
Disclaimer
This article is based on information published through July 16, 2026.
The number of vulnerabilities included in this security update varies by source and counting method. Reports cite 569 or 570 vulnerabilities, while broader counts place the total as high as 622. This article uses approximately 570 vulnerabilities, the figure reported by most of the referenced sources.
What This Article Covers
Microsoft has released a major July 2026 security update addressing vulnerabilities across Windows, Office, SharePoint Server, and other products.
The update was released as part of Patch Tuesday, Microsoft’s regular monthly security update cycle.
The July release is regarded as Microsoft’s largest Patch Tuesday update to date.
Key Points
- Microsoft’s July 2026 Patch Tuesday addressed approximately 570 vulnerabilities, or as many as 622 under broader counting methods.
- The update included two zero-day vulnerabilities already being exploited in attacks and one additional zero-day that had been publicly disclosed.
- Elevation-of-privilege and remote code execution vulnerabilities accounted for a large portion of the update.
- The affected products and components include Windows, Microsoft Office, SharePoint Server, Windows Admin Center, and several enterprise systems.
- Vulnerabilities affecting SharePoint Server and Active Directory Federation Services have already been used in real-world attacks, making prompt updates especially important.
Microsoft Released Its Largest-Ever Security Update
The total number of vulnerabilities included in the July update differs among security firms and technology publications.
Some sources counted 569 or 570 vulnerabilities, while broader counts placed the total as high as 622. Although the totals vary depending on the counting method, the release is widely regarded as Microsoft’s largest Patch Tuesday update to date.
In July 2025, Microsoft fixed 137 vulnerabilities. Using the figure of approximately 570, the July 2026 update includes roughly four times as many fixes as the release from the same month a year earlier.
The update covers several types of security flaws, including elevation of privilege, remote code execution, information disclosure, denial of service, security feature bypass, and spoofing vulnerabilities.
Elevation-of-privilege and remote code execution flaws made up a significant share of the total.
An elevation-of-privilege vulnerability may allow a user with limited permissions to gain administrator-level access.
A remote code execution vulnerability may allow an attacker to run malicious code on a targeted system over a network.
Why Did the Number of Vulnerabilities Increase So Sharply?
One reason for the scale of this update is the broad range of Microsoft products and components covered by the release.
The update applies not only to Windows but also to Microsoft Office, SharePoint Server, Windows Admin Center, and several server and networking components.
Within Windows, affected components include the kernel, Win32k, NTFS, Remote Desktop, DHCP, TCP/IP, Hyper-V, Secure Boot, BitLocker, File Explorer, Print Spooler, SMB, and Windows Installer.
Another important change is Microsoft’s expanding use of AI for vulnerability discovery.
Microsoft is using AI-based systems to examine the Windows codebase and identify security flaws that may previously have gone undetected.
For this reason, the increase in reported vulnerabilities does not necessarily mean that Windows suddenly became significantly less secure. It also reflects Microsoft’s ability to identify more previously hidden issues.
Microsoft has said that as AI-assisted vulnerability discovery expands, future security updates may contain more fixes than users have seen in the past.
What Are the Three Zero-Day Vulnerabilities?
A zero-day vulnerability is a security flaw that is publicly disclosed or exploited in an attack before an official patch becomes available.
The July update included three zero-day vulnerabilities.
Two were already being exploited in real-world attacks, while the third had been publicly disclosed before Microsoft released a security fix.
1) Active Directory Federation Services Elevation-of-Privilege Vulnerability
CVE-2026-56155 is an elevation-of-privilege vulnerability affecting Active Directory Federation Services.
Active Directory Federation Services supports authentication and sign-on functions across connected systems.
A user with limited privileges could exploit the vulnerability to gain administrator-level access.
Microsoft confirmed that the vulnerability had already been exploited in attacks.
2) Microsoft SharePoint Server Elevation-of-Privilege Vulnerability
CVE-2026-56164 is an elevation-of-privilege vulnerability affecting Microsoft SharePoint Server.
SharePoint Server is a collaboration platform used by businesses and organizations to store and share documents and other work-related information.
The vulnerability could allow an unauthenticated attacker to gain elevated privileges on a SharePoint server over a network.
Microsoft confirmed that this vulnerability had also been exploited in real-world attacks.
Organizations operating on-premises SharePoint servers should prioritize the security update.
3) Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-50661 is a vulnerability that could allow an attacker to bypass Windows BitLocker drive encryption.
BitLocker is designed to protect data stored on a computer if the device is lost or stolen.
An attacker with physical access to a targeted device could potentially bypass BitLocker protections and access encrypted data.
The vulnerability had been publicly disclosed before the patch became available, but no confirmed active exploitation had been reported.
Why Timely Updates Matter
Two of the zero-day vulnerabilities included in this update were already being exploited when Microsoft released the patches.
The affected vulnerabilities involve Active Directory Federation Services and Microsoft SharePoint Server.
Microsoft and cybersecurity organizations have advised users and organizations to apply the available security updates promptly.
The July update also includes critical remote code execution vulnerabilities affecting components such as SharePoint Server and Windows Print Spooler.
Systems that have not received the latest security updates remain exposed to the vulnerabilities addressed by the release.
How to Check for Windows Security Updates
Windows users can check whether the latest security updates have been installed through Windows Update.
- Select the Start button and open Settings.
- Select Windows Update.
- Select Check for updates.
- If an update is available, download and install it.
- Restart the computer if Windows asks you to do so after installation.
Recently installed updates can be reviewed by following this path:
Settings → Windows Update → Update history
How to Check Your Windows Version and OS Build Number
The July security update can also be checked by reviewing the Windows version and OS build number.
Windows 11 version 25H2 received OS Build 26200.8875.
Windows 11 version 24H2 received OS Build 26100.8875.
To check this information through Settings, follow this path:
Settings → System → About → Windows specifications
You can also check the information by using the Run window:
- Press the Windows key + R.
- Type winver.
- Select OK.
- Check the Windows version and OS build number shown in the window.
If the displayed build number is lower than the applicable July 2026 build, check Windows Update again.
What Should Businesses and Organizations Check?
Businesses and organizations should verify updates not only on employee computers but also across internally managed servers and authentication systems.
The following systems require particular attention:
- Microsoft SharePoint Server
- Active Directory Federation Services
- Computers running Microsoft Office
- Windows Server environments
- Systems using Remote Desktop Services
- Windows Admin Center
- Servers using Print Spooler or file-sharing functions
The zero-day vulnerabilities affecting SharePoint Server and Active Directory Federation Services have already been exploited in attacks.
Organizations using these products should prioritize the available security updates.
Why Does This Matter?
This update shows how AI is changing cybersecurity.
AI is no longer used only to build software features. It is also being used to identify security flaws across large and complex codebases.
Microsoft is using AI-powered vulnerability discovery systems to find more security issues in the Windows codebase before attackers exploit them.
At the same time, Microsoft has warned that attackers are also using AI to find vulnerabilities and target systems that have not been patched.
As AI-assisted vulnerability discovery expands, both the number and size of future security updates may continue to increase.
What to Watch Next
1) Larger Patch Tuesday Updates
Microsoft has said that customers may see more fixes in future security updates as its use of AI-based vulnerability discovery expands.
2) Continued Exploitation of Unpatched Systems
Two of the zero-day vulnerabilities fixed in July were already being used in attacks.
Organizations using the affected products will need to confirm that the relevant updates have been installed.
3) Faster Deployment of Security Updates
Microsoft has advised organizations to reduce delays in deploying Windows quality and security updates.
The company has also encouraged IT administrators to use update policies and management tools to deploy available fixes more quickly.
DANA NOTES Commentary
The most important part of this security update is not simply that Microsoft fixed approximately 570 or more vulnerabilities.
The larger shift is that AI is now being used not only to develop software, but also to discover security flaws.
AI can help Microsoft identify problems in large codebases that may previously have been difficult to find.
However, Microsoft has also warned that attackers are using AI to search for vulnerabilities and exploit systems that have not yet been updated.
Future security updates may therefore include even more fixes.
What matters most is not the number of vulnerabilities, but how quickly discovered problems are corrected and how quickly those fixes reach the systems people actually use.

