Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
This patch Tuesday includes a staggering 622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft's Edge browser. 62 of the vulnerabilities are rated critical. One was disclosed before today, and two have already been exploited. Given the large number of vulnerabilities, it is difficult to point out noteworthy issues. Already exploited vulnerabilities: CVE-2026-56155 : Active Directory Federation Services Elevation of Privilege Vulnerability. This is an important (not critical) vulnerablity. CVE-2026-56164 : Microsoft SharePoint Server Elevation of Privilege Vulnerability. Microsoft considers this vulnerability's severity only moderate. Disclosed but not yet exploited: CVE-2026-50661 : Windows BitLocker Security Feature Bypass Vulnerability. It is not clear right now if this is one of the Nightmare Eclipse vulnerabilities. Anonymous is credited with discovering the vulnerability. Random Interesting Vulnerabilities: CVE-2026-54128 : Windows DHCP Client Remote Code Execution Vulnerability. A critical vulnerability, but it will require the victim to connect to a network exposed to a malicious DHCP server. Certainly interesting for public wifi network attacks. There are also a few critical DHCP server RCE vulnerabilities being addressed in this update. CVE-2026-54982 , CVE-2026-54995 : Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability. Two critical vulnerabilities. Just like DHCP, the exploit will typically require network-adjacent attackers. I have seen several similar vulnerabilities in MSFT updates in the past, but not seen exploits. A quick word on how to deal with this flood of new vulnerabilities: You still own the same number of Microsoft products. Many products (Office..) are affected by a large number of vulnerabilities. Patching the product should not take a lot more time just because the patch addresses more vulnerabilities. Description CVE Disclosed Exploited Exploitability (old versions) current version Severity CVSS Base (AVG) CVSS Temporal (AVG) .NET Denial of Service Vulnerability %%cve:2026-47302%% No No - - Important 7.5 6.5 %%cve:2026-50525%% No No - - Important 7.5 6.5 %%cve:2026-50651%% No No - - Important 7.5 6.5 %%cve:2026-57108%% No No - - Important 7.5 6.5 .NET Framework Denial of Service Vulnerability %%cve:2026-50524%% No No - - Important 7.5 6.5 %%cve:2026-50527%% No No - - Important 7.5 6.5 %%cve:2026-50648%% No No - - Important 7.5 6.5 .NET Framework Elevation of Privilege Vulnerability %%cve:2026-50650%% No No - - Important 7.8 6.8 .NET Framework Remote Code Execution Vulnerability %%cve:2026-50646%% No No - - Important 7.8 6.8 .NET Remote Code Execution Vulnerability %%cve:2026-50649%% No No - - Important 7.8 6.8 .NET Security Feature Bypass Vulnerability %%cve:2026-47304%% No No - - Important 8.1 7.1 %%cve:2026-50528%% No No - - Important 8.2 7.1 .NET Spoofing Vulnerability %%cve:2026-50659%% No No - - Important 6.5 5.7 .NET Tamperin
Sign in to read the full article
Create a free account to access all news, downloads, and community features
Originally published by SANS ISC
Source: https://isc.sans.edu/diary/rss/33154
This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.