惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
WordPress大学
WordPress大学
C
Check Point Blog
GbyAI
GbyAI
U
Unit 42
Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
J
Java Code Geeks
I
InfoQ
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Hugging Face - Blog
Hugging Face - Blog
Vercel News
Vercel News
博客园 - 【当耐特】
美团技术团队
小众软件
小众软件
S
SegmentFault 最新的问题
Jina AI
Jina AI
阮一峰的网络日志
阮一峰的网络日志
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Cloudflare Blog
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
Visual Studio Blog

Sophos Blogs

Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation 2026 MSP Perspectives Report: How MSPs Are Scaling Cybersecurity Leadership Sophos Next-Gen SIEM Unifies Security Operations and Compliance Messageboards Are All They Need ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split Devil’s advocate? Uncensored Luciferus AI service advertised underground “Eye” spy: Cyclops Blink returns with extended capabilities Ransomware in Education 2026: Key Findings Sophos Joins OpenAI’s Call for Collective Cyber Defense Sophos Ranked #1 Overall Across Endpoint, XDR, MDR, and Firewall in G2 Fall 2026 Reports Fake AI, real malware: Attackers impersonating AI brands A heap of overflow in August’s Patch Tuesday haul Accelerating NetNTLMv1 Lookups Without GPUs Abuse of alternative runtime environments Deno-tes defender headaches ClickFix campaign abuses Deno runtime for infostealer delivery Sophos Working with OpenAI on security from AI, with AI, and for AI N-able N-central exploitation results in RMM tool deployment Interlock ransomware gang creates volatile situation When AI doesn’t know the target is real Chaos in Teams vishing Why Sophos Has Become Its Own AI Test Lab SonicWall SMA1000 vulnerabilities in active exploitation When AI agents look like attackers: what behavioral telemetry tells us Sophos and the Cybersecurity Poverty Line You do surprise me.exe: An unexpected executable in Hola Browser You do surprise me.exe: An unexpected executable in Hola Browser Pointing a Cursor at evading detection Pointing a Cursor at evading detection Pointing a Cursor at evading detection Canvas attack aftermath: What risks come next
July Patch Tuesday only feels endless
About the Author(s) · 2026-07-21 · via Sophos Blogs

Microsoft on Tuesday released 575 patches affecting 29 product families. Sixty-three of the addressed issues are considered by Microsoft to be of Critical severity; 44 CVEs are expected to be exploited within the next 30 days. (Two already are, though neither CVE-2026-56155 nor CVE-2026-56164 is considered to be of Critical severity.) One hundred and three have a CVSS Base score of 8.0 or higher. Just one was publicly disclosed as of release day and two are acknowledged to be under active exploit in the wild.

The advisory tally this month is likewise elevated. In addition to the usual Servicing Stack update, there are 479 advisories, all touching Edge. Virtually all of these were patched in advance of Patch Tuesday, but as ever we encourage readers to be sure that they’ve applied all available browser patches when those are made available. There were no Adobe-related patches made available by Microsoft this month, and aside from the 435 Chromium-issued Edge advisory items, all CVEs (and the Servicing Stack) originated with Microsoft.

Various of this month’s issues are amenable to direct detection by Sophos protections, and we include information on those in the usual table below.

Stepping back from this July’s output, we’re more or less four months into the AI-finder era of bug hunting, and patterns are starting to emerge from the noise. First, either finders are suddenly building coalitions that would shame NATO or simultaneous discovery is rampant. In years past it was unusual to see a single bug credited to more than half a dozen finders; this month alone saw at least four CVEs with ten or more credits listed. One, an otherwise remarkable PowerShell RCE bug labeled CVE-2026-40400, has fifteen. In a related vein, bug totals for certain finders (whether individuals or committees) are astonishing. Having a dozen or more CVEs credited to the same entity in the same month is now entirely normal; this month’s top CVE submitter, 0ccbbf129444eb66344ccafb92b00df4, has 47 July credits (44 in Office, over half the month’s Office total) to their handle.

Second, though the volume is overwhelming, so far these bugs are turning up in the lab, not the wild. (No complaints.) None of 0ccbbf129444eb66344ccafb92b00df4’s bugs have been seen yet in the wild, and only seven of them are Critical-severity. The heat map in Figure 1 shows that in fact, the percentage of bugs that have either been publicly disclosed or found in the wild has dropped in recent months. Even the percentage of CVEs Microsoft deems more likely to be exploited within the next 30 days is relatively low.

pt2607-fig01.png

Figure 1: A heat map analyzing Patch Tuesday numbers over the past year indicates that though the overall CVE counts are high, the bugs that are coming to light in recent months are most likely not immediately threatening the health of the internet.

Does this add credence to the idea that AI bug hunting represents a grand code cleanup that one day will subside, having eliminated all bugs worth finding? We won’t speculate, but it will be interesting to see what happens next.

Finally, the sheer volume of CVEs each month means that many security folk are adapting their Patch Tuesday routines. This blog is no exception. For those readers accustomed to using our appendices for guidance each month, we’re switching to a new system that should appeal greatly to those who love data but prefer it in spreadsheet form. Read on.

By the numbers

  • Total CVEs: 575
  • Publicly disclosed: 1
  • Exploit detected: 2
  • Severity
    • Critical: 63
    • Important: 510
    • Moderate: 2
  • Impact:
    • Denial of Service: 35
    • Elevation of Privilege: 254
    • Information Disclosure: 102
    • Remote Code Execution: 143
    • Spoofing: 16
    • Security Feature Bypass: 17
    • Tampering: 8
  • CVSS base score 9.0 or greater: 21
  • CVSS base score 8.0 or greater: 103

pt2607-fig02.png

Figure 2: It may be hard to discern under the circumstances, but the counts for Security Feature Bypass and Spoofing vulnerabilities actually dropped in July – possibly a sign that certain kinds of bugs are easier to find via AI than others.

Products

  • .NET: 16
  • 365: 79
  • Age of Empires II: 1
  • ASP.NET: 2
  • Azure: 8
  • Bing Search for iOS: 1
  • Copilot: 2
  • Defender / Mac: 3
  • Dynamics NAV: 1
  • Entra: 1
  • Excel: 31
  • Exchange: 5
  • Fabric Data Warehouse: 1
  • GitHub / JetBrains: 1
  • Minecraft Bedrock Dedicated Server: 1
  • MMPE: 2
  • Office: 78
  • PC Manager: 2
  • PowerBI: 1
  • PowerPoint: 3
  • SharePoint: 38
  • SQL: 7
  • Surface: 1
  • VS: 22
  • Windows: 407
  • Windows Admin Center: 6
  • Windows Remote Help: 1
  • Windows Subsystem for Linux: 2
  • Word: 12

As is our custom for this list, CVEs that apply to more than one product family are counted once for each family they affect.

pt2607-fig03.png

Figure 3: In the interests of having a chart that’s usable, we’re doing things a bit differently for the time being. Windows’ 407 CVEs – 31 Critical, 375 Important, one Moderate – are relegated to this caption; we trust the reader didn’t seriously think Windows was pain-free in a month like this. In addition, ten product families received just one patch apiece this month. Please consult the Excel spreadsheet linked below for information on all ten, or read on for a glimpse of the two most depressing of that group.

pt2607-fig04.png

Figure 4: Seven months in, Elevation of Privilege issues are twice as prevalent as Remote Code Execution flaws. Meanwhile, Security Feature Bypass picks up its first Critical-severity patch this month, for the SharePoint issue CVE-2026-55040.

Notable July updates

In addition to the issues discussed above, a few items merit general attention.

CVE-2026-50518 – Windows DHCP Server Remote Code Execution Vulnerability
CVE-2026-50522 – Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2026-55008 – Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-55944 – Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
CVE-2026-56188 -- Windows Server Network Driver Remote Code Execution Vulnerability
CVE-2026-58644 – Microsoft SharePoint Remote Code Execution Vulnerability

Many of the CVEs that look most urgent on paper – CVSS Base above 9.0, Critical severity – are either relatively less likely to be exploited in the next 30 days or have already been mitigated. The six CVEs listed above are neither, and they have been judged by Microsoft to be more likely to be exploited in the next 30 days. If you’re unsure of where to begin with your July patching, here’s your sign.

CVE-2026-50301, CVE-2026-50314, CVE-2026-50467, CVE-2026-55018, CVE-2026-55022, CVE-2026-55033, CVE-2026-55045, CVE-2026-55049, CVE-2026-55056, CVE-2026-55057, CVE-2026-55127, CVE-2026-55129, CVE-2026-55132, CVE-2026-55140, CVE-2026-56193, CVE-2026-56195 (16 Office CVEs)

Preview Pane is a vector for all 16 of these Office CVEs. All but three (CVE-2026-55057, CVE-2026-56193, CVE-2026-56195) are Critical-severity, though all 16 are considered by Microsoft to be less likely to be exploited within the next 30 days.

31 Important-severity Edge CVEs (advisory-only)

Continuing the trend of hyper-productive finders as mentioned above, we salute Microsoft’s own Kugelblitz, finder of 38 Important-severity Edge bugs this month (37 of those with solo credit). Curiously, 31 of those bugs require very specific user interaction – two sequential taps, as one might do to use autofill on a Web page. We know full well that bug-hunting at this volume is most likely automated, and other finders this month also identified a scattering of bugs with the same vector, but the mental image of some poor soul in Redmond tap-tapping a screen over and over in search of Edge bugs makes our mouse fingers ache.

CVE-2026-55010 – Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability
CVE-2026-50663 -- Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability

That’s right – patches for Age of Empires II and Minecraft. Not even your childhood shall be spared the patchapalooza.

Sophos protections

CVESophos Intercept X/Endpoint IPS

Sophos XGS Firewall

CVE-2026-49170Exp/2649170-AExp/2649170-A
CVE-2026-49795Exp/2649795-AExp/2649795-A
CVE-2026-49798Exp/2649798-AExp/2649798-A
CVE-2026-49800Exp/2649800-AExp/2649800-A
CVE-2026-50329Exp/2650329-AExp/2650329-A
CVE-2026-50332Exp/2650332-AExp/2650332-A
CVE-2026-50343Exp/2650343-AExp/2650343-A
CVE-2026-50351Exp/2650351-AExp/2650351-A
CVE-2026-50375Exp/2650375-AExp/2650375-A
CVE-2026-50387Exp/2650387-AExp/2650387-A
CVE-2026-50390Exp/2650390-AExp/2650390-A
CVE-2026-50420Exp/2650420-AExp/2650420-A
CVE-2026-50423Exp/2650423-AExp/2650423-A
CVE-2026-50433Exp/2650433-AExp/2650433-A
CVE-2026-50436Exp/2650436-AExp/2650436-A
CVE-2026-50454Exp/2650454-AExp/2650454-A
CVE-2026-50475Exp/2650475-AExp/2650475-A
CVE-2026-50476Exp/2650476-AExp/2650476-A
CVE-2026-50518sid:2312733sid:2312734
CVE-2026-50522sid:2312729sid:2312729
CVE-2026-50667Exp/2650667-AExp/2650667-A
CVE-2026-50688Exp/2650688-AExp/2650688-A
CVE-2026-54114Exp/2654114-AExp/2654114-A
CVE-2026-54986Exp/2654986-AExp/2654986-A
CVE-2026-54992sid:2312741sid:2312741
CVE-2026-56164sid:2312731, sid:2312732sid:2312731, sid:2312732
CVE-2026-57091Exp/2657091-AExp/2657091-A
CVE-2026-58536Exp/2658536-AExp/2658536-A

As you can every month, if you don’t want to wait for your system to pull down Microsoft’s updates itself, you can download them manually from the Windows Update Catalog website. Run the winver.exe tool to determine which build of Windows you’re running, then download the Cumulative Update package for your specific system’s architecture and build number.

Appendix: PatchTuesday_July2026

Because absolutely no one wants to look at 1000-plus CVEs of bloggery, we present all the data you crave in a far more civilized format – an Excel workbook. You’ll find all your favorite appendix data there, in a format that allows readers to pivot and sort to their hearts’ content. The workbook contains multiple sheets:

PT_Summary – key monthly metrics in a single-screen format
PT_PriSevImp – best for sorting by impact, Microsoft-assigned severity / CVSS, impact, and prospects for exploitability
PT_ByProduct – a more granular breakdown focusing on product families; helpful when dealing with CVEs with multi-family applicability
PT_Windows – a chart showing which versions of Windows are affected by each patched CVE; with the switch to Excel, we are pleased to expand the former Appendix E to include currently supported client versions
PT_Protections – a list of all Sophos-issues protections applicable to this month’s patches; replicates the chart in the blog post for easy reference
PT_Advisories – third-party advisories, information on the periodically offered servicing stack, and all Edge-related CVEs are here
PT_CWE – a breakdown of which vulnerabilities were most often discovered in the products patched this month