Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Microsoft's July 2026 Patch Tuesday addresses a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. The patches fix 59 'Critical' vulnerabilities, with 254 elevation of privilege, 17 security feature bypass, 1…
Intelligence analysis by Llama

Microsoft's July 2026 Patch Tuesday fixes a massive 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. The patches address 59 'Critical' vulnerabilities, with 254 elevation of privilege, 17 security feature bypass, 145 remote code execution, 102 information disclosure, 35 denial of service, and 16 spoofing vulnerabilities.
Imagine you have a big box of LEGOs, and someone has been secretly adding some bad LEGOs that can make the whole box fall apart. Microsoft's Patch Tuesday is like a team of superheroes who come in and remove the bad LEGOs, making the box safe again. This time, they removed a record-breaking 570 bad LEGOs, including two that were already being used by bad guys to make the box fall apart.
Analysis
A Record-Breaking Patch Tuesday
Microsoft's July 2026 Patch Tuesday has set a new record with a staggering 570 flaws addressed, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. This massive number of vulnerabilities highlights the ongoing cat-and-mouse game between attackers and defenders in the cybersecurity landscape.
The patches fix 59 'Critical' vulnerabilities, with 254 elevation of privilege, 17 security feature bypass, 145 remote code execution, 102 information disclosure, 35 denial of service, and 16 spoofing vulnerabilities. The sheer scale of these vulnerabilities underscores the importance of timely security updates in preventing attacks and protecting users.
The Two Actively Exploited Zero-Days
Microsoft has patched two actively exploited zero-day vulnerabilities, with the first being CVE-2026-56155 in Active Directory Federation Services. This vulnerability allows an authorized attacker to elevate privileges locally, and Microsoft credits the discovery to Jeremy Kingston and Scott Clark of the Microsoft Detection and Response Team (DART).
The second actively exploited zero-day is CVE-2026-56164 in Microsoft SharePoint Server, which allows a remote attacker to gain elevated privileges. Microsoft credits the discovery to Jayson Frost with Mandiant Incident Response, Genwei Jiang with Google Cloud, FLARE OTF, and an anonymous researcher.
The Publicly Disclosed Zero-Day
The publicly disclosed zero-day that was fixed is CVE-2026-50661 in Windows BitLocker, which could allow attackers to gain access to encrypted data. Microsoft attributed the discovery to an anonymous researcher.
Recent Updates from Other Companies
Other vendors who released updates or advisories in May 2026 include Adobe, BeyondTrust, Cisco, Fortinet, Gitea, Ivanti, Linux kernel maintainers, NVIDIA, Progress Software, and Ubiquiti. These updates address various vulnerabilities, including authentication bypass, remote code execution, and command injection attacks.
Key points
- Microsoft's July 2026 Patch Tuesday addresses a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed.
- The patches fix 59 'Critical' vulnerabilities, with 254 elevation of privilege, 17 security feature bypass, 145 remote code execution, 102 information disclosure, 35 denial of service, and 16 spoofing vulnerabilities.
- Two actively exploited zero-day vulnerabilities were patched, including CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in Microsoft SharePoint Server.
- The publicly disclosed zero-day that was fixed is CVE-2026-50661 in Windows BitLocker, which could allow attackers to gain access to encrypted data.
- Other vendors who released updates or advisories in May 2026 include Adobe, BeyondTrust, Cisco, Fortinet, Gitea, Ivanti, Linux kernel maintainers, NVIDIA, Progress Software, and Ubiquiti.
If this development plays out positively, it could lead to a significant reduction in the number of attacks and vulnerabilities in the future. Microsoft's use of an AI-powered vulnerability discovery system could help identify and fix security flaws before they are exploited, making the internet a safer place.
However, the sheer number of vulnerabilities fixed in this Patch Tuesday also highlights the ongoing threat landscape. Attackers may continue to find and exploit new vulnerabilities, and users must remain vigilant in keeping their systems and software up to date.


