Microsoft Patch Tuesday July 2026 Priority Fixes

Red | Vulnerability
Download Now
TA2026199 | Microsoft Patch Tuesday July 2026 - Priority Fixes | Hive Pro Threat Advisory

Threat Advisory • Vulnerability Report • TA2026199

Microsoft Patch Tuesday July 2026 - Priority Fixes

Microsoft's July 2026 Patch Tuesday delivers fixes for 622 vulnerabilities, including two actively exploited zero-days, and highlights 15 high-priority CVEs affecting Microsoft SharePoint, Windows Server, Active Directory Federation Services, Windows DHCP Server, Microsoft Exchange Online, Windows BitLocker, Microsoft Dynamics NAV, Minecraft Bedrock Dedicated Server, and Google Chromium.

15 Exploitable CVEs 2 Zero-Days 1 Publicly Disclosed Patch Available Admiralty Code A1
TA Number
TA2026199
Date of Publication
July 15, 2026
First Seen
July 14, 2026
Admiralty Code
A1
Exploitable CVEs
15
Zero-Days Fixed
2
Total Vulns Patched
622
Non-Microsoft CVEs
428
Total Resolved
1,050

Summary

This threat advisory covers Microsoft's July 2026 Patch Tuesday release, first seen on July 14, 2026 and published on July 15, 2026 under Admiralty Code A1. The release affects a broad set of platforms including Microsoft SharePoint, Windows Server, Windows DHCP Server, Microsoft Active Directory Federation Services, Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central, Minecraft Bedrock, Microsoft Office, Microsoft Exchange, and Windows BitLocker.

Affected Platforms:

  • Microsoft SharePoint (Server Subscription Edition, Server 2019, Enterprise Server 2016)
  • Windows Server (2012, 2016, 2019, 2022, 2025)
  • Windows DHCP Server
  • Microsoft Active Directory Federation Services
  • Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central
  • Minecraft Bedrock Dedicated Server
  • Microsoft Office
  • Microsoft Exchange Online
  • Windows BitLocker
  • Google Chromium

Impact: Information Disclosure, Denial of Service, Remote Code Execution, Elevation of Privilege, Security Feature Bypass, Spoofing, Tampering.

Microsoft's July 2026 Patch Tuesday stands out as one of the largest security releases the company has ever shipped, addressing 622 vulnerabilities across its product ecosystem — 63 rated Critical, 552 Important, 6 Moderate, and 1 Low. The patched flaws span 164 remote code execution issues, 256 elevation of privilege flaws, 109 information disclosure bugs, 35 denial-of-service vulnerabilities, 29 spoofing issues, 21 security feature bypasses, and 8 tampering weaknesses. Beyond its own products, Microsoft rolled out patches for 428 non-Microsoft CVEs, bringing the total number of vulnerabilities resolved this month to 1,050. Hive Pro has flagged 15 CVEs from this release as being at risk of active exploitation, representing the top patching priorities for this cycle.


Vulnerability Details

Scale of the July 2026 Release

Microsoft's July 2026 Patch Tuesday addresses the highest number of flaws to date, with fixes for 622 vulnerabilities across its product ecosystem. Of these, 63 are rated Critical, 552 Important, 6 Moderate, and 1 Low. Combined with 428 non-Microsoft CVEs, the total number of vulnerabilities resolved this month reaches 1,050. Hive Pro has flagged 15 CVEs from this release as being at risk of active exploitation, and these represent the top patching priorities for this cycle; organizations should remediate them before working through the remaining fixes.

Zero-Day and Publicly Disclosed Vulnerabilities

Two zero-day vulnerabilities were fixed this month. CVE-2026-56164 is a missing-authentication flaw in Microsoft SharePoint that lets an unauthenticated attacker elevate privileges over a network. CVE-2026-56155 stems from insufficiently granular access control in Active Directory Federation Services (AD FS) and allows an authenticated attacker to elevate privileges locally. One flaw was publicly disclosed ahead of patching: CVE-2026-50661 in Windows BitLocker. Caused by a protection mechanism failure, it allows an attacker with physical access to bypass a security feature.

Critical Microsoft SharePoint Flaws

Several critical SharePoint flaws feature prominently this cycle. CVE-2026-58644 involves deserialization of untrusted data in Microsoft SharePoint and enables remote code execution over a network. CVE-2026-55040 is a weak-authentication issue in Microsoft SharePoint that lets an unauthenticated attacker bypass a security feature remotely. CVE-2026-50522 similarly allows an unauthenticated attacker to run code over a network against Microsoft SharePoint.

Windows Components and Services

The release also tackles a number of high-impact flaws across other Windows components and services. CVE-2026-56188 in the Windows Server network driver permits remote code execution. CVE-2026-56159 and CVE-2026-50518 are both heap-based buffer overflows in the Windows DHCP Server, each allowing remote code execution. CVE-2026-55944 is a deserialization flaw in Microsoft Dynamics NAV that enables code execution over a network, and CVE-2026-55010 is a heap-based buffer overflow in the Minecraft Bedrock Dedicated Server with the same effect. Rounding out this set, CVE-2026-54998 in Microsoft Exchange Online lets an authenticated attacker elevate privileges over a network.

Non-Microsoft: Google Chromium Flaws

On the non-Microsoft side, two Google Chrome flaws stand out. CVE-2026-13774 is a high-severity issue in Google Chromium versions prior to 150.0.7871.47, where a user tricked into installing a malicious extension could have arbitrary code executed via a crafted Chrome extension. CVE-2026-14382 affects ANGLE in Google Chromium versions before 150.0.7871.46 and could let a remote attacker attempt a sandbox escape through a crafted HTML page.

Taken together, Microsoft's July 2026 updates reflect just how complex and fast-moving today's threat landscape has become. With multiple zero-days, privilege escalation flaws, and remote code execution vulnerabilities all addressed in a single release, organizations are strongly urged to apply these patches without delay, reducing their exposure to both opportunistic attacks and more sophisticated, targeted campaigns.

Exploitable CVEs at a Glance
CVE Name Affected Product Patch
CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016 Available
CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability Windows 10, Windows Server 2012, 2016, 2019, 2022, 2025 Available
CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016 Available
CVE-2026-56188 Windows Server Network Driver Remote Code Execution Vulnerability Windows 10 - 11 25H2, Windows Server 2012, 2016, 2019, 2022, 2025 Available
CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability Windows 10, Windows Server 2012, 2016, 2019, 2022, 2025 Available
CVE-2026-55944 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability Microsoft Dynamics NAV 2018 Available
CVE-2026-55047 Microsoft Office Information Disclosure Vulnerability Microsoft Office 2019, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft Office 365 for Mac, Microsoft Office 2016, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021, Microsoft 365 Apps for Enterprise Available
CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016 Available
CVE-2026-55010 Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability Minecraft Bedrock Dedicated Server Available
CVE-2026-54998 Microsoft Exchange Online Elevation of Privilege Vulnerability Microsoft Exchange Online Available
CVE-2026-50661 Windows BitLocker Security Feature Bypass Vulnerability Windows 10 - 11 26H1, Windows Server 2016, 2019, 2022, 2025 Available
CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016 Available
CVE-2026-50518 Windows DHCP Server Remote Code Execution Vulnerability Windows 10, Windows Server 2012, 2016, 2019, 2022, 2025 Available
CVE-2026-13774 Chromium Use After Free in Extensions Vulnerability Google Chromium Available
CVE-2026-14382 Chromium Insufficient Validation of Untrusted Input in ANGLE Vulnerability Google Chromium Available

Note: All exploitable CVEs listed above have patch links hyperlinked from their respective vendor advisories.


Recommendations

01

Evaluate Service Exposure

Conduct an extensive service exposure evaluation to identify any vulnerable services that may be publicly accessible. Take immediate and decisive action to address any identified vulnerabilities, either by installing essential patches or adopting security measures.

02

Keep Systems Updated

Keep your systems up to date by implementing the most recent security updates. To avoid the introduction of new vulnerabilities, follow security rules adapted to unique devices. Furthermore, to strengthen the resilience of devices and apps exposed to the internet, thoroughly review their configurations.

03

Prioritize Actively Exploited CVEs

Prioritize patching the actively exploited vulnerabilities CVE-2026-56164, CVE-2026-56155, and CVE-2026-50661. These vulnerabilities pose significant exploitation risks and should be addressed urgently.

04

Implement Network Segmentation

Implement network segmentation to restrict unauthorized access and reduce the impact of potential attacks. This can be especially effective in scenarios where network adjacency is a factor.

05

Enforce Least Privilege

Adhere to the idea of "least privilege" by giving users only the essential permissions they need for their tasks. This strategy reduces the effects of vulnerabilities related to privilege escalation.


MITRE ATT&CK TTPs

Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Execution
T1059 Command and Scripting Interpreter
Persistence
T1176 Software Extensions
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Privilege Escalation
T1078 Valid Accounts
Defense Evasion
T1211 Exploitation for Defense Evasion
Credential Access
T1556 Modify Authentication Process
Resource Development
T1588 Obtain Capabilities Sub-technique: T1588.006 Vulnerabilities

References & Patch Links