news.mlab.sh
Back to the feed
vulnerability

Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days

High
Summary

Microsoft released a record-breaking 622 security patches this Patch Tuesday, including two actively exploited zero-day vulnerabilities in Active Directory and SharePoint Server. These flaws allow attackers to escalate privileges and exploit vulnerabilities over a network without authentication. The updates cover a wide range of products, including Windows, Office, Azure, and Defender, highlighting Microsoft’s ongoing efforts to proactively address security weaknesses.

Microsoft announced a substantial release of security patches this Patch Tuesday, totaling 622 vulnerabilities. Notably, two zero-day vulnerabilities were being actively exploited in the wild. CVE-2026-56155, affecting Federation Services (AD FS), allows local privilege escalation to administrator, while CVE-2026-56164 in SharePoint Server enables network-based exploitation without authentication. Another significant vulnerability, CVE-2026-50661, a BitLocker bypass, can be exploited by physical attackers. Microsoft’s release notes indicate that Windows received 416 fixes, and the Office suite received 164. Other noteworthy vulnerabilities include critical flaws in Windows VMSwitch (CVSS 9.9), SharePoint (CVSS 9.8), Exchange Server (XSS), Remote Desktop Protocol (RCE), Windows DHCP Server, Windows Server Network driver, and Minecraft Bedrock Dedicated Server. Microsoft’s AI initiatives, specifically using MDASH, are accelerating vulnerability discovery. Adobe also released 88 patches this Patch Tuesday, including critical vulnerabilities in ColdFusion, Commerce, Experience Manager, and Illustrator. SAP patched critical vulnerabilities in NetWeaver and Approuter, and Palo Alto Networks addressed 13 vulnerabilities.

Read the full article at SecurityWeek