Microsoft’s July 2026 Patch Tuesday delivers fixes for approximately 570 vulnerabilities across its product ecosystem, following June’s record-breaking release of 206 flaws that also included three publicly disclosed zero-days.
CVE IDVulnerabilityImpactSeverityZero-Day StatusCVE-2026-56164Microsoft SharePoint Server Elevation of PrivilegeElevation of PrivilegeModerateExploited in the wildCVE-2026-56155Active Directory Federation Services Elevation of PrivilegeElevation of PrivilegeImportantExploited in the wildCVE-2026-50661Windows BitLocker Security Feature BypassSecurity Feature BypassImportantPublicly disclosed (no confirmed exploitation)
CVE-2026-56164 targets Microsoft SharePoint Server and allows an attacker to escalate privileges on a compromised or authenticated session, a pattern consistent with prior SharePoint EoP flaws that have been chained with RCE bugs for full server takeover. Given active exploitation, on-premises SharePoint farms should be treated as a top patching priority regardless of the “Moderate” severity label, since real-world attack chains often combine low-severity EoP bugs with other flaws for maximum impact.
CVE-2026-56155 affects Active Directory Federation Services (AD FS), Microsoft’s identity federation and SSO infrastructure component, and is also confirmed as exploited in the wild. Because AD FS underpins authentication trust across hybrid Azure AD/on-prem environments, successful exploitation could let an attacker escalate privileges and pivot toward broader identity infrastructure compromise, similar to the AD FS golden SAML attack patterns seen in past campaigns.
CVE-2026-50661 is a Windows BitLocker Security Feature Bypass vulnerability that was publicly disclosed ahead of patch availability, though no active exploitation has been confirmed yet. This mirrors the pattern of the disclosed “YellowKey” BitLocker bypass (CVE-2026-45585) from earlier in 2026, where attackers with physical device access exploited flaws in BitLocker’s recovery environment rather than its core encryption, allowing them to bypass disk encryption on lost or stolen devices.
This month’s rollout includes two Critical-rated Remote Code Execution bugs in SharePoint and Print Spooler, alongside dozens of Important-severity Elevation of Privilege and RCE issues affecting core Windows components.
Impact TypeCountElevation of Privilege249Remote Code Execution143Information Disclosure102Denial of Service35Security Feature Bypass17Spoofing16Tampering8Total570
The July batch spans Windows OS components, Microsoft Office, SharePoint Server, Remote Desktop Services, and Windows Admin Center, with most fixes requiring customer action rather than being resolved automatically via cloud servicing.
Two vulnerabilities stand out as Critical: CVE-2026-58644, a Microsoft SharePoint Remote Code Execution flaw, and CVE-2026-58608, a Windows Print Spooler RCE bug, both categories that have historically been favored attack vectors for ransomware operators and nation-state actors.
Elevation of Privilege remains the dominant bug class this cycle, affecting components like the Windows Kernel, DirectX Graphics Kernel, Desktop Window Manager, and Win32K subsystem, which attackers typically chain with an initial foothold to gain SYSTEM-level access.
Enterprises running SharePoint on-premises deployments should prioritize CVE-2026-58644 given its Critical rating and RCE impact, mirroring the exploitation patterns seen in prior SharePoint zero-day campaigns.
Organizations exposing Remote Desktop Services, Windows Admin Center, or DHCP Server to internal or hybrid networks should also treat CVE-2026-58626, CVE-2026-58631, and CVE-2026-58627 as high priorities, since these affect infrastructure commonly targeted in lateral-movement attacks.
CVE IDVulnerabilitySeverityCategoryAffected ComponentCVE-2026-58647Microsoft PowerBI Report Server SpoofingImportantSpoofingPower BICVE-2026-58644SharePoint RCECriticalRCEMicrosoft Office SharePointCVE-2026-58640Windows NTFS RCEImportantRCEWindows NTFSCVE-2026-58638Windows Boot Loader Security Feature BypassImportantSecurity Feature BypassWindows Boot LoaderCVE-2026-58637Windows Client-Side Caching EoPImportantEoPWindows CSC ServiceCVE-2026-58636Microsoft PC Manager EoPImportantEoPWindows PC ManagerCVE-2026-58635Windows Narrator Braille EoPImportantEoPWindows Narrator BrailleCVE-2026-58634Desktop Window Manager EoPImportantEoPDesktop Window ManagerCVE-2026-58633Desktop Window Manager EoPImportantEoPDesktop Window ManagerCVE-2026-58632Windows Win32K EoPImportantEoPWindows Win32KCVE-2026-58631Windows Admin Center RCEImportantRCEWindows Admin CenterCVE-2026-58629DirectX Graphics Kernel EoPImportantEoPWindows DirectXCVE-2026-58628Windows Wireless Network Manager EoPImportantEoPWindows Wireless NetworkingCVE-2026-58627Windows DHCP Server DoSImportantDoSWindows DHCP ServerCVE-2026-58626Windows RDS RCEImportantRCEWindows Remote Desktop ServicesCVE-2026-58619Windows Sensor Data Service EoPImportantEoPWindows Sensor Data ServiceCVE-2026-58618Microsoft Excel RCEImportantRCEMicrosoft Office ExcelCVE-2026-58617M365 Copilot for iOS EoPImportantEoPMicrosoft 365 Copilot for iOSCVE-2026-58614Windows Kernel Security Feature BypassImportantSecurity Feature BypassWindows KernelCVE-2026-58613Windows Cloud Files Mini Filter Driver EoPImportantEoPCloud Files Mini Filter DriverCVE-2026-58610Windows Media Foundation RCEImportantRCEWindows Media FoundationCVE-2026-58609Windows Graphics Component RCEImportantRCEMicrosoft Graphics ComponentCVE-2026-58608Windows Print Spooler RCECriticalRCEWindows Print Spooler ComponentsCVE-2026-58602Windows Kernel-Mode Driver EoPImportantEoPWindows Kernel Mode DriverCVE-2026-58601VHD Miniport Driver EoPImportantEoPVirtual Hard Disk Miniport DriverCVE-2026-58595Microsoft Bing App for iOS SpoofingImportantSpoofingMicrosoft Bing App for iOSCVE-2026-58594Remote Desktop Client RCEImportantRCEWindows RDPCVE-2026-58547Windows UPnP Device Host EoPImportantEoPUPnP (upnp.dll)CVE-2026-58546Windows RDP Client Information DisclosureImportantInfo DisclosureWindows RDPCVE-2026-58545Windows Kernel Security Feature BypassImportantSecurity Feature BypassWindows Kernel
IT administrators should prioritize testing and deploying patches for the two Critical RCE flaws in SharePoint and Print Spooler within the next 48 hours, given their history as high-value exploitation targets.
All other listed CVEs are marked “Customer action required,” meaning automated cloud patching does not apply and manual update deployment through Windows Update or WSUS is necessary for full remediation.
The post Massive Microsoft Patch Tuesday Update: 570 Vulnerabilities Fixed, Including 3 Zero-Days appeared first on Cyber Security News.


