Skip to Content

July Patch Tuesday only feels endless

AI deluge brings 575 CVEs, 479 advisories, reset to blog-post format

Author placeholder

Microsoft on Tuesday released 575 patches affecting 29 product families. Sixty-three of the addressed issues are considered by Microsoft to be of Critical severity; 44 CVEs are expected to be exploited within the next 30 days. (Two already are, though neither CVE-2026-56155 nor CVE-2026-56164 is considered to be of Critical severity.) One hundred and three have a CVSS Base score of 8.0 or higher. Just one was publicly disclosed as of release day and two are acknowledged to be under active exploit in the wild.

The advisory tally this month is likewise elevated. In addition to the usual Servicing Stack update, there are 479 advisories, all touching Edge. Virtually all of these were patched in advance of Patch Tuesday, but as ever we encourage readers to be sure that they’ve applied all available browser patches when those are made available. There were no Adobe-related patches made available by Microsoft this month, and aside from the 435 Chromium-issued Edge advisory items, all CVEs (and the Servicing Stack) originated with Microsoft.

Various of this month’s issues are amenable to direct detection by Sophos protections, and we include information on those in the usual table below.

Stepping back from this July’s output, we’re more or less four months into the AI-finder era of bug hunting, and patterns are starting to emerge from the noise. First, either finders are suddenly building coalitions that would shame NATO or simultaneous discovery is rampant. In years past it was unusual to see a single bug credited to more than half a dozen finders; this month alone saw at least four CVEs with ten or more credits listed. One, an otherwise remarkable PowerShell RCE bug labeled CVE-2026-40400, has fifteen. In a related vein, bug totals for certain finders (whether individuals or committees) are astonishing. Having a dozen or more CVEs credited to the same entity in the same month is now entirely normal; this month’s top CVE submitter, 0ccbbf129444eb66344ccafb92b00df4, has 47 July credits (44 in Office, over half the month’s Office total) to their handle.

Second, though the volume is overwhelming, so far these bugs are turning up in the lab, not the wild. (No complaints.) None of 0ccbbf129444eb66344ccafb92b00df4’s bugs have been seen yet in the wild, and only seven of them are Critical-severity. The heat map in Figure 1 shows that in fact, the percentage of bugs that have either been publicly disclosed or found in the wild has dropped in recent months. Even the percentage of CVEs Microsoft deems more likely to be exploited within the next 30 days is relatively low.

 

pt2607-fig01.png

Figure 1: A heat map analyzing Patch Tuesday numbers over the past year indicates that though the overall CVE counts are high, the bugs that are coming to light in recent months are most likely not immediately threatening the health of the internet.

Does this add credence to the idea that AI bug hunting represents a grand code cleanup that one day will subside, having eliminated all bugs worth finding? We won’t speculate, but it will be interesting to see what happens next.

Finally, the sheer volume of CVEs each month means that many security folk are adapting their Patch Tuesday routines. This blog is no exception. For those readers accustomed to using our appendices for guidance each month, we’re switching to a new system that should appeal greatly to those who love data but prefer it in spreadsheet form. Read on.

By the numbers

  • Total CVEs: 575
  • Publicly disclosed: 1
  • Exploit detected: 2
  • Severity
    • Critical: 63
    • Important: 510
    • Moderate: 2
  • Impact:
    • Denial of Service: 35
    • Elevation of Privilege: 254
    • Information Disclosure: 102
    • Remote Code Execution: 143
    • Spoofing: 16
    • Security Feature Bypass: 17
    • Tampering: 8
  • CVSS base score 9.0 or greater: 21
  • CVSS base score 8.0 or greater: 103

 

pt2607-fig02.png

Figure 2: It may be hard to discern under the circumstances, but the counts for Security Feature Bypass and Spoofing vulnerabilities actually dropped in July – possibly a sign that certain kinds of bugs are easier to find via AI than others.

Products

  • .NET: 16
  • 365: 79
  • Age of Empires II: 1
  • ASP.NET: 2
  • Azure: 8
  • Bing Search for iOS: 1
  • Copilot: 2
  • Defender / Mac: 3
  • Dynamics NAV: 1
  • Entra: 1
  • Excel: 31
  • Exchange: 5
  • Fabric Data Warehouse: 1
  • GitHub / JetBrains: 1
  • Minecraft Bedrock Dedicated Server: 1
  • MMPE: 2
  • Office: 78
  • PC Manager: 2
  • PowerBI: 1
  • PowerPoint: 3
  • SharePoint: 38
  • SQL: 7
  • Surface: 1
  • VS: 22
  • Windows: 407
  • Windows Admin Center: 6
  • Windows Remote Help: 1
  • Windows Subsystem for Linux: 2
  • Word: 12

As is our custom for this list, CVEs that apply to more than one product family are counted once for each family they affect.

 

pt2607-fig03.png

Figure 3: In the interests of having a chart that’s usable, we’re doing things a bit differently for the time being. Windows’ 407 CVEs – 31 Critical, 375 Important, one Moderate – are relegated to this caption; we trust the reader didn’t seriously think Windows was pain-free in a month like this. In addition, ten product families received just one patch apiece this month. Please consult the Excel spreadsheet linked below for information on all ten, or read on for a glimpse of the two most depressing of that group.

pt2607-fig04.png

Figure 4: Seven months in, Elevation of Privilege issues are twice as prevalent as Remote Code Execution flaws. Meanwhile, Security Feature Bypass picks up its first Critical-severity patch this month, for the SharePoint issue CVE-2026-55040.

Notable July updates

In addition to the issues discussed above, a few items merit general attention.

CVE-2026-50518 – Windows DHCP Server Remote Code Execution Vulnerability
CVE-2026-50522 – Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2026-55008 – Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-55944 – Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
CVE-2026-56188 -- Windows Server Network Driver Remote Code Execution Vulnerability
CVE-2026-58644 – Microsoft SharePoint Remote Code Execution Vulnerability

Many of the CVEs that look most urgent on paper – CVSS Base above 9.0, Critical severity – are either relatively less likely to be exploited in the next 30 days or have already been mitigated. The six CVEs listed above are neither, and they have been judged by Microsoft to be more likely to be exploited in the next 30 days. If you’re unsure of where to begin with your July patching, here’s your sign.

CVE-2026-50301, CVE-2026-50314, CVE-2026-50467, CVE-2026-55018, CVE-2026-55022, CVE-2026-55033, CVE-2026-55045, CVE-2026-55049, CVE-2026-55056, CVE-2026-55057, CVE-2026-55127, CVE-2026-55129, CVE-2026-55132, CVE-2026-55140, CVE-2026-56193, CVE-2026-56195 (16 Office CVEs)

Preview Pane is a vector for all 16 of these Office CVEs. All but three (CVE-2026-55057, CVE-2026-56193, CVE-2026-56195) are Critical-severity, though all 16 are considered by Microsoft to be less likely to be exploited within the next 30 days.

31 Important-severity Edge CVEs (advisory-only)

Continuing the trend of hyper-productive finders as mentioned above, we salute Microsoft’s own Kugelblitz, finder of 38 Important-severity Edge bugs this month (37 of those with solo credit). Curiously, 31 of those bugs require very specific user interaction – two sequential taps, as one might do to use autofill on a Web page. We know full well that bug-hunting at this volume is most likely automated, and other finders this month also identified a scattering of bugs with the same vector, but the mental image of some poor soul in Redmond tap-tapping a screen over and over in search of Edge bugs makes our mouse fingers ache.

CVE-2026-55010 – Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability
CVE-2026-50663 -- Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability

That’s right – patches for Age of Empires II and Minecraft. Not even your childhood shall be spared the patchapalooza.

Sophos protections

CVESophos Intercept X/Endpoint IPS

Sophos XGS Firewall

CVE-2026-49170Exp/2649170-AExp/2649170-A
CVE-2026-49795Exp/2649795-AExp/2649795-A
CVE-2026-49798Exp/2649798-AExp/2649798-A
CVE-2026-49800Exp/2649800-AExp/2649800-A
CVE-2026-50329Exp/2650329-AExp/2650329-A
CVE-2026-50332Exp/2650332-AExp/2650332-A
CVE-2026-50343Exp/2650343-AExp/2650343-A
CVE-2026-50351Exp/2650351-AExp/2650351-A
CVE-2026-50375Exp/2650375-AExp/2650375-A
CVE-2026-50387Exp/2650387-AExp/2650387-A
CVE-2026-50390Exp/2650390-AExp/2650390-A
CVE-2026-50420Exp/2650420-AExp/2650420-A
CVE-2026-50423Exp/2650423-AExp/2650423-A
CVE-2026-50433Exp/2650433-AExp/2650433-A
CVE-2026-50436Exp/2650436-AExp/2650436-A
CVE-2026-50454Exp/2650454-AExp/2650454-A
CVE-2026-50475Exp/2650475-AExp/2650475-A
CVE-2026-50476Exp/2650476-AExp/2650476-A
CVE-2026-50518sid:2312733sid:2312734
CVE-2026-50522sid:2312729sid:2312729
CVE-2026-50667Exp/2650667-AExp/2650667-A
CVE-2026-50688Exp/2650688-AExp/2650688-A
CVE-2026-54114Exp/2654114-AExp/2654114-A
CVE-2026-54986Exp/2654986-AExp/2654986-A
CVE-2026-54992sid:2312741sid:2312741
CVE-2026-56164sid:2312731, sid:2312732sid:2312731, sid:2312732
CVE-2026-57091Exp/2657091-AExp/2657091-A
CVE-2026-58536Exp/2658536-AExp/2658536-A

 

As you can every month, if you don’t want to wait for your system to pull down Microsoft’s updates itself, you can download them manually from the Windows Update Catalog website. Run the winver.exe tool to determine which build of Windows you’re running, then download the Cumulative Update package for your specific system’s architecture and build number.

Appendix: PatchTuesday_July2026

Because absolutely no one wants to look at 1000-plus CVEs of bloggery, we present all the data you crave in a far more civilized format – an Excel workbook. You’ll find all your favorite appendix data there, in a format that allows readers to pivot and sort to their hearts’ content. The workbook contains multiple sheets:

PT_Summary – key monthly metrics in a single-screen format
PT_PriSevImp – best for sorting by impact, Microsoft-assigned severity / CVSS, impact, and prospects for exploitability
PT_ByProduct – a more granular breakdown focusing on product families; helpful when dealing with CVEs with multi-family applicability
PT_Windows – a chart showing which versions of Windows are affected by each patched CVE; with the switch to Excel, we are pleased to expand the former Appendix E to include currently supported client versions
PT_Protections – a list of all Sophos-issues protections applicable to this month’s patches; replicates the chart in the blog post for easy reference
PT_Advisories – third-party advisories, information on the periodically offered servicing stack, and all Edge-related CVEs are here
PT_CWE – a breakdown of which vulnerabilities were most often discovered in the products patched this month