惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tor Project blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Threatpost
T
Troy Hunt's Blog
O
OpenAI News
S
Securelist
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
P
Proofpoint News Feed
S
Secure Thoughts
Martin Fowler
Martin Fowler
H
Hacker News: Front Page
博客园_首页
Security Latest
Security Latest
Cyberwarzone
Cyberwarzone
阮一峰的网络日志
阮一峰的网络日志
L
LINUX DO - 热门话题
V2EX - 技术
V2EX - 技术
W
WeLiveSecurity
雷峰网
雷峰网
博客园 - Franky
C
Cyber Attacks, Cyber Crime and Cyber Security
Jina AI
Jina AI
S
Security @ Cisco Blogs
Apple Machine Learning Research
Apple Machine Learning Research
S
Security Affairs
Scott Helme
Scott Helme
T
The Exploit Database - CXSecurity.com
博客园 - 三生石上(FineUI控件)
P
Privacy & Cybersecurity Law Blog
罗磊的独立博客
G
Google Developers Blog
L
Lohrmann on Cybersecurity
量子位
The GitHub Blog
The GitHub Blog
V
Vulnerabilities – Threatpost
大猫的无限游戏
大猫的无限游戏
T
Threat Research - Cisco Blogs
K
Kaspersky official blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Webroot Blog
Webroot Blog
F
Fortinet All Blogs
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
小众软件
小众软件
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
GbyAI
GbyAI
PCI Perspectives
PCI Perspectives
N
News | PayPal Newsroom
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Spread Privacy
Spread Privacy
有赞技术团队
有赞技术团队

Tenable Blog

Oracle July 2026 Critical Patch Update 1235 CVEs | Tenable® AI agent config attacks: How attackers turn trusted Dev harness files into payloads wp2shell: WordPress Core Pre-Auth RCE FAQ | Tenable® SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® Build agentic AI security at Tenable Swarm, Black Hat 2026 SonicWall CVE-2026-15409 and CVE-2026-15410 zero-day exploited | Tenable® Understanding Anthropic’s new AI agent Claude Tag’s access model in Slack 5 reasons to integrate AppSec data with your exposure management platform FedRAMP High, IL5, and zero trust: How federal agencies can secure cloud environments OMB M-26-14: Why federal agencies must fix asset visibility first CISO’s guide to CISA BOD 26-04 and risk-based security metrics for vulnerability management How much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it. The Developer Credential Economy: An inside look at the Miasma worm campaign Oracle Critical Security Patch Update June 2026 | Tenable® How Tenable helps federal agencies comply with CISA BOD 26-04 Get critical cyber risk context: Understanding control validation, CTEM & Tenable One CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) The June 2026 AI Executive Order: What federal agencies need to know and how Tenable can help Tenable joins Anthropic’s Project Glasswing to advance AI-era cyber defense Tenable CTO Vlad Korsunsky Q&A: Countering AI threat multipliers with AI-powered exposure management | Tenable CTO Q&A: C-suite views AI as massive threat, as cyber teams adopt exposure management to counter AI attacks Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs Download pumping: New npm deception technique for supply chain attacks Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect EXPOSURE 2026 prepares cybersecurity professionals for the AI era Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign CVE-2026-9082: Highly Critical SQL Injection Vulnerability in Drupal Core (SA-CORE-2026-004) Tenable One deepens third-party integrations with new Open Connector for unified risk visibility Implement agentic AI in cybersecurity with Tenable Hexa AI: Reduce cyber risk at machine speed Key findings from the Verizon DBIR 2026: Slower vulnerability remediation meets faster exploitation Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182) Bring out your dead: How agentic AI for cybersecurity helps you rid your cloud of forgotten, risky assets Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation Securing data centers in the agentic AI era Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103) Dirty Frag (CVE-2026-43284, CVE-2026-43500): Frequently asked questions about this Linux kernel privilege escalation vulnerability chain Why the approaching flood of vulnerabilities changes everything — and what to do about it The AI-vs-AI battle is already happening. Watch it live at EXPOSURE 2026. Anthropic’s CEO warns the “moment of danger” is real. But most are looking in the wrong place. Security for AI: A strategic framework for closing the AI exposure gap Vulnerability remediation: Match CVEs to asset owners in seconds with Tenable Hexa AI Bridging the gap: How to integrate Claude Security into the Tenable One Exposure Management Platform Copy Fail (CVE-2026-31431): Frequently asked questions about Linux kernel privilege escalation vulnerability Mastering agentic AI security through exposure management As the NVD scales back CVE enrichment, here’s what Tenable customers need to know Five steps to become Mythos ready Oracle April 2026 Critical Patch Update Addresses 241 CVEs Beating the Mythos clock: Using Tenable Hexa AI custom agents for automated patching Unlocking foundational visibility for cyber-physical systems with OT vulnerability management Claude Mythos: Prepare for your board’s cybersecurity questions about the latest AI model from Anthropic Microsoft’s April 2026 Patch Tuesday Addresses 163 CVEs (CVE-2026-32201) Crushing the Axios supply chain threat with Tenable Hexa AI: Use cases for agentic AI What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical Infrastructure CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild The developer credential economy: Why exposure data is the new front line in the supply chain war Frequently Asked Questions About the Axios npm Supply Chain Attack by North Korea-Nexus Threat Actor UNC1069 Supply chain attack on Axios npm package: Scope, impact, and remediations What’s new in Tenable Cloud Security: Custom policies, AWS ABAC, and research-driven protection Uncover prompt injection, insider threats with the Tenable One Model Refusal Detection Security for AI: A guide to managing the risks of vibe coding and AI in software development Meet Tenable Hexa AI: Agentic AI for exposure management
July 2026 Patch Tuesday: Largest Patch Tuesday 569 CVEs
Research Special Operations · 2026-07-15 · via Tenable Blog

9-minute read Jul 14 2026

A blog header image that includes a logo for Tenable Research Special Operations at the top. The image is for the Patch Tuesday for July 2026 detailing 569 total CVEs. The severity breakdown is: 56 Critical, 510 Important, 3 Moderate, and 0 Low.

  1. 56Critical
  2. 510Important
  3. 3Moderate
  4. 0Low

Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.

Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will see a higher volume of security updates included in each security release.”

A pie chart showing the severity distribution across the Patch Tuesday CVEs patched in July 2026.

This month’s update includes patches for:

  • .NET
  • .NET Core
  • .NET Framework
  • ASP.NET Core
  • Active Directory Certificate Services (AD CS)
  • Active Directory Domain Services
  • Active Directory Federation Services (AD FS)
  • Azure Active Directory
  • Azure CycleCloud
  • Azure Monitor Agent
  • Azure Spring Apps
  • Code Integrity DLL (ci.dll)
  • Composite Image File System Driver
  • Content Delivery Manager
  • Desktop Window Manager
  • Extensible Storage Engine (ESENT)
  • GitHub Copilot and Visual Studio
  • GitHub Copilot and Visual Studio Code
  • Github Copilot
  • HTTP/2
  • Microsoft 365 Copilot for iOS
  • Microsoft Bing App for IOS
  • Microsoft Copilot
  • Microsoft Defender
  • Microsoft Defender for Endpoint
  • Microsoft Dynamics NAV
  • Microsoft Edge for Android
  • Microsoft Exchange Server
  • Microsoft Fabric Data Warehouse
  • Microsoft Graphics Component
  • Microsoft Input Method Editor (IME)
  • Microsoft Install Service
  • Microsoft NAT Helper Components (ipnathlp.dll)
  • Microsoft Office
  • Microsoft Office Excel
  • Microsoft Office OneNote
  • Microsoft Office PowerPoint
  • Microsoft Office SharePoint
  • Microsoft Office Word
  • Microsoft Printer Drivers
  • Microsoft Surface
  • Microsoft Windows
  • Microsoft Windows App Store
  • Microsoft Windows Codecs Library
  • Microsoft Windows Media Foundation
  • Microsoft Windows Search Component
  • Microsoft Windows Speech
  • Microsoft XML
  • Microsoft XML Core Services
  • Minecraft Bedrock Dedicated Server
  • Outlook Copilot
  • Power BI
  • Quality Windows Audio/Video Experience (QWAVE) service
  • RPC Runtime
  • Reliable Multicast Transport Driver (RMCAST)
  • Remote Desktop Client
  • Role: DNS Server
  • SQL Server
  • SQL Server ODBC driver
  • Universal Plug and Play (upnp.dll)
  • Virtual Hard Disk (VHD) Miniport Driver
  • Visual Studio
  • Visual Studio Code
  • Window PC Manager
  • Windows Active Directory
  • Windows Admin Center
  • Windows Ancillary Function Driver for WinSock
  • Windows App Installer
  • Windows AppX Deployment Service
  • Windows Application Model
  • Windows Audio Compression Manager (ACM)
  • Windows Audio Service
  • Windows Backup Engine
  • Windows BitLocker
  • Windows Bluetooth Port Driver
  • Windows Bluetooth Service
  • Windows Boot Loader
  • Windows Brokering File System
  • Windows Client-Side Caching (CSC) Service
  • Windows Clip Service
  • Windows Clipboard Server
  • Windows Clipboard User Service
  • Windows Cloud Files Mini Filter Driver
  • Windows Common Log File System Driver
  • Windows Connected User Experiences and Telemetry
  • Windows Container Isolation FS Filter Driver (unionfs.sys)
  • Windows CryptoAPI
  • Windows Cryptographic Services
  • Windows DHCP Client
  • Windows DHCP Server
  • Windows DNS
  • Windows DWM
  • Windows DWM Core Library
  • Windows Data.dll
  • Windows Devices Human Interface
  • Windows DirectX
  • Windows Domain Controller
  • Windows Event Logging Service
  • Windows FTP Service
  • Windows File Explorer
  • Windows File History Service
  • Windows Filtering Platform (WFP)
  • Windows GDI
  • Windows GDI+
  • Windows Graphics Kernel
  • Windows Group Policy
  • Windows HTTP.sys
  • Windows Hyper-V
  • Windows Image Acquisition
  • Windows Installer
  • Windows Internal System User Profile
  • Windows Internal Task Bar
  • Windows Internet Key Exchange (IKE) Protocol
  • Windows Kernel
  • Windows Kernel Mode Driver
  • Windows Kernel-Mode Drivers
  • Windows Key Guard
  • Windows LUAFV
  • Windows Local Security Authority Subsystem Service (LSASS)
  • Windows MIDI Service Module
  • Windows Management Services
  • Windows Media
  • Windows Message Queuing
  • Windows Message Queuing Queue Manager
  • Windows NTFS
  • Windows Narrator Braille
  • Windows Netlogon
  • Windows Network Address Translation (NAT)
  • Windows Network File System
  • Windows Network Policy Server SNMP
  • Windows Notification
  • Windows OLE
  • Windows Operating Systems
  • Windows Overlay Filter
  • Windows PowerShell
  • Windows Presentation Foundation (WPF)
  • Windows Print Spooler Components
  • Windows Projected File System
  • Windows Push Notifications
  • Windows Quality of Service (QoS) Packet Scheduler
  • Windows RDP
  • Windows RPC API
  • Windows Redirected Drive Buffering
  • Windows Remote Access Connection Manager
  • Windows Remote Access Service Infrastructure
  • Windows Remote Desktop Protocol
  • Windows Remote Desktop Services
  • Windows Remote Help Defense
  • Windows Resilient File System (ReFS)
  • Windows Routing and Remote Access Service (RRAS)
  • Windows Runtime
  • Windows SMB
  • Windows SMB Server
  • Windows SMB Server Network Transport Driver (srvnet.sys)
  • Windows Schannel
  • Windows Secure Boot
  • Windows Secure Kernel Mode
  • Windows Secure Socket Tunneling Protocol (SSTP)
  • Windows Sensor Data Service
  • Windows Server
  • Windows Server Backup
  • Windows Server Network driver
  • Windows Server Update Service
  • Windows Spaceport.sys
  • Windows StateRepository API
  • Windows Storage
  • Windows Storage Spaces Direct
  • Windows Subsystem for Linux
  • Windows System
  • Windows TCP/IP
  • Windows Telephony Service
  • Windows Terminal
  • Windows Trusted Runtime Interface Driver
  • Windows USB Audio Class driver (usbaudio.sys)
  • Windows USB Driver
  • Windows USB Hub Driver
  • Windows USB Print Driver
  • Windows USB Video Driver
  • Windows Unified Consent System
  • Windows Universal Disk Format File System Driver (UDFS)
  • Windows User Interface Core
  • Windows VMSwitch
  • Windows Virtual Filtering Platform (VFP)
  • Windows WalletService
  • Windows Web Proxy Auto-Discovery Protocol (WPAD)
  • Windows WebView
  • Windows Win32K
  • Windows Win32K - GRFX
  • Windows Wireless Networking
  • Windows Wireless Wide Area Network Service

A bar chart showing the count by impact of CVEs patched in the July 2026 Patch Tuesday release

Elevation of privilege (EoP) vulnerabilities accounted for 43.8% of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 25.1%.

CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege Vulnerability

CVE-2026-56155 is an EoP vulnerability affecting Active Directory Federation Services. It received a CVSSv3 score of 7.8 and is rated important. Microsoft notes that this flaw was exploited in the wild as a zero-day and is credited to researchers with the Microsoft Detection and Response Team (DART). Successful exploitation would allow an attacker to gain administrator privileges.

CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability

CVE-2026-56164

is an EoP vulnerability in Microsoft SharePoint Server. It received a CVSSv3 score of 5.3 and is rated moderate. According to Microsoft, it was exploited in the wild as a zero-day. This vulnerability affects Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, as well as SharePoint Server 2016 and SharePoint Enterprise Server 2016.

Microsoft notes that its

Antimalware Scan Interface (AMSI) integration

can provide mitigation for this vulnerability by scanning for and detecting malicious POST requests.

CVE-2026-50661 | Windows BitLocker Security Feature Bypass Vulnerability

CVE-2026-50661 is a security feature bypass vulnerability affecting Windows BitLocker. It received a CVSSv3 score of 6.1 and is rated as important. It was publicly disclosed prior to a patch being available and assessed as “Exploitation Less Likely” according to Microsoft's Exploitability Index. While an exploit is public, the advisory notes that exploitation requires physical access to the target device.

Microsoft did not provide any attribution other than to “Anonymous” though based on the advisory description, it’s possible this patch addresses GreatXML, a zero-day BitLocker bypass flaw disclosed by the researcher known as Chaotic Eclipse (Nightmare Eclipse). GreatXML was disclosed on June 10th, a day after the June Patch Tuesday release.

CVE-2026-55944 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability

CVE-2026-55944 is a RCE vulnerability in Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central. It received a CVSSv3 score of 9.8, is rated critical and assessed as “Exploitation More Likely.” Successful exploitation can be achieved by sending a crafted login request to an affected Dynamics NAV or Business Central server in order to trigger a deserialization of untrusted data vulnerability. Microsoft’s advisory cautions that no user-interaction is required, nor is authentication a requirement in order to successfully exploit this vulnerability.

Multiple CVEs | Windows DHCP Server and Client Remote Code Execution, Elevation of Privilege and Denial of Service Vulnerabilities

This month’s updates included patches to address multiple CVEs affecting DHCP Server and Windows DHCP Client. Of the nine CVEs, five were rated as critical and three were assessed as “Exploitation More Likely.” A breakdown of the CVEs can be found in the table below:

CVEDescriptionCVSSv3SeverityExploitability Index
CVE-2026-50518Windows DHCP Server Remote Code Execution Vulnerability9.8CriticalExploitation More Likely
CVE-2026-50370DHCP Server Service Remote Code Execution Vulnerability8.8CriticalExploitation More Likely
CVE-2026-54128Windows DHCP Client Remote Code Execution Vulnerability8.4CriticalExploitation More Likely
CVE-2026-48564DHCP Server Service Remote Code Execution Vulnerability8.8CriticalExploitation Less Likely
CVE-2026-49181Windows DHCP Client Elevation of Privilege Vulnerability7.5ImportantExploitation Less Likely
CVE-2026-56159DHCP Server Service Remote Code Execution Vulnerability9.8CriticalExploitation Unlikely
CVE-2026-50683Windows DHCP Client Elevation of Privilege Vulnerability8.0ImportantExploitation Unlikely
CVE-2026-50685Windows DHCP Server Remote Code Execution Vulnerability7.5ImportantExploitation Unlikely
CVE-2026-58627Windows DHCP Server Denial of Service Vulnerability7.5ImportantExploitation Unlikely

Multiple CVEs | Windows Kernel Elevation of Privilege Vulnerability

Updates this month include 20 CVEs addressing EoP vulnerabilities in the Windows Kernel. CVSSv3 scores range from 4.7 to 9.3 and six of the 20 were assessed as “Exploitation More Likely.” Additionally, Windows Kernel saw several additional security fixes this month with six CVEs for Information Disclosure flaws and two security feature bypasses. A breakdown of the EoP CVEs can be found in the tables below:

Windows Kernel Elevation of Privilege Vulnerabilities

Tenable Solutions

A list of all the plugins released for Microsoft’s July 2026 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.

For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable.

Get more information

Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.

Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

Learn more

  • Exposure Management
  • Vulnerability Management