Microsoft Releases Patch Tuesday: A Deep Dive into July’s Security Updates and the Evolving Landscape of Vulnerability Discovery

Microsoft on Tuesday released 575 patches affecting 29 product families. Sixty-three of the addressed issues are considered by Microsoft to be of Critical severity; 44 CVEs are expected to be exploited within the next 30 days. (Two already are, though neither CVE-2026-56155 nor CVE-2026-56164 is considered to be of Critical severity.) One hundred and three have a CVSS Base score of 8.0 or higher. Just one was publicly disclosed as of release day and two are acknowledged to be under active exploit in the wild.
The advisory tally this month is likewise elevated. In addition to the usual Servicing Stack update, there are 479 advisories, all touching Edge. Virtually all of these were patched in advance of Patch Tuesday, but as ever we encourage readers to be sure that they’ve applied all available browser patches when those are made available. There were no Adobe-related patches made available by Microsoft this month, and aside from the 435 Chromium-issued Edge advisory items, all CVEs (and the Servicing Stack) originated with Microsoft.
Various of this month’s issues are amenable to direct detection by Sophos protections, and we include information on those in the usual table below.
Stepping back from this July’s output, we’re more or less four months into the AI-finder era of bug hunting, and patterns are starting to emerge from the noise. First, either finders are suddenly building coalitions that would shame NATO or simultaneous discovery is rampant. In years past it was unusual to see a single bug credited to more than half a dozen finders; this month alone saw at least four CVEs with ten or more credits listed. One, an otherwise remarkable PowerShell RCE bug labeled CVE-2026-40400, has fifteen. In a related vein, bug totals for certain finders (whether individuals or committees) are astonishing. Having a dozen or more CVEs credited to the same entity in the same month is now entirely normal; this month’s top CVE submitter, 0ccbbf129444eb66344ccafb92b00df4, has 47 July credits (44 in Office, over half the month’s Office total) to their handle.
Second, though the volume is overwhelming, so far these bugs are turning up in the lab, not the wild. (No complaints.) None of 0ccbbf129444eb66344ccafb92b00df4’s bugs have been seen yet in the wild, and only seven of them are Critical-severity. The heat map in Figure 1 shows that in fact, the percentage of bugs that have either been publicly disclosed or found in the wild has dropped in recent months. Even the percentage of CVEs Microsoft deems more likely to be exploited within the next 30 days is relatively low.
July Patch Tuesday: A Record-Breaking Release Amidst Shifting Vulnerability Discovery Trends
Microsoft’s July Patch Tuesday has once again underscored the relentless pace of cybersecurity challenges, with the technology giant issuing a substantial 575 patches across 29 distinct product families. This significant release addresses a wide array of vulnerabilities, with 63 classified as "Critical" in severity. A concerning 44 of these vulnerabilities are anticipated by Microsoft to be actively exploited by malicious actors within the next 30 days, with two already confirmed to be under active attack, although they do not carry the highest severity rating. Adding to the urgency, 103 of the patched issues carry a CVSS (Common Vulnerability Scoring System) Base score of 8.0 or higher, indicating a high potential for exploitation.
This month’s Patch Tuesday also highlights a significant increase in advisory notifications, with 479 advisories issued, primarily concerning Microsoft Edge. While the vast majority of these Edge-related issues were addressed proactively before the official Patch Tuesday, users are strongly advised to ensure their browsers are consistently updated to the latest versions as soon as patches become available. Notably, there were no Adobe-related patches included in this month’s Microsoft release. With the exception of the 435 Chromium-issued Edge advisory items, all other CVEs and the essential Servicing Stack update originated directly from Microsoft.
The sheer volume of vulnerabilities addressed this month provides a stark reminder of the ongoing efforts required to maintain robust cybersecurity postures. Organizations are once again faced with the critical task of prioritizing and deploying these patches to mitigate potential risks.

The Evolving Landscape of Vulnerability Discovery: AI’s Growing Influence
Beyond the immediate implications of the patch release, this month’s data offers a fascinating glimpse into the evolving world of vulnerability discovery. Approximately four months into what is being termed the "AI-finder era," distinct patterns are beginning to emerge from the increased volume of reported bugs. One striking trend is the apparent surge in coordinated vulnerability disclosure or a significant rise in simultaneous discoveries. Historically, it was uncommon for a single vulnerability to be credited to more than a handful of researchers. However, this July saw at least four CVEs with ten or more researchers listed as finders. A particularly noteworthy example is CVE-2026-40400, a critical Remote Code Execution (RCE) vulnerability in PowerShell, which boasts an impressive fifteen credits.
This collaborative or coincidental discovery pattern is mirrored in the sheer volume of vulnerabilities attributed to specific entities. It has become increasingly common for individuals or research groups to be credited with a dozen or more CVEs in a single month. This month’s leading contributor, identified by the handle 0ccbbf129444eb66344ccafb92b00df4, amassed an astonishing 47 July credits, with 44 of those specifically related to Microsoft Office vulnerabilities, accounting for over half of all Office-related CVEs patched this month.
AI’s Impact: Volume vs. Immediate Threat
Despite the overwhelming quantity of newly discovered vulnerabilities, a crucial observation is that the majority are currently being identified in laboratory settings rather than actively exploited in the wild. This is a welcome development for cybersecurity professionals. None of the vulnerabilities discovered by the top contributor, 0ccbbf129444eb66344ccafb92b00df4, have yet been observed in real-world attacks, and only seven of them are classified as Critical severity.
A deeper analysis, visualized in Figure 1, indicates a declining trend in the percentage of vulnerabilities that have been either publicly disclosed or found to be actively exploited in recent months. Even the proportion of CVEs that Microsoft predicts are more likely to be exploited within the next 30 days remains relatively low. This trend raises intriguing questions about the ultimate impact of AI-driven bug hunting. While the sheer volume of discoveries suggests a more thorough uncovering of potential weaknesses, the current lack of widespread active exploitation could be interpreted in several ways. It might signify that these AI-powered tools are indeed facilitating a comprehensive "code cleanup," identifying a vast number of bugs that, while present, are not immediately exploitable or are being discovered before malicious actors can leverage them. The long-term implications of this AI-driven discovery process remain to be seen, but it undeniably marks a significant shift in the cybersecurity landscape.
Adapting to the Scale: New Data Presentation for Patch Management
The sheer magnitude of vulnerabilities disclosed each month necessitates adaptations in how security professionals approach their Patch Tuesday routines. This publication is also adjusting its methodology to better serve its readers. For those who have relied on appendices for guidance, a new system is being implemented, designed to cater to users who value detailed data presented in a more accessible spreadsheet format.
Key Vulnerability Metrics for July
Microsoft’s July Patch Tuesday addresses a broad spectrum of security flaws, with vulnerabilities categorized by type and severity. While the overall number of patches is high, notable shifts are observable in the prevalence of certain vulnerability classes. Figure 2, a heat map analyzing Patch Tuesday numbers over the past year, indicates that while overall CVE counts remain elevated, the nature of the bugs coming to light in recent months suggests they may not pose an immediate, widespread threat to internet security.

Interestingly, July saw a decrease in the counts for Security Feature Bypass and Spoofing vulnerabilities. This decline could potentially indicate that certain types of bugs are more amenable to discovery through AI-driven methods than others, or that the focus of research has shifted.
Product-Specific Vulnerabilities: A Detailed Breakdown
When analyzing the distribution of patches, it’s customary to count a CVE for each product family it affects. This month, the distribution of vulnerabilities across Microsoft’s product families is as follows:
- Windows: This operating system continues to be a primary target, with 407 CVEs addressed in this release. Of these, 31 are Critical, 375 are Important, and one is Moderate. This significant number underscores the ongoing need for diligent patching of Windows environments.
- Microsoft Edge: As previously mentioned, Edge saw a substantial number of advisories, with 435 Chromium-issued advisories and an additional 31 Important-severity Edge CVEs requiring specific user interaction, often involving double-tap gestures akin to using autofill features.
- Microsoft Office: This suite of productivity applications also experienced a significant number of vulnerabilities, with 16 Office CVEs highlighted, many of which are Critical severity and exploitable via the Preview Pane.
- Microsoft SharePoint: This collaboration platform is affected by multiple Remote Code Execution (RCE) vulnerabilities, including CVE-2026-50522 and CVE-2026-58644.
- Microsoft Exchange Server: A Spoofing vulnerability, CVE-2026-55008, has been addressed for this critical server component.
- Microsoft Dynamics NAV and Business Central (On Premises): These business management solutions are impacted by RCE vulnerability CVE-2026-55944.
- Windows Server Network Driver: A critical RCE vulnerability, CVE-2026-56188, has been patched for this essential server component.
- Other Product Families: Ten product families received just one patch apiece this month, highlighting the varied and widespread nature of potential security weaknesses. A comprehensive Excel spreadsheet linked below provides detailed information on all these instances.
Emerging Vulnerability Trends: Elevation of Privilege and Remote Code Execution
Figure 4 provides a compelling visual representation of vulnerability trends over the past seven months. Notably, Elevation of Privilege issues have proven to be twice as prevalent as Remote Code Execution (RCE) flaws. This suggests a strategic focus by attackers on gaining elevated access within systems, which can then be used to facilitate further malicious activities. Concurrently, Security Feature Bypass vulnerabilities have seen their first Critical-severity patch this month, specifically for a SharePoint issue identified as CVE-2026-55040.
Notable July Updates: Prioritizing the Most Pressing Threats
While the sheer volume of patches is daunting, certain vulnerabilities demand immediate attention due to their severity and potential for rapid exploitation. Microsoft has identified six CVEs that warrant particular focus:
- CVE-2026-50518: Windows DHCP Server Remote Code Execution Vulnerability
- CVE-2026-50522: Microsoft SharePoint Remote Code Execution Vulnerability
- CVE-2026-55008: Microsoft Exchange Server Spoofing Vulnerability
- CVE-2026-55944: Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
- CVE-2026-56188: Windows Server Network Driver Remote Code Execution Vulnerability
- CVE-2026-58644: Microsoft SharePoint Remote Code Execution Vulnerability
These vulnerabilities are characterized by high CVSS Base scores (above 9.0), Critical severity ratings, and a higher likelihood of exploitation within the next 30 days, according to Microsoft’s assessment. For organizations struggling to prioritize their patching efforts, these six CVEs represent a clear starting point.
Furthermore, a cluster of 16 Office CVEs, including CVE-2026-50301, CVE-2026-50314, CVE-2026-50467, CVE-2026-55018, CVE-2026-55022, CVE-2026-55033, CVE-2026-55045, CVE-2026-55049, CVE-2026-55056, CVE-2026-55057, CVE-2026-55127, CVE-2026-55129, CVE-2026-55132, CVE-2026-55140, CVE-2026-56193, and CVE-2026-56195, are all exploitable via the Preview Pane. While all but three of these are Critical-severity, Microsoft judges them to be less likely to be exploited in the immediate future.
Edge Vulnerabilities and the Human Element of Bug Hunting

The 31 Important-severity Edge CVEs, primarily advisory-only, highlight the continued productivity of vulnerability researchers. Microsoft’s own Kugelblitz is credited with discovering 38 Important-severity Edge bugs this month, 37 of which were solo discoveries. The intriguing aspect of 31 of these bugs is their reliance on a very specific user interaction: two sequential taps, similar to what one might perform when using autofill on a web page. While the sheer volume of bug hunting at this scale strongly suggests automated processes, the mental image of a researcher meticulously tapping a screen repeatedly in pursuit of vulnerabilities is a curious one, even if it is likely a simplified representation of a complex automated process.
Even the realm of gaming is not immune to the "patchapalooza," with patches released for CVE-2026-55010 (Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability) and CVE-2026-50663 (Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability).
Sophos Protections: Ensuring Defense Against Emerging Threats
Sophos has proactively developed protections for many of the vulnerabilities disclosed in this month’s Patch Tuesday. The table below details specific CVEs and the corresponding Sophos Intercept X/Endpoint IPS and Sophos XGS Firewall signatures designed to detect and block these threats.
| CVE | Sophos Intercept X/Endpoint IPS | Sophos XGS Firewall |
|---|---|---|
| CVE-2026-49170 | Exp/2649170-A | Exp/2649170-A |
| CVE-2026-49795 | Exp/2649795-A | Exp/2649795-A |
| CVE-2026-49798 | Exp/2649798-A | Exp/2649798-A |
| CVE-2026-49800 | Exp/2649800-A | Exp/2649800-A |
| CVE-2026-50329 | Exp/2650329-A | Exp/2650329-A |
| CVE-2026-50332 | Exp/2650332-A | Exp/2650332-A |
| CVE-2026-50343 | Exp/2650343-A | Exp/2650343-A |
| CVE-2026-50351 | Exp/2650351-A | Exp/2650351-A |
| CVE-2026-50375 | Exp/2650375-A | Exp/2650375-A |
| CVE-2026-50387 | Exp/2650387-A | Exp/2650387-A |
| CVE-2026-50390 | Exp/2650390-A | Exp/2650390-A |
| CVE-2026-50420 | Exp/2650420-A | Exp/2650420-A |
| CVE-2026-50423 | Exp/2650423-A | Exp/2650423-A |
| CVE-2026-50433 | Exp/2650433-A | Exp/2650433-A |
| CVE-2026-50436 | Exp/2650436-A | Exp/2650436-A |
| CVE-2026-50454 | Exp/2650454-A | Exp/2650454-A |
| CVE-2026-50475 | Exp/2650475-A | Exp/2650475-A |
| CVE-2026-50476 | Exp/2650476-A | Exp/2650476-A |
| CVE-2026-50518 | sid:2312733 | sid:2312734 |
| CVE-2026-50522 | sid:2312729 | sid:2312729 |
| CVE-2026-50667 | Exp/2650667-A | Exp/2650667-A |
| CVE-2026-50688 | Exp/2650688-A | Exp/2650688-A |
| CVE-2026-54114 | Exp/2654114-A | Exp/2654114-A |
| CVE-2026-54986 | Exp/2654986-A | Exp/2654986-A |
| CVE-2026-54992 | sid:2312741 | sid:2312741 |
| CVE-2026-56164 | sid:2312731, sid:2312732 | sid:2312731, sid:2312732 |
| CVE-2026-57091 | Exp/2657091-A | Exp/2657091-A |
| CVE-2026-58536 | Exp/2658536-A | Exp/2658536-A |
For organizations that prefer to manually download and install updates, Microsoft provides cumulative update packages via the Windows Update Catalog website. Users can determine their current Windows build by running the winver.exe tool and then download the appropriate package for their system architecture and build number.
Comprehensive Data Analysis: The July 2026 Patch Tuesday Workbook
To facilitate a more in-depth understanding of this month’s extensive patch release, a comprehensive Excel workbook has been prepared. This resource, titled "PatchTuesday_July2026," offers a structured and sortable repository of all the disclosed vulnerabilities, moving beyond the limitations of a blog post format. The workbook includes several sheets, each designed to provide specific insights:
- PT_Summary: A concise overview of key monthly metrics.
- PT_PriSevImp: Ideal for sorting by impact, Microsoft-assigned severity, CVSS scores, and exploitability prospects.
- PT_ByProduct: A granular breakdown by product family, useful for managing vulnerabilities with multi-family applicability.
- PT_Windows: Details which versions of Windows are affected by each patched CVE, now expanded to include currently supported client versions.
- PT_Protections: A replica of the Sophos protections chart for easy reference.
- PT_Advisories: Information on third-party advisories, servicing stack updates, and all Edge-related CVEs.
- PT_CWE: A breakdown of the Common Weakness Enumeration (CWE) categories most frequently discovered in the patched products.
This structured approach to data presentation aims to empower security professionals with the tools needed to effectively navigate the complexities of modern patch management and enhance their overall cybersecurity resilience.





