Microsoft Patches a Record 570 Security Flaws

Microsoft has rolled out security updates addressing more than 570 vulnerabilities across Windows and several other products, marking one of the company’s largest Patch Tuesday releases to date. The update nearly triples the number of flaws fixed in the previous month’s record-setting release, with Microsoft attributing the surge in discovered vulnerabilities to the growing use of artificial intelligence in security research.

Among the vulnerabilities patched are nearly 60 rated as critical, meaning attackers could potentially exploit them to take remote control of affected Windows systems with little or no user interaction. The company also fixed three zero-day vulnerabilities, two of which are already being actively exploited by threat actors.

Two of the zero-day flaws enable attackers to gain elevated privileges on Windows systems. They include CVE-2026-56155, affecting Active Directory Federation Services, and CVE-2026-56164, which impacts Microsoft SharePoint. These are part of approximately 250 elevation-of-privilege vulnerabilities resolved in the latest update.

Another notable vulnerability, CVE-2026-50661, affects Windows BitLocker. The security feature bypass could allow someone with physical access to a device to retrieve encrypted information. While Microsoft confirmed the flaw has been publicly disclosed, it said there is currently no evidence that it has been exploited in real-world attacks.

In a July 9 blog post, Microsoft Executive Vice President Pavan Davuluri said customers should expect larger security updates going forward as AI continues to accelerate the discovery of software vulnerabilities.

According to Davuluri, advances in artificial intelligence are enabling researchers to identify weaknesses more quickly, across larger codebases, and with greater efficiency, significantly increasing the number of vulnerabilities uncovered before each release.

Security researchers have also highlighted several high-risk flaws in the latest update. Jack Bicer, Director of Vulnerability Research at Action1, pointed to CVE-2026-48561, a remote code execution vulnerability in Microsoft Copilot that carries a CVSS severity score of 9.6. The flaw could allow an unauthenticated attacker to execute code remotely by hosting a malicious website that causes Microsoft Edge on Android devices to automatically send specially crafted prompts to Copilot when visited by users.

While AI is helping vendors discover and patch vulnerabilities faster, cybersecurity experts warn that the same technology is making it easier for attackers to develop working exploits for newly disclosed flaws.

Microsoft has traditionally relied on its Exploitability Index to estimate the likelihood that attackers will successfully weaponize a vulnerability. However, Satnam Narang, Senior Staff Research Engineer at Tenable, believes the rating system no longer reflects the speed at which AI-powered tools can generate exploits.

He cited the SharePoint zero-day vulnerability, which Microsoft initially classified as “less likely” to be exploited despite its inclusion in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog on July 1.

Narang also referenced research by Anthropic’s Red Team, whose Mythos Preview AI model successfully generated proof-of-concept exploits for 13 of 14 vulnerabilities that Microsoft had previously assessed as unlikely to be exploited. According to him, this demonstrates that vulnerability risk assessments must evolve to account for AI-assisted attackers rather than relying solely on human capabilities.

Industry observers say Microsoft is not alone in increasing the frequency and size of its security updates. Chris Goettl of Ivanti noted that Adobe has announced a shift to publishing security bulletins twice each month, citing AI-driven vulnerability discovery as one of the reasons for the change. He added that Cisco, Mozilla, Oracle, and Google have also accelerated their patch release schedules, with Google’s June 2026 update addressing more than 900 security issues.

Given the unusually large number of patches included in Microsoft’s latest release, experts recommend that users back up their systems and important data before installing the updates. Although applying security patches is essential, large update packages can occasionally introduce compatibility or system stability issues. As a precaution, some users may choose to wait a few days to ensure no widespread problems emerge before deploying the updates.

Add Your Comment