Microsoft's Massive Patch Tuesday: 622 Flaws Fixed, Including Critical SharePoint Vulnerabilities (2026)

Microsoft's July Patch Tuesday update addresses a staggering 622 vulnerabilities, with a significant portion impacting Windows. Among these, two are actively being exploited, and one has already been publicly disclosed, according to Rapid7's analysis. One of the most critical issues is CVE-2026-55040, a critical authentication bypass flaw in Microsoft SharePoint. This vulnerability, discovered by Rapid7's Senior Principal Security Researcher, Stephen Fewer, poses a serious risk as it can lead to unauthenticated remote code execution on vulnerable SharePoint servers. The issue is part of a two-step attack chain, with the second vulnerability remaining undisclosed, pending a future patch from Microsoft.

The SharePoint vulnerabilities extend further, with Microsoft tracking the exploitation of CVE-2026-56164, another SharePoint flaw enabling privilege escalation over a network without prior access. Despite a CVSS v3 base score of 5.3, Rapid7 suggests the practical risk may be higher, emphasizing the importance of prompt patching. Active Directory Federation Services (ADFS) is also in the spotlight with CVE-2026-56155, an elevation of privilege flaw under active exploitation, alongside eight additional vulnerabilities affecting the same product family.

A publicly known BitLocker security feature bypass, CVE-2026-50661, is another concern. This vulnerability allows an attacker with physical access to a device to bypass Windows BitLocker protections. The update also includes an unusual entry for Age of Empires II: Definitive Edition, with CVE-2026-50663, a flaw that could enable code execution through malicious scenario files.

Microsoft's recent changes to how it presents security information have also been noted. The company has stopped listing detailed vulnerability entries in the Security Update Guide, opting for a summary table by product family and a shorter list of notable CVEs. This shift comes as vulnerability volumes continue to rise across the industry, with Microsoft no longer listing Chromium CVEs in the guide. The pressure on defenders to assess risk across a growing number of disclosures is evident, as highlighted by Adam Barnett, Lead Software Engineer at Rapid7.

The July release coincides with support cutoffs for several Microsoft products, including SharePoint Server 2016 and 2019, Project Server 2016 and 2019, Dynamics GP 2016 and 2016 R2, InfoPath 2013, and SharePoint Designer 2013. SQL Server 2016 is transitioning to Extended Security Updates, while SQL Server 2014 enters its final year under that scheme. Visual Studio 2022 Version 17.12 Long-Term Servicing Channel is also reaching its release end date, limiting supported options for users.

In summary, Microsoft's Patch Tuesday update addresses a vast array of vulnerabilities, with a focus on SharePoint and ADFS issues. The update coincides with support cutoffs for several products, highlighting the ongoing challenges in maintaining secure software ecosystems. As the industry grapples with rising vulnerability volumes, the pressure on defenders to stay vigilant and proactive in their patching processes is more critical than ever.

Microsoft's Massive Patch Tuesday: 622 Flaws Fixed, Including Critical SharePoint Vulnerabilities (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Errol Quitzon

Last Updated:

Views: 5260

Rating: 4.9 / 5 (59 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Errol Quitzon

Birthday: 1993-04-02

Address: 70604 Haley Lane, Port Weldonside, TN 99233-0942

Phone: +9665282866296

Job: Product Retail Agent

Hobby: Computer programming, Horseback riding, Hooping, Dance, Ice skating, Backpacking, Rafting

Introduction: My name is Errol Quitzon, I am a fair, cute, fancy, clean, attractive, sparkling, kind person who loves writing and wants to share my knowledge and understanding with you.