In an unprecedented security event, Microsoft released the July 2026 Patch Tuesday update and announced fixes for 570 security vulnerabilities — a record number in the company’s history. What’s most concerning is that 3 of these vulnerabilities were of the Zero-Day type, and two of them were already exploited in cyberattacks before the update was released.

Microsoft July 2026 Update: 570 Security Vulnerabilities and Record Patch Tuesday
Microsoft’s July 2026 update is the largest in history — fixing 570 security vulnerabilities at once

What’s the Story Behind the Largest Update in History?

Microsoft releases security updates every second Tuesday of the month, known as Patch Tuesday. In July 2026, the company shattered its own record — last month (June) had 206 vulnerabilities, and now it’s 570 in one go. But why such a massive increase?

The main reason is a new AI system developed by Microsoft to automatically detect security vulnerabilities. This system (multi-model agentic scanning) scanned millions of lines of Windows code and uncovered a massive number of previously unknown vulnerabilities. In short: AI exposed hidden weaknesses that had gone unnoticed for years.

Details: What Do the 570 Vulnerabilities Include?

The update is massive and covers nearly all Microsoft products:

  • 254 vulnerabilities of the Elevation of Privilege type — the most dangerous as they allow attackers full control.
  • 145 vulnerabilities of the Remote Code Execution type — enabling attackers to run malicious programs on your device.
  • 102 vulnerabilities of the Information Disclosure type — leaking your private data.
  • 59 vulnerabilities rated as Critical (extremely severe).
  • In addition to vulnerabilities in Office, SharePoint, SQL Server, Defender, and others.
Computer screen showing Windows security updates to protect users
The update covers Windows 10, 11, Office, SharePoint — most Microsoft products

The Three Dangerous Zero-Day Vulnerabilities You Need to Know

First — CVE-2026-56155: Vulnerability in Active Directory Federation Services
Already exploited in attacks. Allows attackers to gain full administrative privileges in enterprise identity management systems. The danger here is that AD FS is the backbone of Single Sign-On (SSO) in organizations — meaning if compromised, it gives control over all accounts.

Second — CVE-2026-56164: Vulnerability in SharePoint Server
Also exploited in attacks. Allows privilege escalation via SharePoint servers. The biggest risk is that this vulnerability is often used in combination with o

Third — CVE-2026-50661: BitLocker vulnerability
Has not been used in attacks (yet) but is publicly disclosed. Allows bypassing BitLocker encryption if the attacker has physical access to the device. Means if your laptop is lost or stolen, someone can read your files!

Developer securing servers and protecting against security vulnerabilities
BitLocker vulnerability is serious for laptop owners — protecting your data requires immediate update

How does this apply in Saudi Arabia?

Saudi Arabia is witnessing a huge digital transformation thanks to Vision 2030. Most companies and government institutions use Microsoft systems (Windows, Office 365, SharePoint, Azure). Neglecting these updates means:

  • Exposing employee and customer data to risk
  • Possible breach of internal company and institution systems
  • Massive financial losses — the cost of a breach could exceed millions of riyals
  • Violating Saudi cyber security regulations (such as NCA and SDAIA)

For this reason, the National Cybersecurity Authority (NCA) in Saudi Arabia recommends applying security updates as soon as they are released, especially in vital sectors such as banks, energy, and healthcare.

Important points about the update

  • The update is available for all supported versions of Windows 10 and 11
  • Includes Office, SharePoint, SQL Server, Azure, and Defender
  • 468 additional vulnerabilities in Edge browser have been fixed from the Chromium update
  • Artificial intelligence is responsible for discovering most of the new vulnerabilities
  • The update is available through Windows Update or the Microsoft Update Catalog website

❓ Frequently Asked Questions

Who needs this update?
All Windows users — from individuals to large companies. Any device running Windows 10 or 11 or Windows Server needs this update immediately. Office, SharePoint, and Azure users also.

Where is the update installed?
From the Settings menu (Settings) ← Update & Security ← Windows Update ← Check for updates. Or for servers via Windows Server Update Services (WSUS).

What is the cost of the update?
Completely free. Patch Tuesday security updates come as part of the Windows subscription and do not cost the user any extra amount. Even older versions of Windows get them for free.

How long does the installation take?
Varies depending on the device’s speed and the number of updates. For regular home devices: 10-30 minutes. Servers may take an hour or more. Important: The device will need to be restarted after installation.

How do I start the update now?
Open Settings (Start ← Settings) or press Win+I ← Choose Windows Update ← Click on “Check for updates” ← Wait for the download and installation ← Restart the device. And if you are a tech administrator in a company, use

Is the update secure and does not cause problems?
Generally, yes, but like any major update, it is always recommended to make a backup of your important files before installation, especially on work devices.

Summary

Microsoft’s July 2026 update is the largest in history — 570 security vulnerabilities fixed at once. With cyberattacks continuing to rise worldwide, and amidst the accelerating digital transformation in Saudi Arabia, securing your devices and data is no longer an option, but a necessity. Do not delay the update — today’s vulnerabilities are tomorrow’s attacks.

🔐 Share the article with your colleagues and employees — cybersecurity is everyone’s responsibility.