edge, nor fixes shipped earlier in July for Azure OpenAI, M365 Copilot, Exchange Online, or Entra Provisioning Service.
What admins need to do
The AD FS and SharePoint zero-days are both confirmed exploited, so prioritizing those patches is non-negotiable for any organization running either service. For SharePoint specifically, Microsoft offers a temporary mitigation: enabling the Antimalware Scan Interface (AMSI) on the server and setting Request Body Scan mode to Full can reduce exposure until the patch is deployed.
Users on Windows 10 receive the fixes via KB5099539, an extended security update. Windows 11 machines get them via KB5101650 and KB5099414. As always, enterprise administrators should test in staging before broad rollout, but given two actively exploited zero-days, the window for deliberation is short.
As first reported by BleepingComputer, this is the largest Patch Tuesday on record. The trend is likely to continue as Microsoft's AI-powered scanning surfaces more vulnerabilities on its own — a net positive for defenders, even if the update cadence becomes more demanding.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source