Skip to content

July 2026: Microsoft Releases Record of 621 CVEs with Active Attacks

The bottom line: Microsoft releases 621 CVEs in July 2026—the largest single release in its history—with two vulnerabilities already being actively exploited.

Microsoft’s July 2026 patch day exceeds with 621 new CVEs already by mid-year the total number of all previous annual disclosures. At least two vulnerabilities are already being used for attacks, including gaps in Active Directory Federation Services and SharePoint.

The July 2026 update represents Microsoft’s previous record disclosure: 621 new CVEs were released, 63 of which classified as critical. The disclosure thus already surpasses by mid-year the total number of all vulnerability disclosures from any single prior year since tracking began. In parallel, two security vulnerabilities are already being exploited for attacks, leading to the characterization as “bug apocalypse” by the TrendAI Zero Day Initiative.

Two actively exploited vulnerabilities require immediate action: CVE-2026-56155 in Microsoft Active Directory Federation Services shows insufficient access control (CVSS 7.8) and can be exploited with local access and low privileges. CVE-2026-56164 in Microsoft SharePoint Server is being actively exploited, although it is only rated at 5.3—a missing authentication check enables network-based attacks without user interaction. Internet-accessible SharePoint installations are at immediate risk.

Further critical vulnerabilities concentrate on Hyper-V, SharePoint, RDP, and network components. CVE-2026-57092 in Windows VMSwitch (CVSS 9.9) exploits a use-after-free flaw and can enable attackers with low privileges to breach the boundary between virtual machines and the host system. CVE-2026-50522 and CVE-2026-58644 in SharePoint enable remote code execution (CVSS 9.8) through faulty deserialization without required authentication. CVE-2026-56190 (RDP), CVE-2026-50518 (DHCP Server), and CVE-2026-56188 (Network Driver) enable unauthenticated code execution over the network.

Additionally affected are Microsoft Exchange Server (CVE-2026-55008—stored XSS in Outlook Web Access), BitLocker (CVE-2026-50661—security feature bypass), and surprisingly also game titles such as Minecraft Bedrock Dedicated Server (unauthenticated remote code execution, CVSS 9.8). The disclosure is unusual in its breadth and also affects Chromium and Microsoft Edge with numerous additional vulnerabilities.


Source: www.it-daily.net · Published 19 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: