Bottom line: CISOs must immediately prioritize the three critical zero-days (CVE-2026-56155, CVE-2026-56164, CVE-2026-50661), but also inventory RC4-dependent systems and prepare for AES encryption migration to avoid authentication failures after the update.
Microsoft released the largest security update in its history in July 2026, addressing 570 vulnerabilities. Among them are three zero-days and 59 critical gaps, and the update enforces the elimination of the deprecated RC4 encryption in Kerberos.
The Microsoft security update from July 2026 addresses a total of 570 vulnerabilities in Windows, Office, Exchange Server, SharePoint Server, SQL Server, Azure and Visual Studio. The error distribution includes 59 critical gaps, 145 errors that enable remote code execution, and three actively exploited zero-days.
The three zero-day vulnerabilities have the highest immediate criticality: CVE-2026-56155 (AD FS) and CVE-2026-56164 (SharePoint Server) enable privilege escalation, with SharePoint also allowing remote access over the network. CVE-2026-50661 bypasses BitLocker encryption but requires physical device access. Security firm Zecurit classifies all three as immediate patching priorities.
Effective immediately, Windows domain controllers refuse to accept Kerberos tickets encrypted with RC4 unless an explicit exception configuration exists. The goal is to force industry-wide migration to AES encryption to prevent attack scenarios where attackers brute-force hashes offline. Systems with RC4-based service accounts, legacy applications, or incompatible non-Windows systems will experience authentication failures after installation.
Microsoft has temporarily halted the rollout of the update for certain Dell systems with Intel processors on Windows 11 to investigate compatibility issues. Affected devices display system crashes, performance degradation, overheating, and rapid battery drain after the update. A fix is being developed jointly with Dell.
Source: www.it-daily.net · Published 15 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.