Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here. Excellent call. Take an extended break from your regularly scheduled activities as we let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for July 2026
Adobe has now moved to a bimonthly release schedule, which means they will be releasing patches on the second and fourth Tuesdays of the month. I’ll continue to cover the second Tuesday release here and update this blog should the fourth Tuesday release contain anything significant. I think this is a smart way to break up a monster release into something a bit more manageable. Apple has said they are taking a similar approach. We’ll see if other vendors follow their lead.
For the first part of the July release, Adobe released 12 bulletins addressing 88 unique CVEs in Adobe ColdFusion, Commerce, After Effects, Animate, Audition, Bridge, Creative Cloud Desktop Application, Experience Manager, Illustrator, Media Encoder, Premiere Pro, and the Content Credentials SDK.
Here’s this month’s overview table:
| Bulletin ID | Product | CVE Count | Highest Severity | Highest CVSS | Exploited | Deployment Priority |
|---|---|---|---|---|---|---|
| Adobe Commerce | 13 | Critical | 9.6 | No | 2 | |
| Adobe Animate | 6 | Critical | 8.6 | No | 3 | |
| Adobe Bridge | 6 | Critical | 7.8 | No | 3 | |
| Adobe Experience Manager | 13 | Critical | 9.6 | No | 3 | |
| Adobe Media Encoder | 5 | Critical | 7.8 | No | 3 | |
| Content Credentials SDK | 12 | Critical | 8.2 | No | 3 | |
| TOTAL | 12 bulletins | 88 |
While nothing is under active exploit, I would prioritize the Cold Fusion and Commerce patches first. The patch for Cold Fusion even clocks in with a CVSS 9.9 bug. Beyond that, most of these updates are pretty straightforward. If you’re using these products, patch them. However, you can use you regular patch cadence here.
Microsoft Patches for July 2026
Here it is. The Mother of All Releases. To call this record-breaking is an understatement. How to count this mess is anyone’s guess, but I see new Microsoft 621 CVEs for the month of July. Some of these are in online services where no user action is required. They also list about 480 bugs in Chromium and Microsoft Edge (Chromium-based) that I won’t cover here. Here’s how I put this in context. I looked at the last 20 years of Microsoft releases. The CVE count year-to-date exceeds all other years’ totals.

The products covered this month are also astonishing. There are patches for Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Ages of Empire II, and Minecraft Server (really!). That phrase “Windows components” does some pretty heavy lifting here, too, as just about everything you’ve ever heard of is getting patched. All told, there are 63 rated Critical, six rated Moderate, one rated Low, with the rest rated Important in severity. Eight of these bugs were submitted through the ZDI program (more on that later). Two CVEs are listed as under active exploit while one other is listed as publicly known.
So how do we eat this elephant? One byte at a time (pun intended). Let’s start by looking a closer look at some of the more interesting updates for this month, starting with the bugs being exploited in the wild.
- - Microsoft SharePoint Server Elevation of Privilege Vulnerability
The other bug being exploited in the wild this month is a modest CVSS 5.3 – but it shows why Moderate severity bugs still matter. It's a missing-authentication flaw, meaning an unauthenticated attacker can hit it over the network with no user interaction required. When something this reachable is being actively abused, patch it now and worry about the score later.
- /, so it’s odd to see Microsoft list it as “Exploit Maturity Unknown” since we literally handed them a working exploit. Just another reason to do your own risk assessment and not rely 100% on the vendor. If you have any Internet accessible SharePoint servers, test and deploy this patch quickly.
- - Microsoft Exchange Server Spoofing Vulnerability
Ignore the title here and treat this like the XSS bug it is. The vulnerability is listed as a CVSS 9.6 since it’s a stored cross-site scripting flaw in Outlook Web Access, with a scope-changed impact that lets it break out of the web app context entirely. An attacker sends a specially crafted email, and if the victim simply opens it in OWA, arbitrary JavaScript executes in their browser session — no attachment needed, no macro warning, just viewing the message does it. If you’re using OWA, test and deploy this one quickly.
- - Windows Server Network driver Remote Code Execution Vulnerability
Another Critical-rated bug, this one is caused by a race condition. It’s always fun to see a TOCTOU bug rated this high, since race conditions are notoriously finicky to exploit reliably. While it may prove tricky to exploit, this bug could allow an attacker to execute privileged code over the network without user interaction. Don’t let the race condition lull you to sleep on a wormable bug.
-
Federation Services Elevation of Privilege Vulnerability
Security Feature Bypass Vulnerability
of Privilege Vulnerability
Remote Code Execution Vulnerability
Kernel Remote Code Execution Vulnerability
Synapse Elevation of Privilege Vulnerability
Remote Code Execution Vulnerability
and Microsoft Dynamics 365 Business Central (On Premises) Remote Code
Execution Vulnerability
Code Execution Vulnerability
Server Spoofing Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Server Security Feature Bypass Vulnerability
Remote Code Execution Vulnerability
Media Foundation Remote Code Execution Vulnerability
Media Foundation Remote Code Execution Vulnerability
VMSwitch Elevation of Privilege Vulnerability
Code Execution Vulnerability
Dedicated Server Remote Code Execution Vulnerability
Directory Domain Services Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Code Execution Vulnerability
Elevation of Privilege Vulnerability
Code Execution Vulnerability
Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Mode Elevation of Privilege Vulnerability
Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Service (WSUS) Elevation of Privilege Vulnerability
Vulnerability
Vulnerability
of Service Vulnerability
of Service Vulnerability
Code Execution Vulnerability
Bypass Vulnerability
Vulnerability
Denial of Service Vulnerability
Federation Server Denial of Service Vulnerability
Service Vulnerability
of Privilege Vulnerability
Denial of Service Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
(ci.dll) Elevation of Privilege Vulnerability
Manager Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Kernel Elevation of Privilege Vulnerability
Kernel Elevation of Privilege Vulnerability
Kernel Elevation of Privilege Vulnerability
Kernel Elevation of Privilege Vulnerability
Vulnerability
II: Definitive Edition Remote Code Execution Vulnerability
Visual Studio Code Security Feature Bypass Vulnerability
Service Vulnerability
Service Vulnerability
Elevation of Privilege Vulnerability
File System Elevation of Privilege Vulnerability
File System Elevation of Privilege Vulnerability
File System Elevation of Privilege Vulnerability
Endpoint for Mac Elevation of Privilege Vulnerability
Library Elevation of Privilege Vulnerability
(Chromium-based) Elevation of Privilege Vulnerability
(Chromium-based) Information Disclosure Vulnerability
(Chromium-based) Remote Code Execution Vulnerability
(Chromium-based) Remote Code Execution Vulnerability
(Chromium-based) Remote Code Execution Vulnerability
(Chromium-based) Remote Code Execution Vulnerability
(Chromium-based) Remote Code Execution Vulnerability
(Chromium-based) Remote Code Execution Vulnerability
(Chromium-based) Remote Code Execution Vulnerability
(Chromium-based) Remote Code Execution Vulnerability
(Chromium-based) Remote Code Execution Vulnerability
(Chromium-based) Remote Code Execution Vulnerability
(Chromium-based) Security Feature Bypass Vulnerability
(Chromium-based) Spoofing Vulnerability
(Chromium-based) Spoofing Vulnerability
(Chromium-based) Spoofing Vulnerability
(Chromium-based) Spoofing Vulnerability
(Chromium-based) Spoofing Vulnerability
Android Information Disclosure Vulnerability
Android Information Disclosure Vulnerability
Android Remote Code Execution Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Server Elevation of Privilege Vulnerability
Warehouse Remote Code Execution Vulnerability
Queuing Queue Manager Remote Code Execution Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Remote Code Execution Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Server Information Disclosure Vulnerability
Server Spoofing Vulnerability
Server Spoofing Vulnerability
Server Spoofing Vulnerability
Server Spoofing Vulnerability
Server Spoofing Vulnerability
Elevation of Privilege Vulnerability
Information Disclosure Vulnerability
Store Elevation of Privilege Vulnerability
Store Elevation of Privilege Vulnerability
Media Foundation Remote Code Execution Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Feature Bypass Vulnerability
Privilege Vulnerability
ASP.NET Core Denial of Service Vulnerability
Management service/API (RPC server) Elevation of Privilege Vulnerability
Remote Code Execution Vulnerability
Feature Bypass Vulnerability
Elevation of Privilege Vulnerability
Play (upnp.dll) Information Disclosure Vulnerability
Management Service Elevation of Privilege Vulnerability
(VHD) Miniport Driver Elevation of Privilege Vulernability
Security Feature Bypass Vulnerability
Security Feature Bypass Vulnerability
Privilege Vulnerability
Privilege Vulnerability
Privilege Vulnerability
Disclosure Vulnerability
Directory Denial of Service Vulnerability
Directory Domain Services Denial of Service Vulnerability
Directory Federation Services (ADFS) Information Disclosure Vulnerability
Directory Federation Services Denial of Service Vulnerability
Directory Federation Services Denial of Service Vulnerability
Directory Federation Services Denial of Service Vulnerability
(WAC) Remote Code Execution Vulnerability
(WAC) Remote Code Execution Vulnerability
Elevation of Privilege Vulnerability
Function Driver for WinSock Elevation of Privilege Vulnerability
Function Driver for WinSock Elevation of Privilege Vulnerability
Installer Elevation of Privilege Vulnerability
Installer Elevation of Privilege Vulnerability
Deployment Extensions Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Driver Remote Code Execution
Security Feature Bypass Vulnerability
Elevation of Privilege Vulnerability
Server Elevation of Privilege Vulnerability
Mini Filter Driver Elevation of Privilege Vulnerability
Mini Filter Driver Information Disclosure Vulnerability
File System Driver Elevation of Privilege Vulnerability
Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability
Services Security Feature Bypass Vulnerability
Remote Code Execution Vulnerability
Elevation of Privilege Vulnerability
Remote Code Execution Vulnerability
Elevation of Privilege Vulnerability
Tampering Vulnerability
Remote Code Execution Vulnerability
Library Information Disclosure
Vulnerability
Service Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Service Elevation of Privilege Vulnerability
Remote Code Execution Vulnerability
Code Execution Vulnerability
Component Remote Code Execution Vulnerability
Interface Device Information Disclosure Vulnerability
Elevation of Privilege Vulnerability
Editor (IME) Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Bar Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Information Disclosure Vulnerability
Security Feature Bypass Vulnerability
Driver Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Virtualization Filter Driver Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Information Disclosure Vulnerability
Codec Information Disclosure Vulnerability
Queuing Service (MSMQ) Remote Code Execution Vulnerability
Module Elevation of Privileges Vulnerability
Module Elevation of Privileges Vulnerability
Elevation of Privilege Vulnerability
Connections Service Elevation of Privilege Vulnerability
System Remote Code Execution Vulnerability
Server SNMP Information Disclosure Vulnerability
Elevation of Privilege Vulnerability
of Privilege Vulnerability
of Privilege Vulnerability
of Privilege Vulnerability
Information Disclosure Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Code Execution Vulnerability
Systems Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Remote Code Execution Vulnerability
Configuration Elevation of Privilege Vulnerability
Information Disclosure Vulnerability
System Elevation of Privilege Vulnerability
Notification Information Disclosure Vulnerability
Notification Information Disclosure Vulnerability
Notifications Elevation of Privilege Vulnerability
Drive Buffering System Elevation of Privilege Vulnerability
Service Infrastructure Elevation of Privilege Vulnerability
Client Information Disclosure Vulnerability
Client Information Disclosure Vulnerability
Client Information Disclosure Vulnerability
Protocol (RDP) Information Disclosure Vulnerability
Protocol (RDP) Information Disclosure Vulnerability
Protocol (RDP) Information Disclosure Vulnerability
Services Elevation of Privilege Vulnerability
Defense Elevation of Privilege Vulnerability
System (ReFS) Elevation of Privilege Vulnerability
System (ReFS) Elevation of Privilege Vulnerability
System (ReFS) Remote Code Execution Vulnerability
System (ReFS) Remote Code Execution Vulnerability
System (ReFS) Remote Code Execution Vulnerability
System (ReFS) Remote Code Execution Vulnerability
Remote Access Service (RRAS) Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Information Disclosure Vulnerability
Service Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
of Privilege Vulnerability
Information Disclosure Vulnerability
Denial of Service Vulnerability
Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability
Elevation of Privilege Vulnerability
StateRepository API Server file Elevation of Privilege Vulnerability
Direct Remote Code Execution Vulnerability
Linux (WSL2) Kernel Tampering Vulnerability
Elevation of Privilege Vulnerability
Information Disclosure Vulnerability
Remote Code Execution Vulnerability
Consent System Elevation of Privilege Vulnerability
Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Class Driver Information Disclosure Vulnerability
Class Driver Information Disclosure Vulnerability
Elevation of Privilege Vulnerability
Driver Elevation of Privilege Vulnerability
Driver Elevation of Privilege Vulnerability
Driver Elevation of Privilege Vulnerability
Core Elevation of Privilege Vulnerability
Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Elevation of Privilege Vulnerability
Network Manager Elevation of Privilege Vulnerability
Network Service (WwanSvc) Elevation of Privilege Vulnerability
(Chromium-based) Spoofing Vulnerability
Tampering Vulnerability
Edge (Chromium-based) Spoofing Vulnerability
<![if supportMisalignedColumns]>
<![endif]>
** Indicates this CVEs has already been resolved by Microsoft, and no further action is needed by the end user.
I’ll do my best to summarize everything else in this release, but no promises. I’m only human after all.
Looking at the remaining Critical-rated patches, Office is its own weather system: fourteen Word/Excel/PowerPoint/Office RCEs clustered at CVSS 7.8, plus five Windows Media Foundation RCEs. Outside of the Preview Pane attack vector, they are individually unremarkable; collectively, patch Office and reboot. Always reboot. We’ve already mentioned DHCP some, but DHCP Server can't catch a break. Beyond the one already covered, add CVE-2026-56159, CVE-2026-48564, CVE-2026-50370, and DHCP Client cousin CVE-2026-54128. Five DHCP RCEs in one release. Rounding things out, Print Spooler (CVE-2026-58608), Windows TCP/IP (CVE-2026-54999), and a SQL Server RCE pair (CVE-2026-54117/54118) all receive patches, and all are rated a CVSS 8.8. VE-2026-55944 (Dynamics NAV/Business Central On-Prem RCE, 9.8) is the same deserialization flavor as the SharePoint pair; it’s unauthenticated, network-reachable, and easy to overlook since it's not SharePoint. CVE-2026-48561 (Microsoft Copilot RCE, 9.6) and CVE-2026-50380 (Windows GDI+ RCE, 9.6) round out the near-top tier. Don't forget CVE-2026-55040, a SharePoint Security Feature Bypass (9.1) — patch it in the same pass as the SharePoint RCE pair since it's the same product family. Identity and infrastructure get hit too: CVE-2026-54121 (AD Certificate Services EoP, 8.8) and CVE-2026-50444 (WSUS EoP, 8.8). The obscure Reliable Multicast Transport Driver (RMCAST) takes two RCEs (CVE-2026-54982, CVE-2026-54995), and CVE-2026-50474 gives Remote Desktop Client its own RCE, separate from the RDP one already covered. The rest is a long tail: Defender RCE x2, GDI+ again, Windows Media x2, Secure Kernel Mode EoP x2, and a second Hyper-V EoP. You can consider these “normal” as far as patch cadence goes.
That leaves us with 95 RCE to discuss. I would explain, but there is too much, so let me sum up. CVE-2026-55944 (Dynamics NAV/Business Central On-Prem, 9.8) is the same deserialization flavor as the SharePoint pair: unauthenticated, easy to miss since it's not SharePoint. CVE-2026-54990 (Remote Desktop Client), CVE-2026-49172 (Windows FTP Service), and CVE-2026-50447 (MSMQ) all hit 9.8 too, proof severity labels lag CVSS sometimes. CVE-2026-48561 (Copilot) and CVE-2026-50380 (GDI+) sit at 9.6.
The pattern worth watching: 14 Windows NTFS and 7 ReFS RCEs/ That makes 21 filesystem-driver bugs, an unusually large cluster suggesting a shared root cause. Microsoft Edge (Chromium-based) contributes 21 more that are genuinely Microsoft's to patch, not Chromium re-listing noise. Remote Desktop Client racks up a second and third RCE (CVE-2026-50474, CVE-2026-58594), and Windows Admin Center picks up two (CVE-2026-56196/56197) — WAC exposure keeps creeping into these releases. Exchange Server (CVE-2026-55005) and AD Domain Services (CVE-2026-49178) both land at 8.8.
And because this release wouldn't be complete without it: CVE-2026-50663, an RCE in Age of Empires II: Definitive Edition. Yes, really. Patch your civilization anyway.
There are close to 260 EoP bugs in this month’s release. Microsoft could have just published the EoPs and still had a record-setting month. As usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. What’s really frustrating is that 94 have no explicit privilege statement at all. Microsoft just says “elevate privileges” with no detail. By my count, that leaves around 25 bugs to consider. Some don’t elevate at all. The FAQ literally says the attacker just gets “the rights of the user running the affected application.” That covers Win32k, Clip Service, Search Service, MSMQ, and SharePoint. A few get a Low-to-Medium integrity bump. There are also a couple that lead to downgraded service accounts or arbitrary file deletion, but nothing else I’ve seen really stands out too much.
There are 20 Security Feature Bypass (SFB) bugs this month, and it's a genuinely mixed bag. CVE-2026-55040 leads at Critical, CVSS 9.1 as it’s weak authentication in SharePoint Server. Patch it in the same pass as the SharePoint RCE pair since it's the same product. The AI-coding-tool trend continues: GitHub Copilot and Visual Studio Code and Visual Studio all land SFB bugs, mostly injection or path-traversal flavored. BitLocker is this month's lone publicly disclosed bug. It’s not exploited yet, but public disclosure is a countdown clock, not a free pass. It requires physical access, as does the bug in Microsoft XML. The firmware/boot cluster is worth a second look: Secure Boot, Boot Loader, and Key Guard all touch the trust chain below the OS. Meaning, despite a low CVSS score, “if this fails, nothing above it can be trusted” stakes. Rounding out the SFB patches, there are two .NET SFBs, two Windows Kernel SFBs, and a DNS/Cryptographic Services bringing up the rear.
The July release includes 31Spoofing bugs this month, and we’ve already covered the most important (Exchange). SharePoint Server accounts for another ten with almost all the same root cause: stored XSS letting an authenticated attacker spoof content in the browser. Microsoft Edge (Chromium-based) contributes fifteen more spanning access-control failures, SSRF, type confusion, and UI misrepresentation. All genuinely Microsoft's to patch, not re-listed Chromium noise. The remaining six round out the usual suspects: a Windows NAT spoofing bug reachable from an adjacent network, a Bing app flaw on iOS, a PowerBI Report Server XSS issue, a .NET output-encoding bug, and an AD FS spoofing flaw. None publicly disclosed, none exploited, but with SharePoint's history this year, don't let "just Spoofing" lull you into deprioritizing the patch cycle.
Of 111 Information Disclosure bugs, the overwhelming majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. GitHub Copilot is the standout. Here, the bug insufficiently protected credentials, meaning actual secrets leak, not memory scraps. The Windows Admin Center flaw discloses data via improper authentication. A management console leaking to an unauthorized party is a bigger deal than it sounds. SharePoint uses SSRF to pull data server-side, and the Event Logging Service is a protection-mechanism failure, not a memory bug at all. Edge picks up three genuinely file-system-flavored disclosures — improper authorization, files/directories accessible to external parties, and link-following — plus Edge for Android exposing “private personal information” twice and two path-traversal bugs. The remaining 40+ are mostly one-line “exposure of sensitive information to an unauthorized actor” entries scattered across File Explorer, Push Notifications, Cryptographic Services, and Win32k.
Only 8 Tampering bugs this month, the smallest bucket, but a couple stand out. The top of the list is a WSUS bug, caused by an uncaught exception that lets an unauthenticated attacker tamper with the update service over the network. That’s your patch-management infrastructure itself being the target, which always deserves extra attention. Windows CNG (the crypto API) picks up a missing-cryptographic-step flaw, and Windows DNS Client shows up three separate times across the list, twice for improper access control and once for missing authentication on a critical function. DNS resolution having this many tampering paths in one release is worth flagging as a pattern rather than three unrelated bugs. The one genuinely different entry is Outlook Copilot, described simply as vulnerable to “malicious uses” enabling tampering over the network. That’s a fantastically vague phrasing for an AI-assistant feature, continuing this year's running theme of Copilot-branded features showing up somewhere in every release. Finally, a .NET link-following bug and a WSL2 kernel race condition receive patches. Both require local/authorized access to trigger.
Still with me? Good, because we have 35 DoS bugs to cover, and this is really an identity-infrastructure story more than a grab-bag. Active Directory Federation Services alone accounts for seven of them, all sitting at CVSS 7.5, all stack-based buffer overflows or infinite loops that let an unauthenticated attacker knock the service over the network. The .NET ecosystem is the other big cluster: .NET, .NET Framework, and ASP.NET Core/OData contribute nine bugs combined, almost all “allocation of resources without limits or throttling”. HTTP.sys and HTTP/2 pick up the same flavor. LSASS shows up twice, which is always worth a second look given what that process actually holds. Rounding out the list are patches for Windows DHCP Server, SMB Server, Secure Channel, Hyper-V, and IKE Protocol each take a single hit, mostly requiring authorized or adjacent-network access rather than being wide open to the internet.
No new advisories are being released this month.
Looking Ahead
The next Patch Tuesday will be on August 11, just after Hacker Summer Camp in sunny Las Vegas. Should I survive the heat, I’ll be back then to give you my full thoughts on the release – no matter how large it may be. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!
SOCIAL SHARE CARD GENERATOR