Microsoft July 2026 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch addressed 570 flaws, including 3 publicly disclosed zero-day vulnerabilities.

Microsoft has addressed multiple vulnerabilities that could allow attackers to gain elevated privileges, perform spoofing and denial-of-service attacks, bypass security restrictions, obtain sensitive information, or execute arbitrary code and gain access to the affected systems.

The two actively exploited zero-days in the July Patch are:

  • Active Directory Federation Services Elevation of Privilege Vulnerability “CVE- 2026-56155” allows the authorized attacker to elevate privileges locally.
  • Microsoft SharePoint Server Elevation of Privilege Vulnerability “CVE-2026- 56164” allows the unauthorized attacker to elevate privileges over the network.

The publicly disclosed zero-day flaw in the July Patch is:

  • Windows BitLocker Security Feature Bypass Vulnerability “CVE-2026-50661” allows the attacker to gain access to encrypted data.

Sample of the addressed vulnerabilities:

1. Microsoft VMSwitch User after free Elevation of Privilege Vulnerability (CVE- 2026-57092):

  • CVSS: 9.9
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges

2. Microsoft Message Queuing Service (MSMQ) Remote Code Execution Vulnerability (CVE-2026-50447):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Remote Code Execution
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft MSRC

References