Microsoft released software updates on July 14 to plug at least 570 security holes across Windows and other software, nearly triple the record it set in June 2026. The company attributed the surge in vulnerability discoveries to AI-assisted code review processes now integrated into its development pipeline.
Among the patched vulnerabilities, two were under active exploitation at the time of release: an elevation of privilege in Active Directory Federation Services (CVE-2026-56155) and an elevation of privilege in SharePoint Server (CVE-2026-56164). A third publicly disclosed BitLocker security feature bypass (CVE-2026-50661) was not yet exploited but carried significant risks for enterprise deployments.
The SharePoint flaw drew particular attention from CISA, which added it to its Known Exploited Vulnerabilities catalog and urged federal agencies to patch by July 19. The vulnerability allows remote attackers to execute arbitrary code on SharePoint servers without authentication.
Security researchers noted that the scale of this Patch Tuesday represents a new normal for vulnerability management. With AI tools discovering bugs faster than ever, organizations must prioritize patch deployment based on active exploitation intelligence rather than CVSS scores alone. As reported by Krebs on Security, the record-breaking patch count signals both the power and the challenge of AI-assisted security testing.
