
Microsoft Shatters Patch Tuesday Record with More Than 620 Security Fixes in July
Microsoft has released one of the largest collections of security updates in its history, addressing more than 620 vulnerabilities across Windows, Microsoft Office, Exchange, Edge, and other products during July. The company’s official Patch Tuesday release alone fixed 570 new security flaws, setting a new record for monthly security patches.
The unprecedented number of fixes highlights both the growing complexity of Microsoft’s software ecosystem and the increasing pace of cybersecurity threats.
A Record-Breaking Month for Security Updates
Microsoft’s July Patch Tuesday far surpassed the previous monthly record of 206 vulnerabilities, which was set just one month earlier in June.
Since the beginning of 2026, Microsoft has now fixed approximately 1,380 vulnerabilities, already exceeding the previous annual record of 1,250 set in 2020.
The next scheduled Patch Tuesday is set for August 11, 2026.
Windows Receives More Than 400 Security Fixes
The majority of July’s updates targeted Windows.
Microsoft addressed 413 vulnerabilities affecting supported versions of:
- Windows 10
- Windows 11
- Windows Server
The release comes shortly after Microsoft announced an extension of the Windows 10 Extended Security Updates (ESU) program through October 12, 2027.
Active Directory Vulnerability Already Under Attack
Among this month’s patches, one vulnerability is already being actively exploited.
The flaw, CVE-2026-56155, affects Active Directory Federation Services (ADFS) and allows attackers to gain administrator privileges due to insufficient access controls.
Affected platforms include:
- Windows Server 2012 through Windows Server 2025
- Windows 10 versions 1607 and 1809
Because the vulnerability is already being exploited in the wild, administrators are encouraged to deploy the update immediately.
Critical Remote Code Execution Vulnerabilities
Microsoft fixed numerous critical flaws capable of allowing remote code execution.
Notable vulnerabilities include:
- CVE-2026-57092 — A Hyper-V VMSwitch use-after-free vulnerability that enables attackers with low privileges inside a virtual machine to elevate privileges on the host system.
- CVE-2026-56190 — A Remote Desktop Protocol (RDP) vulnerability that allows specially crafted RDP packets to execute arbitrary code through improperly initialized memory.
- CVE-2026-50518 — A remote code execution flaw affecting DHCP Server.
- CVE-2026-56188 — A Windows Server network driver vulnerability that allows malicious network packets to trigger remote code execution across supported Windows versions.
Office Receives Nearly 100 Security Fixes
Microsoft also addressed 97 vulnerabilities in Microsoft Office products.
Among them were:
- 17 critical remote code execution vulnerabilities
- Numerous flaws that can be exploited simply by previewing a malicious Office document
- Additional “open-and-own” vulnerabilities triggered when users open specially crafted Office files
The updates further reinforce the importance of keeping Office applications fully patched.
SharePoint Vulnerabilities Under Active Exploitation
Several SharePoint Server vulnerabilities also received attention.
Most notably:
- CVE-2026-56164 — An elevation-of-privilege vulnerability already being exploited in active attacks.
- CVE-2026-55040 — A security feature bypass vulnerability that allows unauthorized access to files.
- CVE-2026-50522 and CVE-2026-58644 — Critical remote code execution flaws, with one having already been demonstrated during the Pwn2Own hacking competition.
Exchange and Edge Updates
Microsoft fixed:
- Four vulnerabilities in Exchange Server
- One additional vulnerability in Exchange Online
Among them, CVE-2026-55008 allows attackers to execute malicious JavaScript through Outlook Web Access (OWA) by exploiting a cross-site scripting (XSS) flaw.
Meanwhile, Microsoft Edge 150.0.4078.65, based on Chromium 150.0.7871.115, patched 27 Chromium vulnerabilities. Those fixes are separate from Microsoft’s Patch Tuesday totals, and when combined with nearly 400 Chromium vulnerabilities addressed earlier in July, the month’s overall security fixes exceed 1,000 across Microsoft’s ecosystem.
Gamers Should Update Too
Microsoft also released security updates for several gaming products.
For Minecraft Bedrock Dedicated Server, the company has already patched CVE-2026-55010, requiring no further action from server operators.
However, Age of Empires II: Definitive Edition users should install the latest update promptly. The patched CVE-2026-50663 vulnerability allows attackers to distribute malicious scenario files capable of placing and potentially executing harmful code on another player’s system.
One of Microsoft’s Largest Security Releases Ever
July 2026 marks one of the most significant Patch Tuesday releases Microsoft has ever issued. With hundreds of vulnerabilities fixed—including several already being exploited in real-world attacks—the update underscores the growing importance of installing Windows and Microsoft software updates as soon as they become available.




