Microsoft's July 2026 Patch Tuesday addresses a record 570 security vulnerabilities — nearly triple last month's record count — including 60 critical flaws and three zero-days already exploited in the wild. Microsoft attributes the surge to AI-assisted vulnerability discovery. Notable CVEs include elevation-of-privilege zero-days in Active Directory Federation Services and SharePoint, a BitLocker security bypass, and a remote code execution flaw in Microsoft Copilot (CVSS 9.6). Security researchers warn that Microsoft's exploitability index is outdated in the AI era, as Anthropic's red team model generated working exploits for 13 of 14 vulnerabilities rated 'less likely' to be exploited. Adobe, Cisco, Mozilla, Oracle, and Google are also accelerating patch cadences, citing AI-driven discovery. Users are advised to wait a few days before applying patches given the volume and risk of stability issues.

4m read timeFrom krebsonsecurity.com
Post cover image
17 Impressions