Summary

Microsoft’s July 2026 Patch Tuesday is the largest in the company’s history, addressing between 570 and 622 security vulnerabilities across Windows and its broader software ecosystem — nearly triple the count from last month’s already record-breaking release. Of those, 57 are rated Critical. Microsoft attributed the unprecedented volume directly to AI-assisted vulnerability discovery, with EVP Pavan Davuluri stating that AI is now enabling the company to “find more issues, faster, across more code.”

Two zero-day vulnerabilities are being actively exploited in the wild and have been added to CISA’s Known Exploited Vulnerabilities catalog. CVE-2026-56155 is an elevation-of-privilege flaw in Active Directory Federation Services (AD FS). CVE-2026-56164 is a missing-authentication bug in Microsoft SharePoint Server that allows an unauthenticated attacker to elevate privileges over the network with low complexity — SharePoint had previously been rated “Exploitation Less Likely” before it was added to CISA’s KEV on July 1. A third zero-day, CVE-2026-50661, is a BitLocker security feature bypass requiring physical access; it has been publicly disclosed but is not yet actively exploited.

Other highlights include CVE-2026-48561, a CVSS 9.6 remote code execution flaw in Microsoft Copilot exploitable via a malicious webpage that silently feeds crafted prompts to Copilot through Edge for Android, and a high-severity stored XSS in Outlook Web Access (CVE-2026-55008) triggerable by simply opening a crafted email. Tenable researcher Satnam Narang also flagged that Anthropic’s Mythos Preview model produced working proof-of-concept exploits for 13 of 14 vulnerabilities rated “Exploitation Less Likely” — a direct indictment of Microsoft’s human-centric exploitability index.

Sources

Commentary

The numbers here are staggering, but the real story is what they signal: AI has permanently changed the cadence of vulnerability discovery, and the old patch-in-30-days posture is dead. When AI models can crank out working exploits for flaws that Microsoft itself called “unlikely” to be exploited, every day of delay is a calculated gamble. The SharePoint zero-day’s journey from “Exploitation Less Likely” to actively exploited to CISA KEV in under two weeks should be a wake-up call for every enterprise sitting on a 30-day patch cycle.

The Copilot RCE vector is particularly worth watching: a malicious webpage silently weaponizing your AI assistant via Edge is a new and elegant attack class. As AI gets baked deeper into the OS, the attack surface expands in ways that traditional patch metrics weren’t designed to track. This is the new normal.

By Allan