- 228/2026
- Critical
Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch addressed 570 flaws, including 3 publicly disclosed zero-day vulnerabilities.
Microsoft has addressed multiple vulnerabilities that could allow attackers to gain elevated privileges, perform spoofing and denial-of-service attacks, bypass security restrictions, obtain sensitive information, or execute arbitrary code and gain access to the affected systems.
The two actively exploited zero-days in the July Patch are:
- Active Directory Federation Services Elevation of Privilege Vulnerability “CVE- 2026-56155” allows the authorized attacker to elevate privileges locally.
- Microsoft SharePoint Server Elevation of Privilege Vulnerability “CVE-2026- 56164” allows the unauthorized attacker to elevate privileges over the network.
The publicly disclosed zero-day flaw in the July Patch is:
- Windows BitLocker Security Feature Bypass Vulnerability “CVE-2026-50661” allows the attacker to gain access to encrypted data.
Sample of the addressed vulnerabilities:
1. Microsoft VMSwitch User after free Elevation of Privilege Vulnerability (CVE- 2026-57092):
- CVSS: 9.9
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Consequences: Gain Privileges
2. Microsoft Message Queuing Service (MSMQ) Remote Code Execution Vulnerability (CVE-2026-50447):
- CVSS: 9.8
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Consequences: Remote Code Execution
Vulnerabilities
Mitigations
The enterprise should deploy this patch as soon as the testing phase is completed.
