Microsoft Patches Record 570 Windows Vulnerabilities in July Update, Including Three Actively Exploited Zero-Days
Microsoft has issued its largest monthly security update yet, releasing patches for a record 570 vulnerabilities across Windows and associated products. The July Patch Tuesday rollout includes three zero-day flaws, two of which were already being actively exploited in real attacks.
Fifty-nine of the issues received a critical severity rating. Of these, 48 allow remote code execution, nine enable privilege escalation, and the remainder involve security feature bypass or data tampering. The largest category of fixes addressed privilege escalation vulnerabilities, totaling 254, followed by 145 remote code execution flaws, 102 information disclosure issues, 35 denial-of-service problems, and 16 spoofing vulnerabilities.
The first actively exploited zero-day, CVE-2026-56155, affects Active Directory Federation Services. An authenticated attacker can abuse the flaw to obtain administrative privileges. Microsoft has not yet disclosed technical details of the observed attacks.
The second zero-day, CVE-2026-56164, resides in SharePoint Server. Due to missing authentication checks, a remote attacker can elevate privileges. As a temporary mitigation, Microsoft recommends enabling AMSI and full request-body scanning.
The third zero-day, CVE-2026-50661, was already publicly known before the update. It allows an attacker with physical access to bypass BitLocker encryption and access protected data. Microsoft had previously warned that the volume of patches would increase because the company is now using AI to hunt for vulnerabilities in the Windows source code.
The update touches numerous components, including multiple versions of .NET and .NET Framework, Active Directory Certificate Services, Active Directory Domain Services, Active Directory Federation Services, Azure Active Directory, Microsoft Office and Excel, Microsoft Defender, Exchange Server, and various Azure services. A selection of the addressed CVEs includes:
- .NET – CVE-2026-50649 (Remote Code Execution, Important), CVE-2026-50525 (Denial of Service, Important)
- Active Directory Federation Services – CVE-2026-56155 (Elevation of Privilege, Important)
- Microsoft Office – CVE-2026-55129, CVE-2026-55049, CVE-2026-55045 (Remote Code Execution, Critical)
- Microsoft Defender – CVE-2026-55012, CVE-2026-55011 (Remote Code Execution, Critical)
Security teams are strongly encouraged to deploy the updates as soon as possible to reduce exposure to both known and newly discovered threats.
Related articles
N-able Releases Hotfix for Exploited N-central Authentication Bypass Flaw CVE-2026-18577
N-able has published a hotfix addressing a high-severity authentication bypass vulnerability in its N-central IT operations management platform. The flaw, tracked as CVE-2026-18577, allows attackers to bypass authentication through alternative paths or channels and potentially take over user accounts. It affects N-central 2026.1 and earlier versions and stems from an incomplete fix for the earlier CVE-2026-18556 issue. The vulnerability carries a CVSS v4.0 base score of 8.2 and is rated High severity. Exploitation has already been observed in the wild, with Indicators of Compromise including related IP addresses now publicly available. N-able released N-central 2026.3 Hotfix 1 (build 2026.3.1.7) on August 2, 2026, and urges customers to apply the update while also recommending agent updates where possible.
Adobe Releases Emergency Update for Campaign Classic Fixing Multiple Critical Vulnerabilities
Adobe has issued an urgent security update for Adobe Campaign Classic to address seven critical vulnerabilities, including several with a maximum CVSSv3.1 base score of 10.0. The flaws affect on-premises deployments on Windows and Linux as well as the on-premises components of hybrid setups. Notably, the newly released fixes also impact the previous emergency update from July 29, version 7.4.3 build 9398, requiring users to apply the latest patch immediately. Among the most severe issues are a server-side request forgery vulnerability tracked as CVE-2026-48331, an input handling flaw in the template engine identified as CVE-2026-48323, and an SQL injection vulnerability labeled CVE-2026-48330. Adobe published the corresponding security advisory on August 3, 2026, urging rapid remediation despite the short interval since the prior update.
Dark Patterns in Vulnerability Management: How Metrics Undermine Real Security
Vulnerability management programs often fail not due to lack of scanners but because of poorly chosen metrics that prioritize reporting over actual risk reduction. Teams focus on closing easy vulnerabilities, meeting CVSS-based deadlines, and improving dashboard numbers while attackers exploit the shortest path to critical assets. The article examines five common traps including total vulnerability counts, context-free SLAs, closure rate targets, static dashboards, and claims of no critical findings. It argues that these metrics create a false sense of security and distort team behavior according to Goodhart's Law. Instead, organizations should adopt attack path metrics, exposure management approaches such as CTEM, and measurements that track real reduction in attacker reachability. The piece highlights MaxPatrol Carbon as an example of tools that model attacker paths rather than isolated CVEs.
MongoDB Server Patches 24 Vulnerabilities Including Critical Flaw in mongod Compute Mode
MongoDB has released updates addressing 24 vulnerabilities in MongoDB Server, with one rated critical. The patches cover multiple branches and include fixes for CVE-2026-13072, which carries a CVSSv3.1 base score of 9.2. The critical issue affects standalone mongod instances with compute mode enabled and stems from insufficient validation of external input that can lead to memory corruption. Additional fixes resolve 16 high-severity issues, seven medium, and one low, including CVE-2026-13059 that could allow unauthorized read-write actions by low-privileged authenticated users. Updated versions MongoDB 8.3.7, 8.2.12, 8.0.28, and 7.0.39 are now available. The company published the updates on July 22, 2026, and urges immediate application to maintain system integrity.