Microsoft Patches 570 CVEs in Record Patch Tuesday
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50661 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. NVD description · AI analysis pending | 4.6 | <1% |
| — | ||
| CVE-2026-56155 | Local Privilege Escalation in Microsoft Active Directory Federation Services CVE-2026-56155 is a high-severity (CVSS 3.1: 7.8) access-control flaw (CWE-1220) in Microsoft Active Directory Federation Services (AD FS), in which insufficient granularity of access control lets an authorized attacker elevate privileges locally. Exploitation requires only low local privileges and no user interaction, so any locally authenticated user or process on a system with the AD FS role can trigger it. Successful exploitation yields full local privilege escalation with high impact on confidentiality, integrity, and availability. It affects organizations running AD FS on Windows Server 2012, 2016, 2019, 2022, and 2025, and on Windows 10 versions 1607 and 1809, per CISA's affected-products list. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-07-14, confirming in-the-wild exploitation despite a modest EPSS of 0.3%; it was fixed as part of Microsoft's record-breaking July 2026 Patch Tuesday. Do: Apply Microsoft's July 2026 security updates to all affected Windows 10 and Windows Server systems, prioritizing servers hosting the AD FS role, especially federation servers tied to Microsoft 365 or hybrid identity. Per CISA KEV and BOD 26-04, federal agencies must apply vendor mitigations promptly or discontinue use, and all defenders should inventory AD FS servers, restrict local logon to them, and triage for signs of local privilege-escalation activity. No public PoC or workaround beyond patching is currently known. | 7.8 | <1% | KEV |
| largetens of thousands of internet-exposed AD FS servers; likely six figures of total AD FS deployments affected | |
| CVE-2026-56164 | Missing Authentication in Microsoft SharePoint Server Allows Privilege Escalation Microsoft SharePoint Server contains a missing authentication for critical function vulnerability (CWE-306) that lets an unauthenticated attacker elevate privileges over a network without valid credentials. The flaw is triggered when the affected SharePoint function is accessed remotely without any authentication check, allowing an attacker to gain higher privileges than intended. Successful exploitation could enable an attacker to take elevated actions within the SharePoint environment, potentially leading to further compromise of the server and its data. All organizations running on-premises Microsoft SharePoint Server are potentially affected, though specific versions have not yet been enumerated by Microsoft or CISA. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-14, indicating it is being actively exploited, and its EPSS score of 26.6% (98th percentile) reflects a high near-term exploitation risk. Do: Apply Microsoft's security updates for SharePoint Server as soon as they are available, and check Microsoft's advisory for the specific affected version ranges once published. In the meantime, restrict network access to SharePoint servers, especially for internet-facing instances, and verify whether your environment falls under CISA BOD 26-04 requirements given the KEV listing. Monitor for updated guidance from Microsoft and CISA, as exploitation is confirmed and patching urgency is high. | 9.8 | 27% | KEV |
| masspotentially millions of users and well over 100,000 exposed installations worldwide |
Full article646 words · extracted from infosecurity-magazine.com · click to collapse
Microsoft has released updates for an unprecedented 570 CVEs during this month’s Patch Tuesday on July 14.
The patch deluge came after warnings from the tech giant that its use of agentic AI to find new flaws would lead to an increase in security updates for customers.
Trey Ford, chief strategy and trust officer at Bugcrowd, said this was the new normal for the foreseeable future.
“The real story is economic. AI has collapsed the cost of finding vulnerabilities, and this increase in volume is a new floor, not the ceiling … at least for a while,” he added.
“Leadership teams need to stop treating patch volume as a monthly surprise, we must fund it as a fixed operating cost, because the intake will not be going back down for a while. The organizations that win won't be the ones that patch fastest this month. They'll be the ones who built a process that scales when the next couple months continue to increase.”
Among the vulnerabilities in July’s Patch Tuesday are three zero-day vulnerabilities; two of which have been exploited in the wild.
CVE-2026-56155 is an elevation of privilege (EoP) vulnerability in Active Directory Federation Services which allows an authorized attacker to elevate privileges locally.
“Eight other vulnerabilities are also published today in Active Directory Federation Services, all ranked as Important on Microsoft’s proprietary severity ranking scale,” explained Rapid7 principal software engineer, Adam Barnett.
“The advisory doesn’t explicitly describe the location of the attacker, but it’s likely that an attacker would need an existing toehold on the target system to chain together with the elevation of privilege opportunity on offer here.”
The second exploited zero-day is CVE-2026-56164, another EoP bug but this time in Microsoft SharePoint Server. No existing privileges are required to launch an attack, and exploitation has been branded “low complexity” by Microsoft.
The US Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to harden their SharePoint systems in response to exploitation of this and two other vulnerabilities published earlier this year.
The publicly disclosed zero day is CVE-2026-50661: a Windows BitLocker security feature bypass flaw which could allow attackers to access encrypted data. Exploitation would require an unauthorized attacker to have physical access to a target machine.
A New Era of Mass Updates
In total, July’s Patch Tuesday saw the release of updates for 254 EoP vulnerabilities, 145 remote code execution (RCE) bugs, and 102 information disclosure flaws. Fifty-nine were rated critical, of which the vast majority (48) were RCE flaws.
However, Microsoft isn’t the only vendor to increase its volume of updates for users. Google fixed over 460 Edge/Chromium flaws this month, and Adobe recently switched its patching cadence to twice a month.
Qualys security research manager, Mayuresh Dani, commented, “This trend was predicted and we’re seeing the evidence of it happening now. As more advanced and frontier AI models become available, we can expect an upward trend to continue and then slow down.”
“What we’re observing is that AI automated fuzzing, LLM-assisted variant hunting, and static analysis at scale are discovering bugs faster than enterprises can remediate.”
Qualys urged organizations to:
- Move from CVSS-only prioritization to Exploit Prediction Scoring System (EPSS) and CISA KEV
- Graduate to a tiered-patching SLA mechanism. For example, a KEV-listed CVE or EPSS >0.5 should be patched within 24-36 hours. Classification should be risk-based and will be different each organization
- Introduce attack surface reduction and mitigation mechanisms, such as ensuring systems like Active Directory Federation Service aren’t internet-connected, on-premises SharePoint doesn’t have public access, and remote management tools aren’t reachable from anywhere
- Improve patching practices so it is easier to validate updates, and monitor installs and system stability on a select group with automated rollback support. Approved patches should then be pushed to all required systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-570-cves-patch-tuesday/