Microsoft’s July Patch Tuesday update addresses a record 570 security vulnerabilities in Windows, including three zero-day flaws that have been actively exploited or publicly disclosed.
Among the 570 bugs, the update includes 254 elevation-of-privilege vulnerabilities, 145 remote-code-execution vulnerabilities, and 59 rated as “critical.” The previous largest update, in June, addressed just over 200 flaws.
Two of the zero-days fixed this month have been actively exploited. The first, identified as CVE-2026-56155, is an elevation of privilege flaw in Active Directory Federation Services that allows attackers to gain local privileges. This vulnerability was discovered by Microsoft Detection and Response Team members Jeremy Kingston and Scott Clark.
The second zero-day, CVE-2026-56164, is also an elevation of privilege flaw affecting Microsoft SharePoint Server. This flaw permits unauthorized attackers to elevate privileges over a network due to missing authentication for a critical function. It was identified by researchers Jayson Frost from Mandiant Incident Response, Genwei Jiang from Google Cloud, FLARE OTF, and an anonymous individual.
The third zero-day, CVE-2026-50661, is a security bypass flaw in Windows BitLocker, which could allow attackers with physical access to obtain encrypted data. No known exploits for this vulnerability have been reported, and Microsoft credits an anonymous researcher for its discovery.
Patch Tuesday updates generally occur on the second Tuesday of each month around 10 a.m. PT. Users are advised to ensure they install these updates promptly. To check for updates, navigate to Start > Settings > Windows Update > Check for Windows updates.




