Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
ID: a11cac16-6473-5a5a-885f-3ae847b6a9f4
STIX ID: report--a11cac16-6473-5a5a-885f-3ae847b6a9f4
Feed Name: The Hacker News
Microsoft's July Patch Tuesday is the largest on record (622 CVEs) and includes two actively exploited zero-days—CVE-2026-56164 in on-premises SharePoint (remote, unauthenticated privilege escalation) and CVE-2026-56155 in Active Directory Federation Services (local privilege escalation)—plus a disclosed BitLocker bypass; the report urges immediate patching, attention to SharePoint/AD FS remediation, and careful rollout due to Kerberos RC4 hardening that can break legacy authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
