Microsoft Patches a Document 570 Safety Flaws – Krebs on Safety

abaidmirza July 15, 2026

Microsoft Patches a Document 570 Safety Flaws – Krebs on Safety

Microsoft Corp. right this moment launched software program updates to plug at the very least 570 safety holes in its Home windows working techniques and different software program, nearly triple the variety of vulnerabilities the software program large fastened in its record-smashing Patch Tuesday launch final month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by synthetic intelligence.

A picture of a windows laptop in its updating stage, saying do not turn off the computer.

Practically 60 of the bugs quashed in July’s Patch Tuesday earned a “vital” severity ranking, that means miscreants or malware may use them to grab distant management over a Home windows machine with little or no assist from the consumer. Microsoft additionally addressed three zero-day flaws which might be already being exploited within the wild.

Two of the zero-day weaknesses enable an attacker to raise their consumer rights on a Home windows system, as do roughly 250 different elevation of privilege flaws fastened this month; they embody CVE-2026-56155 — an Energetic Listing Federation Providers bug — and CVE-2026-56164, a Microsoft Sharepoint vulnerability.

CVE-2026-50661 is a safety function bypass in Home windows BitLocker that would enable attackers to realize entry to encrypted information if they’ve bodily entry to the machine. Microsoft stated this bug has been detailed publicly, however that it’s not conscious of any energetic exploitation.

In a weblog publish on July 9, Microsoft Government Vice President Pavan Davuluri wrote that Home windows customers will discover “the next quantity of safety updates included in every safety launch” on account of AI aiding within the discovery of vulnerabilities.

“The tempo of vulnerability discovery is altering with advances in AI making it doable to seek out extra points, sooner, throughout extra code, with new mechanisms that may speed up each discovery and evaluation,” Davuluri wrote.

Jack Bicer, director of vulnerability analysis at Action1, referred to as consideration to CVE-2026-48561, a distant code execution flaw in Microsoft Copilot (with a 9.6 CVSS risk rating) that permits an unauthorized attacker to execute code over the community. Microsoft says an attacker may exploit this bug by internet hosting a malicious web site that causes Microsoft Edge for Android to routinely ship crafted prompts to Copilot when a consumer visits the positioning.

As AI advances the state of vulnerability discovery and remediation, additionally it is making it simpler for attackers to shortly devise working exploits for identified software program flaws. Microsoft has lengthy labeled safety bugs utilizing its “exploitability index,” which is Redmond’s greatest guess as to how doubtless it’s that attackers will have the ability to work out a dependable technique to exploit a given vulnerability.

However Satnam Narang, senior workers analysis engineer at Tenable, argues that Microsoft’s exploitability index must do a greater job of shifting with the machine velocity of discovery. For instance, Microsoft initially gave this month’s SharePoint zero-day an exploitability ranking of “much less doubtless,” though the flaw was added to CISA’s Identified Exploited Vulnerabilities checklist on July 1.

“Anthropic’s Crimson Crew’s personal findings for identified vulnerabilities (n-days) revealed how fragile this method has turn into, with its Mythos Preview mannequin having the ability to produce proof-of-concept exploits for 13 of 14 vulnerabilities that had been rated ‘Exploitation Much less Doubtless’ or ‘Exploitation Unlikely,’” Narang stated. “What this implies is that our method of Patch Tuesday has modified, as a result of the exploitability index is centered round people, not AI instruments, and as these instruments proceed to enhance, protection wants to enhance alongside it.”

Chris Goettl at Ivanti noticed that the report patch numbers from Microsoft come as a lot of different main software program makers are growing their patch cadence, together with Adobe which introduced right this moment it’s transferring to twice-monthly safety bulletins printed on the 2nd and 4th Tuesday of every month (Adobe additionally cited AI for accelerating their patch cycles). Cisco, Mozilla and Oracle are also delivery updates extra steadily, whereas Google’s patch batches in June 2026 totaled greater than 900 safety fixes, Goettl famous.

Backing up your Home windows system and/or information is at all times a good suggestion earlier than making use of working system updates. Given the quantity of patches addressed this month it might be clever for finish customers to attend a number of days earlier than making use of these fixes. It’s not unusual for safety patches to introduce system stability points, and people possibilities in all probability enhance fairly a bit with the large patch rely launched right this moment.

Additional studying:

Action1’s Patch Tuesday blog

Automox’s rundown


Source link

Leave a Reply

Your email address will not be published. Required fields are marked *