Bottom line: The volume of monthly discovered security vulnerabilities has surged due to improved AI-powered vulnerability detection; security teams must adjust their response times and prioritize by risk rather than following the Exploitability Index alone.
Microsoft patched 569 security vulnerabilities in July — a monthly record — and recommends CSOs accelerate their patch cycles. In parallel, SAP released 20 security updates, including a critical memory corruption vulnerability in NetWeaver with a CVSS score of 9.9.
With 569 security vulnerabilities this month, Microsoft has set a new monthly record. 59 of them are classified as critical. For comparison: in June, the numbers were still at 198 patches. The previous record annual volume of 1,245 security vulnerabilities from all of 2020 could be surpassed by year-end according to Satnam Narang, Senior Staff Research Engineer at Tenable.
Among the patches are three so-called zero-days: CVE-2026-56155 (privilege escalation in Active Directory Federation Services) and CVE-2026-56164 (SharePoint Server) are already being actively exploited. CVE-2026-50661 is a security feature bypass in Windows BitLocker that has been publicly disclosed. Experts suspect a connection to zero-day disclosures by the researcher “Nightmare Eclipse” or “Chaotic Eclipse”, though this has not been officially confirmed.
The sharp increase in numbers is attributed to improved AI models that detect vulnerabilities faster. However, experts warn: the Exploitability Index system, which assesses the likelihood of practical exploitation, is still calibrated to human capabilities. Anthropic’s red-team tests showed that an AI model could create proof-of-concept exploits in 13 out of 14 cases for vulnerabilities rated as “Exploitation Less Likely”.
In parallel, SAP released 20 patches. The most critical vulnerability is a memory corruption in NetWeaver Application Server ABAP, SAP Kernel, and frontend services (SAP GUI for HTML) with a CVSS score of 9.9.
CSOs must reconsider their prioritization strategy: the previous reliance on Exploitability ratings becomes insufficient in the face of automated exploit development. July’s numbers already exceed all annual values from the past 20 years.
Source: www.csoonline.com · Published 15 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.