In the world of information security, an event has occurred that experts will discuss for a long time to come. Microsoft released the July Patch Tuesday security update for Windows 10 and Windows 11 operating systems, setting a new historical record. In just one month, the corporation patched 570 documented vulnerabilities, surpassing the previous month's figures and making this release the largest in the company's history in terms of the number of fixed issues.
Zero-day threats and active attacks
Among the massive array of fixes, zero-day errors—vulnerabilities for which a patch appears only after the problem has been discovered—draw particular attention. In this update, Microsoft closed three such critical holes. Moreover, two of them have already been exploited by attackers in real cyberattacks.
The most dangerous vulnerabilities are those affecting corporate infrastructure:
- Active Directory Federation Services (CVE-2026-56155)
- SharePoint Server (CVE-2026-56164)
- Windows BitLocker (CVE-2026-50661)
Exploitation of issues in Active Directory Federation Services and SharePoint Server has already been recorded, making them a priority for immediate remediation on organizational servers.
Fix statistics: the scale of the problem
An analysis of the update composition shows that Microsoft has conducted a colossal amount of work on security auditing. In total, within the scope of this release, the following were fixed:
- 254 vulnerabilities allowing privilege escalation;
- 145 remote code execution errors;
- 102 issues related to the disclosure of confidential information;
- 35 vulnerabilities leading to denial of service (DoS);
- 17 security bypass errors;
- 16 cases of data tampering.
59 vulnerabilities were classified as critical. Many of them allow attackers to remotely execute arbitrary code on an infected system, making them extremely dangerous for any device connected to the network.
The role of artificial intelligence in finding holes
Why did the number of fixes reach such a scale? Microsoft explains the increase in the number of detected problems by the expanded use of artificial intelligence tools during internal security checks. The company emphasizes that the record number of patches does not indicate a deterioration in Windows security. On the contrary, it indicates that vulnerability detection methods have become more effective, allowing holes to be found and closed before hackers discover and exploit them.
New features for Windows 11 users
In addition to purely protective measures, the cumulative update brought a number of new capabilities for Windows 11 users. Among the key innovations:
- Point-in-Time Restore technology, which allows restoring applications, settings, files, and system state to a previous point.
- Advanced widget customization options on the desktop.
- Improvements in the "Magnifier" tool for people with visual impairments.
- Extended Bluetooth compatibility with a range of devices.
Installation recommendations
Although corporate users are recommended to perform standard compatibility checks before mass deployment of updates, the presence of two actively exploited zero-day vulnerabilities dictates its own rules. Microsoft strongly advises prioritizing the installation of patches on systems accessible from the internet, as well as on authentication services.
For personal users, the company recommends installing the update via the standard Windows Update mechanism immediately after its release to guarantee the protection of their data and devices.