HackMyIP
← Back to News
2026-07-14 KrebsOnSecurity

Microsoft Patches Record 570 Flaws in July Patch Tuesday, Credits AI for Surge

VulnerabilityZero-DayAI Security

Microsoft released patches for a record-breaking 570 security vulnerabilities across its operating systems and software portfolio in July's Patch Tuesday, nearly triple the count from its previous record-setting release. The software giant attributes the dramatic uptick to advances in artificial intelligence accelerating vulnerability discovery. Nearly 60 of the flaws fixed carry a "critical" severity rating, meaning attackers could exploit them to seize remote control over Windows devices with minimal user interaction. Microsoft also addressed three zero-day vulnerabilities, including two already being actively exploited in the wild.

Two of the zero-day weaknesses—CVE-2026-56155, an Active Directory Federation Services flaw, and CVE-2026-56164, a Microsoft SharePoint vulnerability—allow attackers to elevate privileges on a Windows system, as do approximately 250 other elevation-of-privilege bugs patched this month. CVE-2026-50661, a BitLocker security feature bypass, could grant attackers access to encrypted data if they have physical access to the device. Microsoft noted the bug has been publicly disclosed but is not known to be under active exploitation. Jack Bicer, director of vulnerability research at Action1, highlighted CVE-2026-48561, a remote code execution flaw in Microsoft Copilot carrying a CVSS score of 9.6, which allows unauthorized network-based code execution by luring victims to a malicious site that auto-sends crafted prompts to Copilot via Edge for Android.

In a July 9 blog post, Microsoft Executive Vice President Pavan Davuluri acknowledged the shift, stating that "the pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code." However, that same AI acceleration is empowering attackers to develop working exploits at machine speed. Satnam Narang, senior staff research engineer at Tenable, argued Microsoft's exploitability index is failing to keep pace—Microsoft originally rated July's SharePoint zero-day as "less likely" to be exploited, yet CISA added it to the Known Exploited Vulnerabilities catalog on July 1. Organizations should prioritize patching immediately and audit their exposure; administrators can use a port scanner to identify exposed services and a SSL/TLS checker to verify secure configurations, while individual users should run a password checker to ensure credentials tied to patched Microsoft accounts remain strong.

Source: KrebsOnSecurity →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →