Microsoft patches 622 bugs, including two exploited zero-days

Microsoft released July Patch Tuesday updates fixing 622 vulnerabilities, including two zero-days exploited in Active Directory Federation Services and SharePoint Server.

Microsoft on Tuesday released July Patch Tuesday updates that fix 622 vulnerabilities across Windows, Office and other products, including two flaws that have been exploited in the wild.

The two exploited zero-days are tracked as CVE-2026-56155 and CVE-2026-56164. CVE-2026-56155 affects Active Directory Federation Services and can allow a local attacker to elevate privileges to administrator. CVE-2026-56164 affects SharePoint Server and can be exploited remotely over a network without authentication, potentially leading to privilege escalation. Microsoft also called attention to CVE-2026-50661, a BitLocker security feature bypass that can be used by an attacker with physical access; that issue was publicly disclosed before the July update.

Microsoft’s release notes show 416 of the fixes apply to Windows and 164 to Office. Other high-severity fixes include a Windows VMSwitch vulnerability tracked as CVE-2026-57092 with a CVSS score of 9.9 and SharePoint defects including CVE-2026-50522 rated 9.8. Additional addressed flaws include a cross-site scripting bug in Exchange Server (CVE-2026-55008) and remote code execution vulnerabilities in Remote Desktop Protocol (CVE-2026-56190), Windows DHCP Server (CVE-2026-50518), a Windows Server network driver (CVE-2026-56188) and the Minecraft Bedrock Dedicated Server (CVE-2026-55010). Microsoft’s updates also cover Azure, Defender, developer tools, Edge and SQL Server.

Tenable senior staff research engineer Satnam Narang suggested the BitLocker bypass could be related to a recent batch of zero-days disclosed by a researcher who uses the names Nightmare‑Eclipse or Chaotic‑Eclipse, and noted there has been no official confirmation.

Windows executive vice president Pavan Davuluri wrote that AI is accelerating vulnerability discovery at Microsoft and described a multi-model agentic scanning harness called MDASH that the company uses to find bugs across the Windows codebase.

Adobe issued its own fixes on Tuesday for 88 vulnerabilities in products including ColdFusion, Commerce, Experience Manager and Illustrator. System administrators and organizations running affected Microsoft and Adobe products are advised to apply the July updates promptly to address known exploitation and reduce exposure to high-risk bugs.

Articles by this author