Microsoft fixed at least 570 vulnerabilities in its July 2026 Patch Tuesday, released July 14, a record total independently tallied by Krebs on Security and BleepingComputer. Krebs reports the total is nearly triple June’s release.
Microsoft ties the surge to vulnerability discovery driven by AI. In a July 9 blog post, the company said new AI-powered internal tooling surfaces candidate flaws at far greater scale than its earlier manual methods. That mechanism is self-reported by Microsoft and not independently verified, so treat the internal details as a vendor claim.
The number to plan around is Microsoft’s own guidance: customers should expect higher volumes of fixes in each release going forward. This is a new baseline, not a one-off spike.
For security programs, that changes the math. Patch-window staffing, regression-test cycles, and change-management throughput were all sized against historical monthly volume in the low hundreds. A 570-fix batch breaks those assumptions.
Raw count is not urgency, though. About 60 fixes carry a critical rating, and Microsoft says three zero-days were already under active exploitation. Krebs also highlights CVE-2026-48561, a Copilot remote-code-execution flaw (CVSS 9.6) reachable through browser-triggered prompts, a reminder that AI-feature attack surface now sits inside the monthly cycle.
Prioritize by exploitability and exposure, patch the active zero-days first, and budget for sustained volume.
Source: Windows Experience Blog



Leave a Reply