Microsoft released its July 2026 Patch Tuesday updates to fix 570 security flaws, including two zero-days already being used in attacks and one publicly disclosed flaw. The exploited bugs are CVE-2026-56155 in Active Directory Federation Services (AD FS), a local privilege-escalation issue, and CVE-2026-56164 in Microsoft SharePoint Server, a network-reachable elevation-of-privilege flaw caused by missing authentication for a critical function; Microsoft also fixed the publicly disclosed BitLocker bypass CVE-2026-50661.
Ionut Arghire
2026.07.15
72% relevant
This article adds post-Patch-Tuesday operational guidance and KEV action for SharePoint, specifically highlighting CVE-2026-56164 as actively exploited and reminding defenders that CVE-2026-55040 and CVE-2026-58644 were also fixed in the same July release.
2026.07.15
84% relevant
This article adds operational impact to the July 2026 Patch Tuesday story: Microsoft has paused distribution of that month's Windows security update for some Dell devices with Intel processors because Dell-reported incompatibilities can cause shutdowns, overheating, poor performance, and battery drain.
2026.07.15
97% relevant
This article is a direct follow-up on the same July 2026 Patch Tuesday event, adding updated scale (622 CVEs), naming the exploited flaws CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services, and noting a notable SharePoint exploit chain involving CVE-2026-55040.
info@thehackernews.com (The Hacker News)
2026.07.15
76% relevant
This appears to add follow-on reporting that a researcher published proof-of-concept exploit code for a new Windows zero-day within hours of Microsoft's July 2026 Patch Tuesday, increasing urgency around one of the flaws addressed in that release.
2026.07.14
99% relevant
This article is a report on the same July 2026 Microsoft Patch Tuesday event and adds detail on the scale of the release, including 622 Microsoft CVEs plus 428 Chromium CVEs in Edge, and specifics on exploited CVEs CVE-2026-56155 (AD FS) and CVE-2026-56164 (SharePoint), as well as publicly disclosed CVE-2026-50661 and other critical issues.
info@thehackernews.com (The Hacker News)
2026.07.14
97% relevant
This appears to be another report on the same July 2026 Microsoft Patch Tuesday event, describing the same underlying release cycle and highlighting two zero-days under active attack, while differing mainly in flaw-count framing.
BrianKrebs
2026.07.14
99% relevant
This is a direct report on the same July 2026 Microsoft Patch Tuesday event, adding detail on the total flaw count, the three zero-days addressed, the publicly disclosed BitLocker issue CVE-2026-50661, and notable high-severity bugs such as Copilot RCE CVE-2026-48561.
Ionut Arghire
2026.07.14
98% relevant
This article covers the same July 2026 Microsoft Patch Tuesday event and adds that Microsoft says it fixed a record 622 vulnerabilities, highlights the exploited zero-days CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint Server, and notes public disclosure of BitLocker bypass CVE-2026-50661 plus several other critical flaws.
Lawrence Abrams
2026.07.14
100% relevant
This article establishes a distinct July 2026 Microsoft Patch Tuesday event centered on newly fixed zero-days, separate from the already tracked June 2026 Patch Tuesday story.