🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)

📰 IT Security Nachrichten 🕛 kürzlich 55 Min Lesezeit CVE-2026-26145
0

The July 2026 Security Update Review

Cyber Threat & Vulnerability Dossier CVSS 9.9 CRITICAL EPSS 84.4%
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔑 Geringe Nutzerrechte nötig
SCHADENSPROFIL
⛔ Dienstausfall (DoS) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-119: Memory Corruption
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (thezdi.com)
🔬 IoC Intelligence (621 Indikatoren erkannt)
CVE-2026-56155CVE-2026-56164CVE-2026-57092CVE-2026-50522CVE-2026-56190CVE-2026-55008CVE-2026-50518CVE-2026-56188+613 weitere
🗣️ Stimme:

Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here. Excellent call. Take an extended break from your regularly scheduled activities as we let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our
Adobe ColdFusion
13
Critical
9.9
No
1



Adobe After Effects
3
Critical
7.8
No
3



Adobe Audition
6
Critical
7.8
No
3



Adobe Creative Cloud Desktop Application
2
Critical
8.1
No
3



Adobe Illustrator
5
Critical
9.3
No
3



Adobe Premiere Pro
4
Critical
7.8
No
3


- Active Directory Federation Services Elevation of Privilege Vulnerability
This is one of several AD FS being patched this month, but it’s the only one being actively exploited. It stems from insufficient access-control granularity and does require local access and low privileges to start, but AD FS is exactly the kind of identity infrastructure attackers love to pivot through once they're in. It can also be paired with an RCE as we often see in ransomware. Test and deploy this patch quickly.

-     - Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
This patch rates the highest CVSS score for the month: a solid 9.9. It’s a use-after-free that lets a low-privileged attacker escalate to full host compromise across a VM boundary. We saw something like this demonstrated at Pwn2Own Berlin on ESXi, but it clearly isn’t alone. If you’re using VMSwitch in your Hyper-V deployments (and you likely are), test and deploy this one quickly.

-     - Microsoft SharePoint Remote Code Execution Vulnerability
This matching pair of CVSS 9.8 bugs results from the deserialization-of-untrusted-data and are reachable without authentication or user interaction. CVE-2026-50522 was demonstrated during - Remote Desktop Protocol Remote Code Execution Vulnerability
This patch covers an unauthenticated, network-reachable, no user interaction required bug. The root cause is a classic one: use of uninitialized resource (CWE-908), meaning specially crafted RDP traffic can interact with memory that was never properly initialized, letting an attacker corrupt memory and potentially steer code execution. RDP Servers are a common target, so audit your systems to see which are internet accessible and start from there.

-     - Windows DHCP Server Remote Code Execution Vulnerability
There are a couple of these DHCP RCE patches in this release, but the other has caveats while this one does not. Both are heap-based buffer overflows scoring CVSS 9.8, both unauthenticated and network-reachable. If you're running DHCP Server role on anything Internet-adjacent (you're not, right?), these move to the top of the list.

-    - Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability
File this in the “why not” category. This bug is a heap-based buffer overflow in Minecraft Bedrock Dedicated Server, also CVSS 9.8 and also unauthenticated RCE. Yes, your kid’s Minecraft server (it is your kid’s server, right?) is exposed to the same class of bug as your DHCP infrastructure. Patch it anyway.

Here’s the full list of CVEs released by Microsoft for July 2026:

















































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































<![if supportMisalignedColumns]>









<![endif]>
CVE Title Severity CVSS Public Exploited Type
Microsoft SharePoint
Server Elevation of Privilege Vulnerability
Moderate 5.3 No Yes EoP
Active Directory
Certificate Services Elevation of Privilege Vulnerability
Critical 8.8 No No EoP
DHCP Server Service
Remote Code Execution Vulnerability
Critical 8.8 No No RCE
DHCP Server Service
Remote Code Execution Vulnerability
Critical 9.8 No No RCE
Microsoft 365 Copilot
Elevation of Privilege Vulnerability
Critical 9.3 No No EoP
Microsoft Copilot
Remote Code Execution Vulnerability
Critical 9.6 No No RCE
Microsoft Defender
Remote Code Execution Vulnerability
Critical 7.8 No No RCE
Microsoft Entra
Provisioning Service Elevation of Privilege Vulnerability
Critical 9.9 No No EoP
Microsoft Exchange
Online Elevation of Privilege Vulnerability
Critical 8.8 No No EoP
Microsoft Message
Queuing Queue Manager Remote Code Execution Vulnerability
Critical 8.4 No No RCE
Microsoft Office
Remote Code Execution Vulnerability
Critical 7.8 No No RCE
Microsoft Office
Remote Code Execution Vulnerability
Critical 7.8 No No RCE
Microsoft Office
Remote Code Execution Vulnerability
Critical 7.8 No No RCE
Microsoft Office
Remote Code Execution Vulnerability
Critical 7.8 No No RCE
Microsoft PowerPoint
Remote Code Execution Vulnerability
Critical 7.8 No No RCE
Microsoft PowerPoint
Remote Code Execution Vulnerability
Critical 7.8 No No RCE
Microsoft SharePoint
Remote Code Execution Vulnerability
Critical 9.8 No No RCE
Microsoft SQL Server
Remote Code Execution Vulnerability
Critical 8.8 No No RCE
Microsoft Windows
Media Foundation Remote Code Execution Vulnerability
Critical 7.8 No No RCE
Microsoft Windows
Media Foundation Remote Code Execution Vulnerability
Critical 8.8 No No RCE
Microsoft Windows
Media Foundation Remote Code Execution Vulnerability
Critical 8.8 No No RCE
Microsoft Word Remote
Code Execution Vulnerability
Critical 7.8 No No RCE
Microsoft Word Remote
Code Execution Vulnerability
Critical 7.8 No No RCE
Remote Desktop Client
Remote Code Execution Vulnerability
Critical 8.8 No No RCE
Windows DHCP Client
Remote Code Execution Vulnerability
Critical 8.4 No No RCE
Windows GDI+ Remote
Code Execution Vulnerability
Critical 7.8 No No RCE
Windows Hyper-V
Elevation of Privilege Vulnerability
Critical 7.4 No No EoP
Windows Media Remote
Code Execution Vulnerability
Critical 7.8 No No RCE
Windows Print Spooler
Remote Code Execution Vulnerability
Critical 8.8 No No RCE
Windows Reliable
Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Critical 8.1 No No RCE
Windows Secure Kernel
Mode Elevation of Privilege Vulnerability
Critical 7 No No EoP
Windows Server Network
driver Remote Code Execution Vulnerability
Critical 9.8 No No RCE
Windows TCP/IP Remote
Code Execution Vulnerability
Critical 8.8 No No RCE
.NET Denial of Service
Vulnerability
Important 7.5 No No DoS
.NET Denial of Service
Vulnerability
Important 7.5 No No DoS
.NET Framework Denial
of Service Vulnerability
Important 7.5 No No DoS
.NET Framework
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
.NET Remote Code
Execution Vulnerability
Important 7.8 No No RCE
.NET Security Feature
Bypass Vulnerability
Important 8.2 No No SFB
.NET Tampering
Vulnerability
Important 7 No No Tampering
Active Directory
Domain Services Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Active Directory
Federation Server Spoofing Vulnerability
Important 4.8 No No Spoofing
ASP.NET Core Elevation
of Privilege Vulnerability
Important 8.8 No No EoP
Azure Active Directory
Denial of Service Vulnerability
Important 7.5 No No DoS
Azure CycleCloud
Elevation of Privilege Vulnerability
Important 8.8 No No EoP
Azure Monitor Agent
Metrics Extension Elevation of Privilege Vulnerability
Important 8.8 No No EoP
Clipboard User Service
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Composite Image File
System driver (cimfs.sys) Information Disclosure Vulnerability
Important 5.5 No No Info
Desktop Window Manager
Elevation of Privilege Vulnerability
Important 8.8 No No EoP
Desktop Window Manager
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
DirectX Graphics
Kernel Elevation of Privilege Vulnerability
Important 6.3 No No EoP
DirectX Graphics
Kernel Elevation of Privilege Vulnerability
Important 7.8 No No EoP
DirectX Graphics
Kernel Elevation of Privilege Vulnerability
Important 7.8 No No EoP
DNS Client Tampering
Vulnerability
Important 6.1 No No Tampering
Extensible Storage
Engine (ESENT) Elevation of Privilege Vulnerability
Important 7.8 No No EoP
GitHub Copilot and
Visual Studio Code Information Disclosure Vulnerability
Important 6.5 No No Info
GitHub Copilot Remote
Code Execution Vulnerability
Important 7.8 No No RCE
HTTP.sys Information
Disclosure Vulnerability
Important 6.2 No No Info
Internet Key Exchange
(IKE) Protocol Denial of Service Vulnerability
Important 7.5 No No DoS
Microsoft Bing App for
IOS Spoofing Vulnerability
Important 8.1 No No Spoofing
Microsoft Brokering
File System Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Microsoft Brokering
File System Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Microsoft Defender for
Endpoint for Mac Elevation of Privilege Vulnerability
Important 7 No No EoP
Microsoft Defender for
Endpoint for Mac Information Disclosure Vulnerability
Important 4.7 No No Info
Microsoft DWM Core
Library Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Microsoft Edge
(Chromium-based) Information Disclosure Vulnerability
Important 7.4 No No Info
Microsoft Edge
(Chromium-based) Remote Code Execution Vulnerability
Important 8.8 No No RCE
Microsoft Edge
(Chromium-based) Remote Code Execution Vulnerability
Important 7.6 No No RCE
Microsoft Edge
(Chromium-based) Remote Code Execution Vulnerability
Important 7.1 No No RCE
Microsoft Edge
(Chromium-based) Remote Code Execution Vulnerability
Important 7.5 No No RCE
Microsoft Edge
(Chromium-based) Remote Code Execution Vulnerability
Important 8.8 No No RCE
Microsoft Edge
(Chromium-based) Remote Code Execution Vulnerability
Important 8.3 No No RCE
Microsoft Edge
(Chromium-based) Remote Code Execution Vulnerability
Important 8.3 No No RCE
Microsoft Edge
(Chromium-based) Remote Code Execution Vulnerability
Important 8.3 No No RCE
Microsoft Edge
(Chromium-based) Remote Code Execution Vulnerability
Important 7.5 No No RCE
Microsoft Edge
(Chromium-based) Remote Code Execution Vulnerability
Important 8.1 No No RCE
Microsoft Edge
(Chromium-based) Security Feature Bypass Vulnerability
Important 8.7 No No SFB
Microsoft Edge
(Chromium-based) Security Feature Bypass Vulnerability
Important 8.2 No No SFB
Microsoft Edge
(Chromium-based) Spoofing Vulnerability
Important 5.4 No No Spoofing
Microsoft Edge
(Chromium-based) Spoofing Vulnerability
Important 7.1 No No Spoofing
Microsoft Edge
(Chromium-based) Spoofing Vulnerability
Important 8.1 No No Spoofing
Microsoft Edge
(Chromium-based) Spoofing Vulnerability
Important 8.1 No No Spoofing
Microsoft Edge
(Chromium-based) Spoofing Vulnerability
Important 5.4 No No Spoofing
Microsoft Edge for
Android Information Disclosure Vulnerability
Important 7.1 No No Info
Microsoft Edge for
Android Information Disclosure Vulnerability
Important 6.8 No No Info
Microsoft Edge for
Android Security Feature Bypass Vulnerability
Important 6.5 No No SFB
Microsoft Excel
Information Disclosure Vulnerability
Important 6.1 No No Info
Microsoft Excel
Information Disclosure Vulnerability
Important 5.5 No No Info
Microsoft Excel
Information Disclosure Vulnerability
Important 5.5 No No Info
Microsoft Excel
Information Disclosure Vulnerability
Important 7.1 No No Info
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Excel Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Exchange
Server Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Microsoft Exchange
Server Remote Code Execution Vulnerability
Important 8.8 No No RCE
Microsoft Install
Service Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Microsoft NAT Helper
Components (ipnathlp.dll) Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Microsoft Office
Information Disclosure Vulnerability
Important 5.5 No No Info
Microsoft Office
Information Disclosure Vulnerability
Important 5.5 No No Info
Microsoft Office
Information Disclosure Vulnerability
Important 5.5 No No Info
Microsoft Office
Information Disclosure Vulnerability
Important 5.5 No No Info
Microsoft Office
Information Disclosure Vulnerability
Important 5.5 No No Info
Microsoft Office
Information Disclosure Vulnerability
Important 7.8 No No Info
Microsoft Office
Information Disclosure Vulnerability
Important 5.5 No No Info
Microsoft Office
Remote Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Office
Remote Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft PC Manager
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Microsoft PowerBI
Report Server Spoofing Vulnerability
Important 8 No No Spoofing
Microsoft SharePoint
Elevation of Privilege Vulnerability
Important 8.8 No No EoP
Microsoft SharePoint
Server Spoofing Vulnerability
Important 6.5 No No Spoofing
Microsoft SharePoint
Server Spoofing Vulnerability
Important 4.6 No No Spoofing
Microsoft SharePoint
Server Spoofing Vulnerability
Important 7.3 No No Spoofing
Microsoft SharePoint
Server Spoofing Vulnerability
Important 7.3 No No Spoofing
Microsoft SharePoint
Server Spoofing Vulnerability
Important 4.6 No No Spoofing
Microsoft SQL Server
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Microsoft SQL Server
Elevation of Privilege Vulnerability
Important 8.8 No No EoP
Microsoft SQL Server
Information Disclosure Vulnerability
Important 6.5 No No Info
Microsoft Windows App
Store Elevation of Privilege Vulnerability
Important 7 No No EoP
Microsoft Windows App
Store Information Disclosure Vulnerability
Important 7.1 No No Info
Microsoft Windows
Media Foundation Remote Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Word
Information Disclosure Vulnerability
Important 5.5 No No Info
Microsoft Word Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Word Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft Word Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Microsoft XML Core
Services Elevation of Privilege Vulnerability
Important 7 No No EoP
Netlogon RPC Elevation
of Privilege Vulnerability
Important 7.8 No No EoP
OData for ASP.NET and
ASP.NET Core Denial of Service Vulnerability
Important 7.5 No No DoS
Quality Windows
Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability
Important 7 No No EoP
Remote Desktop Client
Remote Code Execution Vulnerability
Important 9.8 No No RCE
Remote Desktop
Protocol Remote Code Execution Vulnerability
Important 9.8 No No RCE
SQL Server ODBC driver
Elevation of Privilege Vulnerability
Important 9.8 No No EoP
Surface Broker SDMA
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Universal Plug and
Play (upnp.dll) Information Disclosure Vulnerability
Important 5.5 No No Info
Universal Print
Management Service Elevation of Privilege Vulnerability
Important 6.3 No No EoP
Visual Studio Code
Remote Code Execution Vulnerability
Important 8.4 No No RCE
Visual Studio Code
Security Feature Bypass Vulnerability
Important 7.1 No No SFB
Visual Studio Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Win32k Elevation of
Privilege Vulnerability
Important 7 No No EoP
Win32k Elevation of
Privilege Vulnerability
Important 8.8 No No EoP
Win32k Information
Disclosure Vulnerability
Important 3.3 No No Info
Window Virtual
Filtering Platform (VFP) Denial of Service Vulnerability
Important 5.3 No No DoS
Windows Active
Directory Domain Services Denial of Service Vulnerability
Important 6.5 No No DoS
Windows Active
Directory Domain Services Remote Code Execution Vulnerability
Important 8.8 No No RCE
Windows Active
Directory Federation Services Denial of Service Vulnerability
Important 7.5 No No DoS
Windows Active
Directory Federation Services Denial of Service Vulnerability
Important 7.5 No No DoS
Windows Active
Directory Federation Services Denial of Service Vulnerability
Important 5.9 No No DoS
Windows Active
Directory Federation Services Denial of Service Vulnerability
Important 7.5 No No DoS
Windows Admin Center
(WAC) Remote Code Execution Vulnerability
Important 8.8 No No RCE
Windows Admin Center
Elevation of Privilege Vulnerability
Important 8.1 No No EoP
Windows Admin Center
Information Disclosure Vulnerability
Important 6.5 No No Info
Windows Ancillary
Function Driver for WinSock Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Ancillary
Function Driver for WinSock Information Disclosure Vulnerability
Important 5.5 No No Info
Windows App Package
Installer Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Application
Model Core API Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Audio
Compression Manager (ACM) Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Audio Service
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Backup Service
Elevation of Privilege Vulnerability
Important 7.3 No No EoP
Windows Bluetooth
Service Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Client-Side
Caching Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Clipboard
Server Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Cloud Files
Mini Filter Driver Elevation of Privilege Vulnerability
Important 6.3 No No EoP
Windows Cloud Files
Mini Filter Driver Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Common Log
File System Driver Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Connected User
Experiences and Telemetry Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Cryptographic
Services Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Cryptography
API: Next Generation (CNG) Tampering Vulnerability
Important 7.1 No No Tampering
Windows DHCP Client
Elevation of Privilege Vulnerability
Important 7.5 No No EoP
Windows DHCP Server
Denial of Service Vulnerability
Important 7.5 No No DoS
Windows DirectX
Information Disclosure Vulnerability
Important 6.2 No No Info
Windows DNS Client
Elevation of Privilege Vulnerability
Important 8.1 No No EoP
Windows DNS Server
Remote Code Execution Vulnerability
Important 8 No No RCE
Windows Domain
Controller Denial of Service Vulnerability
Important 7.5 No No DoS
Windows DWM Core
Library Information Disclosure
Vulnerability
Important 5.5 No No Info
Windows Event Logging
Service Remote Code Execution Vulnerability
Important 8 No No RCE
Windows File Explorer
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows File Explorer
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows File Explorer
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows File Explorer
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Filtering
Platform Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows GDI Elevation
of Privilege Vulnerability
Important 7.8 No No EoP
Windows Graphics
Component Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Group Policy
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Hyper-V Denial
of Service Vulnerability
Important 4.5 No No DoS
Windows Image
Acquisition Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Installer
Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Internal
System User Profile Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Kernel
Elevation of Privilege Vulnerability
Important 4.7 No No EoP
Windows Kernel
Elevation of Privilege Vulnerability
Important 6.8 No No EoP
Windows Kernel
Elevation of Privilege Vulnerability
Important 9.3 No No EoP
Windows Kernel
Elevation of Privilege Vulnerability
Important 7.1 No No EoP
Windows Kernel
Elevation of Privilege Vulnerability
Important 5.5 No No EoP
Windows Kernel
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Kernel
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Kernel
Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Kernel
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Kernel
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Kernel
Information Disclosure Vulnerability
Important 6.2 No No Info
Windows Kernel
Information Disclosure Vulnerability
Important 3.3 No No Info
Windows Kernel
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Kernel
Security Feature Bypass Vulnerability
Important 5.5 No No SFB
Windows Kernel-Mode
Driver Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Kernel-Mode
Driver Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Key Guard
Security Feature Bypass Vulnerability
Important 5.5 No No SFB
Windows Local Security
Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Important 6.5 No No DoS
Windows Management
Services Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Media
Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Media
Elevation of Privilege Vulnerability
Important 8.8 No No EoP
Windows Media
Elevation of Privilege Vulnerability
Important 7.5 No No EoP
Windows Media
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Media
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Media
Information Disclosure Vulnerability
Important 5.3 No No Info
Windows Message
Queuing (MSMQ) Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Message
Queuing Service (MSMQ) Remote Code Execution Vulnerability
Important 7.5 No No RCE
Windows MIDI Service
Module Elevation of Privileges Vulnerability
Important 7 No No EoP
Windows Narrator
Braille Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Network
Connections Service Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Network File
System Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Network Policy
Server SNMP Information Disclosure Vulnerability
Important 7.5 No No Info
Windows NFS Server
Elevation of Privilege Vulnerability
Important 8.8 No No EoP
Windows Notification
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows NTFS Elevation
of Privilege Vulnerability
Important 7.8 No No EoP
Windows NTFS Elevation
of Privilege Vulnerability
Important 7 No No EoP
Windows NTFS Elevation
of Privilege Vulnerability
Important 7.8 No No EoP
Windows NTFS Remote
Code Execution Vulnerability
Important 7.3 No No RCE
Windows NTFS Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Windows NTFS Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Windows NTFS Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Windows NTFS Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Windows NTFS Remote
Code Execution Vulnerability
Important 7.8 No No RCE
Windows NTFS Remote
Code Execution Vulnerability
Important 7.3 No No RCE
Windows OLE Elevation
of Privilege Vulnerability
Important 7.8 No No EoP
Windows Operating
Systems Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Overlay Filter
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Overlay Filter
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Print
Configuration Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Print Spooler
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Print Spooler
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Push
Notification Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Push
Notification Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Push
Notifications Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Quality of
Service (QoS) Packet Scheduler Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Remote Access
Elevation of Privilege Vulnerability
Important 8.8 No No EoP
Windows Remote Desktop
Client Elevation of Privilege Vulnerability
Important 7.5 No No EoP
Windows Remote Desktop
Client Information Disclosure Vulnerability
Important 6.5 No No Info
Windows Remote Desktop
Client Information Disclosure Vulnerability
Important 6.5 No No Info
Windows Remote Desktop
Client Information Disclosure Vulnerability
Important 6.5 No No Info
Windows Remote Desktop
Protocol (RDP) Information Disclosure Vulnerability
Important 6.5 No No Info
Windows Remote Desktop
Protocol (RDP) Information Disclosure Vulnerability
Important 6.5 No No Info
Windows Remote Desktop
Protocol (RDP) Information Disclosure Vulnerability
Important 6.5 No No Info
Windows Remote Desktop
Services Remote Code Execution Vulnerability
Important 8.8 No No RCE
Windows Resilient File
System (ReFS) Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Resilient File
System (ReFS) Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Resilient File
System (ReFS) Elevation of Privilege Vulnerability
Important 6.8 No No EoP
Windows Resilient File
System (ReFS) Remote Code Execution Vulnerability
Important 7.8 No No RCE
Windows Resilient File
System (ReFS) Remote Code Execution Vulnerability
Important 7.8 No No RCE
Windows Resilient File
System (ReFS) Remote Code Execution Vulnerability
Important 7.8 No No RCE
Windows Routing and
Remote Access Service (RRAS) Elevation of Privilege Vulnerability
Important 7.1 No No EoP
Windows Routing and
Remote Access Service (RRAS) Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Runtime
Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Runtime
Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Runtime
Elevation of Privilege Vulnerability
Important 8.5 No No EoP
Windows Runtime
Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Runtime
Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Runtime
Elevation of Privilege Vulnerability
Important 8.8 No No EoP
Windows Runtime
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Runtime
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Search Service
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Secure Channel
Denial of Service Vulnerability
Important 5.3 No No DoS
Windows Secure Channel
Information Disclosure Vulnerability
Important 8.1 No No Info
Windows Sensor Data
Service Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Server Update
Service (WSUS) Tampering Vulnerability
Important 7.5 No No Tampering
Windows SMB
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows SMB
Information Disclosure Vulnerability
Important 5.5 No No Info
Windows SMB Server
Elevation of Privilege Vulnerability
Important 8.8 No No EoP
Windows Spaceport.sys
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Speech Runtime
Elevation of Privilege Vulnerability
Important 7.5 No No EoP
Windows Storage
Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Subsystem for
Linux (WSL2) Kernel Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows System Secure
Feature Bypass Vulnerability
Important 5.1 No No SFB
Windows TCP/IP
Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Telephony
Server Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows Trusted
Runtime Interface Driver Information Disclosure Vulnerability
Important 5.5 No No Info
Windows Universal Disk
Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Important 7.3 No No EoP
Windows Universal Plug
and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Important 5.5 No No EoP
Windows USB Audio
Class Driver Information Disclosure Vulnerability
Important 6.1 No No Info
Windows USB Driver
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows USB Print
Driver Elevation of Privilege Vulnerability
Important 6.4 No No EoP
Windows USB Print
Driver Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows USB Print
Driver Elevation of Privilege Vulnerability
Important 7 No No EoP
Windows USB Video
Driver Elevation of Privilege Vulnerability
Important 6.6 No No EoP
Windows WalletService
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Web Proxy
Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Win32 Kernel
Subsystem Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Win32k
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Win32k
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Win32k
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Win32k
Elevation of Privilege Vulnerability
Important 7.8 No No EoP
Windows Zero Trust DNS
Security Feature Bypass Vulnerability
Important 5.5 No No SFB
Microsoft Edge
(Chromium-based) Information Disclosure Vulnerability
Moderate 4.2 No No Info
Microsoft Edge
(Chromium-based) Spoofing Vulnerability
Moderate 6.5 No No Spoofing
Windows Network
Address Translation (NAT) Spoofing Vulnerability
Moderate 8.3 No No Spoofing
CVE-2026-58597 Microsoft
Edge (Chromium-based) Spoofing Vulnerability
Low 4.3 No No Spoofing




















** Indicates this CVEs has already been resolved by Microsoft, and no further action is needed by the end user.

 

 

I’ll do my best to summarize everything else in this release, but no promises. I’m only human after all.

 

Looking at the remaining Critical-rated patches, Office is its own weather system: fourteen Word/Excel/PowerPoint/Office RCEs clustered at CVSS 7.8, plus five Windows Media Foundation RCEs. Outside of the Preview Pane attack vector, they are individually unremarkable; collectively, patch Office and reboot. Always reboot. We’ve already mentioned DHCP some, but DHCP Server can't catch a break. Beyond the one already covered, add CVE-2026-56159, CVE-2026-48564, CVE-2026-50370, and DHCP Client cousin CVE-2026-54128. Five DHCP RCEs in one release. Rounding things out, Print Spooler (CVE-2026-58608), Windows TCP/IP (CVE-2026-54999), and a SQL Server RCE pair (CVE-2026-54117/54118) all receive patches, and all are rated a CVSS 8.8. VE-2026-55944 (Dynamics NAV/Business Central On-Prem RCE, 9.8) is the same deserialization flavor as the SharePoint pair; it’s unauthenticated, network-reachable, and easy to overlook since it's not SharePoint. CVE-2026-48561 (Microsoft Copilot RCE, 9.6) and CVE-2026-50380 (Windows GDI+ RCE, 9.6) round out the near-top tier. Don't forget CVE-2026-55040, a SharePoint Security Feature Bypass (9.1) — patch it in the same pass as the SharePoint RCE pair since it's the same product family. Identity and infrastructure get hit too: CVE-2026-54121 (AD Certificate Services EoP, 8.8) and CVE-2026-50444 (WSUS EoP, 8.8). The obscure Reliable Multicast Transport Driver (RMCAST) takes two RCEs (CVE-2026-54982, CVE-2026-54995), and CVE-2026-50474 gives Remote Desktop Client its own RCE, separate from the RDP one already covered. The rest is a long tail: Defender RCE x2, GDI+ again, Windows Media x2, Secure Kernel Mode EoP x2, and a second Hyper-V EoP. You can consider these “normal” as far as patch cadence goes.

That leaves us with 95 RCE to discuss. I would explain, but there is too much, so let me sum up. CVE-2026-55944 (Dynamics NAV/Business Central On-Prem, 9.8) is the same deserialization flavor as the SharePoint pair: unauthenticated, easy to miss since it's not SharePoint. CVE-2026-54990 (Remote Desktop Client), CVE-2026-49172 (Windows FTP Service), and CVE-2026-50447 (MSMQ) all hit 9.8 too, proof severity labels lag CVSS sometimes. CVE-2026-48561 (Copilot) and CVE-2026-50380 (GDI+) sit at 9.6.

The pattern worth watching: 14 Windows NTFS and 7 ReFS RCEs/ That makes 21 filesystem-driver bugs, an unusually large cluster suggesting a shared root cause. Microsoft Edge (Chromium-based) contributes 21 more that are genuinely Microsoft's to patch, not Chromium re-listing noise. Remote Desktop Client racks up a second and third RCE (CVE-2026-50474, CVE-2026-58594), and Windows Admin Center picks up two (CVE-2026-56196/56197) — WAC exposure keeps creeping into these releases. Exchange Server (CVE-2026-55005) and AD Domain Services (CVE-2026-49178) both land at 8.8.

And because this release wouldn't be complete without it: CVE-2026-50663, an RCE in Age of Empires II: Definitive Edition. Yes, really. Patch your civilization anyway.

There are close to 260 EoP bugs in this month’s release. Microsoft could have just published the EoPs and still had a record-setting month. As usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. What’s really frustrating is that 94 have no explicit privilege statement at all. Microsoft just says “elevate privileges” with no detail. By my count, that leaves around 25 bugs to consider. Some don’t elevate at all. The FAQ literally says the attacker just gets “the rights of the user running the affected application.” That covers Win32k, Clip Service, Search Service, MSMQ, and SharePoint. A few get a Low-to-Medium integrity bump. There are also a couple that lead to downgraded service accounts or arbitrary file deletion, but nothing else I’ve seen really stands out too much.

There are 20 Security Feature Bypass (SFB) bugs this month, and it's a genuinely mixed bag. CVE-2026-55040 leads at Critical, CVSS 9.1 as it’s weak authentication in SharePoint Server. Patch it in the same pass as the SharePoint RCE pair since it's the same product. The AI-coding-tool trend continues: GitHub Copilot and Visual Studio Code and Visual Studio all land SFB bugs, mostly injection or path-traversal flavored. BitLocker is this month's lone publicly disclosed bug. It’s not exploited yet, but public disclosure is a countdown clock, not a free pass. It requires physical access, as does the bug in Microsoft XML. The firmware/boot cluster is worth a second look: Secure Boot, Boot Loader, and Key Guard all touch the trust chain below the OS. Meaning, despite a low CVSS score, “if this fails, nothing above it can be trusted” stakes. Rounding out the SFB patches, there are two .NET SFBs, two Windows Kernel SFBs, and a DNS/Cryptographic Services bringing up the rear.

The July release includes 31Spoofing bugs this month, and we’ve already covered the most important (Exchange). SharePoint Server accounts for another ten with almost all the same root cause: stored XSS letting an authenticated attacker spoof content in the browser. Microsoft Edge (Chromium-based) contributes fifteen more spanning access-control failures, SSRF, type confusion, and UI misrepresentation. All genuinely Microsoft's to patch, not re-listed Chromium noise. The remaining six round out the usual suspects: a Windows NAT spoofing bug reachable from an adjacent network, a Bing app flaw on iOS, a PowerBI Report Server XSS issue, a .NET output-encoding bug, and an AD FS spoofing flaw. None publicly disclosed, none exploited, but with SharePoint's history this year, don't let "just Spoofing" lull you into deprioritizing the patch cycle.

Of 111 Information Disclosure bugs, the overwhelming majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. GitHub Copilot is the standout. Here, the bug insufficiently protected credentials, meaning actual secrets leak, not memory scraps. The Windows Admin Center flaw discloses data via improper authentication. A management console leaking to an unauthorized party is a bigger deal than it sounds. SharePoint uses SSRF to pull data server-side, and the Event Logging Service is a protection-mechanism failure, not a memory bug at all. Edge picks up three genuinely file-system-flavored disclosures — improper authorization, files/directories accessible to external parties, and link-following — plus Edge for Android exposing “private personal information” twice and two path-traversal bugs. The remaining 40+ are mostly one-line “exposure of sensitive information to an unauthorized actor” entries scattered across File Explorer, Push Notifications, Cryptographic Services, and Win32k.

Only 8 Tampering bugs this month, the smallest bucket, but a couple stand out. The top of the list is a WSUS bug, caused by an uncaught exception that lets an unauthenticated attacker tamper with the update service over the network. That’s your patch-management infrastructure itself being the target, which always deserves extra attention. Windows CNG (the crypto API) picks up a missing-cryptographic-step flaw, and Windows DNS Client shows up three separate times across the list, twice for improper access control and once for missing authentication on a critical function. DNS resolution having this many tampering paths in one release is worth flagging as a pattern rather than three unrelated bugs. The one genuinely different entry is Outlook Copilot, described simply as vulnerable to “malicious uses” enabling tampering over the network. That’s a fantastically vague phrasing for an AI-assistant feature, continuing this year's running theme of Copilot-branded features showing up somewhere in every release. Finally, a .NET link-following bug and a WSL2 kernel race condition receive patches. Both require local/authorized access to trigger.

Still with me? Good, because we have 35 DoS bugs to cover, and this is really an identity-infrastructure story more than a grab-bag. Active Directory Federation Services alone accounts for seven of them, all sitting at CVSS 7.5, all stack-based buffer overflows or infinite loops that let an unauthenticated attacker knock the service over the network. The .NET ecosystem is the other big cluster: .NET, .NET Framework, and ASP.NET Core/OData contribute nine bugs combined, almost all “allocation of resources without limits or throttling”.  HTTP.sys and HTTP/2 pick up the same flavor. LSASS shows up twice, which is always worth a second look given what that process actually holds. Rounding out the list are patches for Windows DHCP Server, SMB Server, Secure Channel, Hyper-V, and IKE Protocol each take a single hit, mostly requiring authorized or adjacent-network access rather than being wide open to the internet.

No new advisories are being released this month.

Looking Ahead

The next Patch Tuesday will be on August 11, just after Hacker Summer Camp in sunny Las Vegas. Should I survive the heat, I’ll be back then to give you my full thoughts on the release – no matter how large it may be. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf thezdi.com.
↗ Original-Artikel auf thezdi.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Hackers Just Poisoned the Rust Supply Chain | Threat Wire
1 Quelle
Hackers Found a Way Into Humanoid Robots | Threat Wire
1 Quelle
Bits und so #1021 (Passwort für Laufwerk)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten The July 2026 Security Update Review

Thematisch verwandte Begriffe: July, 2026, Security, Update · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...