Microsoft Patches Record 570 Security Flaws in July 2026 Update

Microsoft released software updates to patch 570 security vulnerabilities across its Windows operating systems and other software in its July 2026 Patch Tuesday release. The total nearly triples the previous record set just last month and includes two zero-day vulnerabilities that are already being actively exploited.

The record-breaking patch count reflects Microsofts increasing reliance on AI-assisted vulnerability discovery. The company has acknowledged that its engineering teams are using large language models to identify security flaws more efficiently, resulting in a significant uptick in the number of vulnerabilities being discovered and patched each month.

Two of the vulnerabilities fixed in this months update are already being exploited in the wild, according to Microsoft. Both have been added to CISA Known Exploited Vulnerabilities catalog. An additional vulnerability was publicly disclosed before Microsoft could release a patch, giving attackers a head start on developing exploits.

The SharePoint platform received particular attention in this months updates. Rapid7 researchers discovered a critical authentication bypass vulnerability tracked as CVE-2026-55040 that, when chained with another flaw scheduled to be patched in August, could allow unauthenticated remote code execution against vulnerable SharePoint servers. SharePoint Server Subscription Edition, 2019, and 2016 are all affected.

The scale of the updates has prompted Microsoft to change how it communicates Patch Tuesday information. The company no longer lists individual CVEs in its Security Update Guide, instead providing a summary table of vulnerability counts by product family and a slim notable CVEs section. The change reflects the growing challenge of managing thousands of individual vulnerability disclosures each year.

References

This article was adapted from Krebs on Security. Read the original here.