
Microsoft has released patches for more than 570 vulnerabilities during the July 2026 Patch Tuesday cycle, marking a historic volume of fixes. Among the vulnerabilities addressed are two that are already being leveraged by attackers (CVE-2026-56155 and CVE-2026-56164) and one that had been previously disclosed (CVE-2026-50661). The release follows a trend of increasingly large Patch Tuesday updates, driven largely by the integration of artificial intelligence tools into both security research and attack workflows.
Key Vulnerabilities Addressed
CVE-2026-56155 is an elevation of privilege (EoP) vulnerability in Active Directory Federation Services (ADFS). Microsoft’s incident response teams have observed active exploitation in the wild. The flaw stems from insufficient access control granularity, requiring only local access and low privileges to initiate an attack. Dustin Childs, head of threat awareness at TrendAI’s Zero Day Initiative, noted that ADFS is a critical identity infrastructure component that attackers frequently pivot through once inside a network, often pairing it with remote code execution exploits in ransomware campaigns. The fix includes hardening the Access Control List (ACL) on the AD FS Distributed Key Manager container.
CVE-2026-56164 is an EoP vulnerability in Microsoft SharePoint Server that is also under active attack. Reported by Google’s incident response team and an anonymous researcher, the flaw is remotely exploitable with low complexity. While enabling the Antimalware Scan Interface (AMSI) on SharePoint servers can serve as a mitigation, Microsoft strongly recommends applying the security update. The same update addresses additional SharePoint remote code execution vulnerabilities (CVE-2026-50522 and CVE-2026-58644) as well as a critical security feature bypass flaw (CVE-2026-55040). The latter was discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer and is part of a two-vulnerability chain that can lead to unauthenticated remote code execution. The second exploit remains under embargo, with a patch expected in August 2026.
CVE-2026-50661 is a Windows BitLocker security feature bypass vulnerability that has been publicly disclosed but not yet exploited. CrowdStrike noted that this CVE may correspond to the GreatXML BitLocker bypass exploit released by the researcher known as Nightmare Eclipse. The vulnerability allows an attacker to bypass BitLocker encryption, potentially exposing sensitive data on compromised devices.
In addition, the US Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to apply extra hardening measures on SharePoint servers, given that attackers are actively exploiting two recently patched vulnerabilities (CVE-2026-32201 and CVE-2026-45659). The latter was originally rated as less likely to be exploited by Microsoft's Exploitability Index but was subsequently added to CISA's Known Exploited Vulnerabilities catalog on July 1.
AI-Assisted Discovery and Its Impact on Patching
The unprecedented volume of vulnerabilities fixed this month is a direct result of Microsoft's accelerated use of AI to discover security flaws internally. The company has confirmed that AI models are being deployed to analyze codebases, identify potential weaknesses, and prioritize remediation. This approach mirrors similar efforts by other security researchers and attackers, who are also leveraging AI to find and exploit vulnerabilities faster than ever before.
Microsoft has updated its patching guidance to recommend deploying quality updates within three days of release, with deadlines set to zero or one day and grace periods of no more than two days. This reflects the reality that attackers using AI can quickly develop exploits for known vulnerabilities, leaving organizations with little time to react.
Satnam Narang, senior staff research engineer at Tenable, emphasized that the Exploitability Index, which is designed to predict the likelihood of exploitation, must evolve alongside AI-driven discovery. He cited Anthropic’s Red Team findings that their Mythos Preview model successfully produced proof-of-concept exploits for 13 of 14 vulnerabilities rated as less likely or unlikely to be exploited. This demonstrates that traditional human-centric assessments are no longer sufficient in an era where machine-speed analysis is commonplace.
The cybersecurity agencies of the Five Eyes nations (United States, United Kingdom, Canada, Australia, New Zealand) have issued joint recommendations urging organizations to integrate AI tools into their security operations. Key advice includes reducing attack surface by limiting access, accelerating patching workflows, prioritizing updates by risk, decommissioning legacy systems where possible, strengthening identity and access controls, and proactively preparing for incidents.
Following the July Patch Tuesday release, Microsoft updated the advisory for CVE-2026-58644, a SharePoint remote code execution vulnerability fixed in June but disclosed only this week, to indicate that it is now being exploited by attackers. This late revelation underscores the dynamic nature of vulnerability management and the importance of continuous monitoring.
Historically, Patch Tuesday has evolved from a predictable monthly cycle into a high-stakes event where organizations must rapidly assess and deploy fixes. The July 2026 update breaks all previous records, exceeding the previous high of 365 vulnerabilities patched in a single month. This increase is not solely due to AI discovery; it also reflects the growing complexity of software and the expanding attack surface of modern systems. However, AI has undoubtedly accelerated the rate at which vulnerabilities are identified, both by defenders and attackers.
Security researchers have long warned that the gap between disclosure and exploitation is shrinking. The integration of AI into vulnerability research tools enables automated scanning of vast codebases, identification of subtle patterns, and generation of exploit code with minimal human intervention. This trend is likely to continue, making it imperative for organizations to adopt agile patching strategies and leverage AI-driven defenses to stay ahead.
The July 2026 Patch Tuesday serves as a wake-up call. With over 570 vulnerabilities fixed, two actively exploited in the wild, and one publicly disclosed but unpatched for a period, the need for speed and precision in vulnerability management has never been greater. Organizations must embrace AI not only to discover vulnerabilities but also to orchestrate rapid response, prioritize critical updates, and maintain robust security postures in an increasingly aggressive threat landscape.
Source:Help Net Security News
