Protect.Computer
NEWS

Microsoft Patches 570 Security Flaws, Two Actively Exploited

· 1 min read · Device safety Got hacked
Microsoft Patches 570 Security Flaws, Two Actively Exploited

Microsoft released its July 2026 Patch Tuesday security updates on July 14, fixing a record-breaking 570 security vulnerabilities — far more than any previous month. Of those, 59 are rated Critical, and two zero-days are already being used in real attacks right now.

The two actively exploited vulnerabilities are CVE-2026-56155, a flaw in Windows Active Directory Federation Services that allows attackers to gain administrator-level privileges, and CVE-2026-56164, a similar privilege escalation flaw in Microsoft SharePoint Server. A third zero-day, CVE-2026-50661, affects Windows BitLocker and has been publicly disclosed but is not yet confirmed exploited — it could allow an attacker to access data on an encrypted drive.

How to check if you’re affected

Affected versions include any Windows system that has not yet installed the July 2026 cumulative updates. Here is how to update:

  1. Open SettingsWindows Update and click Check for updates.
  2. Install all pending updates and restart when prompted.
  3. After restarting, return to Windows Update and confirm no further updates are waiting.

If your computer shows that it is fully up to date with July 14, 2026 updates installed, you are protected against the two actively exploited flaws.

Sources

Related reading