Microsoft smashes Patch Tuesday record for second successive month
Microsoft released a massive Patch Tuesday update, exceeding 600 security vulnerabilities – the largest in the program's history. This surge in vulnerabilities, driven in part by AI-assisted discovery, has led to a significant increase in exploited flaws, with two vulnerabilities already being actively exploited in the wild. The company is shifting its advisory format to streamline the process, but this also creates a challenge for defenders to quickly assess the full scope of the risks.
Microsoft released a record-breaking Patch Tuesday update, containing over 600 security vulnerabilities – more than triple the previous record and the largest in the program's history. The company’s Security Update Guide now presents a summary table of vulnerabilities by product family, alongside a ‘Notable CVEs’ section, replacing the previously itemized list. This shift is intended to simplify the process for defenders, but it also means that analysts and third-party trackers must now piece together the full picture from underlying advisory feeds.
Microsoft revealed that two of these vulnerabilities are currently being exploited in the wild. CVE-2026-56164, an elevation-of-privilege flaw in on-premises SharePoint Server, allows an unauthenticated attacker to escalate privileges over the network, rated as ‘Important’ with a CVSS score of 5.3. CVE-2026-56155, an elevation-of-privilege flaw in Active Directory Federation Services, also allows an authenticated attacker to escalate privileges locally, and was discovered by Microsoft’s DART incident-response unit. Both were not on CISA’s Known Exploited Vulnerabilities (KEV) catalog as of Wednesday morning.
A third vulnerability, CVE-2026-55040, a security feature bypass in SharePoint, was discovered by Rapid7 researcher Stephen Fewer and disclosed in coordination with Microsoft. Rapid7 noted that this bypass is part of an exploit chain, with the second vulnerability remaining embargoed and expected to be patched in August. Trend Micro’s Zero Day Initiative rated this bypass 9.1.
Microsoft also patched CVE-2026-50661, a publicly disclosed BitLocker security feature bypass, which allows a physical attacker to circumvent drive encryption. Rapid7 linked this advisory to a vulnerability announced under the name ‘GreatXML’ by Nightmare Eclipse, a researcher who had threatened to release a new exploit coinciding with this Patch Tuesday, though he partially walked back that threat.
Instead, a new proof-of-concept, nicknamed ‘LegacyHive,’ emerged from Nightmare Eclipse’s GitHub repository, allowing a non-privileged user to mount another user’s registry hive. Microsoft also addressed CVE-2026-50656, a Defender elevation-of-privilege vulnerability, with an out-of-band update on July 8, following Nightmare Eclipse’s release of proof-of-concept code. Nightmare Eclipse has since claimed the patch introduces a disk-exhaustion vector.
This surge in vulnerabilities is partly attributed to AI-assisted discovery, with Microsoft using its internal AI system, MDASH, to hunt for flaws. The National Cyber Security Centre (NCSC) in Britain issued a similar warning in April, anticipating a wave of urgent updates, and while that wave has arrived, a corresponding surge in cyberattacks hasn't yet been observed.
