Today’s Patch Tuesday Alert addresses Microsoft’s July 2026 Security Updates. The FIRE team is actively working on coverage for these vulnerabilities and expect to ship that coverage as soon as it is completed.
In-the-Wild & Disclosed CVEs
A vulnerability in SharePoint could allow for an unauthenticated user to execute code due to deserialization of untrusted data. Microsoft has reported this vulnerability as Exploitation Detected.
A vulnerability in SharePoint could allow unauthorized attackers to elevate permissions due to missing authentication requirements. Microsoft has reported this vulnerability as Exploitation Detected.
A vulnerability in the Active Directory Federation Services (AD FS) could allow for privilege escalation, ultimately gaining Administrator permissions. Microsoft has reported this vulnerability as Exploitation Detected.
Successful exploitation of this BitLocker vulnerability could allow an attacker to bypass BitLocker encryption on a storage device. The attacker would require physical access to the device. Microsoft has reported this vulnerability as Exploitation Less Likely.
CVE Breakdown by Tag
While historical Microsoft Security Bulletin groupings are gone, Microsoft vulnerabilities are tagged with an identifier. This list provides a breakdown of the CVEs on a per tag basis. Vulnerabilities are also colour coded to aid with identifying key issues.
- Traditional Software
- Mobile Software
- Cloud or Cloud Adjacent
- Vulnerabilities that are being exploited or that have been disclosed will be highlighted
| Tag | CVE Count | CVEs |
| Microsoft Copilot | 1 | CVE-2026-48561 |
| Windows Secure Kernel Mode | 2 | CVE-2026-42982, CVE-2026-50392 |
| SQL Server | 7 | CVE-2026-47296, CVE-2026-54117, CVE-2026-54118, CVE-2026-55002, CVE-2026-47295, CVE-2026-50468, CVE-2026-54116 |
| Azure Synapse | 1 | CVE-2026-26145 |
| Azure OpenAI | 1 | CVE-2026-45499 |
| Microsoft Entra Provisioning Service (SyncFabric) | 1 | CVE-2026-57100 |
| Microsoft Exchange Online | 1 | CVE-2026-54998 |
| M365 Copilot | 1 | CVE-2026-41106 |
| Windows Terminal | 2 | CVE-2026-59117, CVE-2026-54124 |
| Windows Media | 15 | CVE-2026-34349, CVE-2026-50327, CVE-2026-50404, CVE-2026-50358, CVE-2026-50336, CVE-2026-50398, CVE-2026-50414, CVE-2026-50379, CVE-2026-50433, CVE-2026-50394, CVE-2026-50415, CVE-2026-50655, CVE-2026-50676, CVE-2026-50677, CVE-2026-58542 |
| Windows Ancillary Function Driver for WinSock | 4 | CVE-2026-34346, CVE-2026-50312, CVE-2026-50462, CVE-2026-57093 |
| Microsoft Windows App Store | 4 | CVE-2026-42900, CVE-2026-49165, CVE-2026-49784, CVE-2026-50356 |
| Windows Bluetooth Port Driver | 1 | CVE-2026-42975 |
| ASP.NET Core | 5 | CVE-2026-47300, CVE-2026-47303, CVE-2026-50506, CVE-2026-56170, CVE-2026-45646 |
| .NET | 8 | CVE-2026-47302, CVE-2026-47304, CVE-2026-50525, CVE-2026-50526, CVE-2026-50528, CVE-2026-50649, CVE-2026-50651, CVE-2026-50659 |
| SQL Server ODBC driver | 1 | CVE-2026-42990 |
| Windows App Installer | 3 | CVE-2026-48572, CVE-2026-48571, CVE-2026-50400 |
| Windows Brokering File System | 5 | CVE-2026-49162, CVE-2026-50305, CVE-2026-50361, CVE-2026-50466, CVE-2026-50458 |
| Active Directory Domain Services | 4 | CVE-2026-49164, CVE-2026-57976, CVE-2026-49178, CVE-2026-50366 |
| Microsoft Printer Drivers | 2 | CVE-2026-49166, CVE-2026-55004 |
| Windows Kernel | 35 | CVE-2026-49167, CVE-2026-49173, CVE-2026-54132, CVE-2026-58614, CVE-2026-49795, CVE-2026-49798, CVE-2026-50294, CVE-2026-49808, CVE-2026-50316, CVE-2026-50354, CVE-2026-50300, CVE-2026-50332, CVE-2026-50329, CVE-2026-50419, CVE-2026-50377, CVE-2026-50390, CVE-2026-50463, CVE-2026-50423, CVE-2026-50397, CVE-2026-50436, CVE-2026-50399, CVE-2026-50475, CVE-2026-50429, CVE-2026-50459, CVE-2026-50477, CVE-2026-50478, CVE-2026-50484, CVE-2026-50670, CVE-2026-50673, CVE-2026-50688, CVE-2026-50687, CVE-2026-56643, CVE-2026-56644, CVE-2026-58532, CVE-2026-58545 |
| Windows Storage Spaces Direct | 2 | CVE-2026-49168, CVE-2026-50299 |
| Role: DNS Server | 2 | CVE-2026-49169, CVE-2026-50426 |
| Windows StateRepository API | 1 | CVE-2026-49170 |
| Microsoft Windows Speech | 1 | CVE-2026-49171 |
| Windows WalletService | 1 | CVE-2026-49176 |
| Windows DNS | 6 | CVE-2026-49175, CVE-2026-49174, CVE-2026-50295, CVE-2026-50465, CVE-2026-50495, CVE-2026-50487 |
| Windows FTP Service | 1 | CVE-2026-49172 |
| Windows TCP/IP | 4 | CVE-2026-49177, CVE-2026-54999, CVE-2026-50306, CVE-2026-50307 |
| GitHub Copilot and Visual Studio Code | 1 | CVE-2026-47282 |
| Visual Studio Code | 4 | CVE-2026-45496, CVE-2026-50520, CVE-2026-57101, CVE-2026-57102 |
| Age of Empires II: Definitive Edition Game | 1 | CVE-2026-50663 |
| Active Directory Federation Services (AD FS) | 11 | CVE-2026-54983, CVE-2026-50695, CVE-2026-56155, CVE-2026-50304, CVE-2026-50368, CVE-2026-50324, CVE-2026-50355, CVE-2026-50411, CVE-2026-50647, CVE-2026-50684, CVE-2026-58529 |
| Windows Hyper-V | 4 | CVE-2026-54129, CVE-2026-54127, CVE-2026-50485, CVE-2026-50680 |
| Quality Windows Audio/Video Experience (QWAVE) service | 1 | CVE-2026-54989 |
| Windows Overlay Filter | 3 | CVE-2026-54987, CVE-2026-50435, CVE-2026-50409 |
| Windows Internet Key Exchange (IKE) Protocol | 1 | CVE-2026-50696 |
| Remote Desktop Client | 4 | CVE-2026-54990, CVE-2026-50330, CVE-2026-50474, CVE-2026-50504 |
| Windows Common Log File System Driver | 1 | CVE-2026-50697 |
| Windows USB Print Driver | 8 | CVE-2026-55000, CVE-2026-54111, CVE-2026-54991, CVE-2026-54996, CVE-2026-49802, CVE-2026-49806, CVE-2026-50674, CVE-2026-58543 |
| Windows Win32K | 12 | CVE-2026-54107, CVE-2026-54986, CVE-2026-54112, CVE-2026-54114, CVE-2026-49805, CVE-2026-50297, CVE-2026-50325, CVE-2026-50416, CVE-2026-50489, CVE-2026-56184, CVE-2026-57095, CVE-2026-58632 |
| Microsoft Windows Media Foundation | 6 | CVE-2026-54993, CVE-2026-58610, CVE-2026-56189, CVE-2026-57090, CVE-2026-57094, CVE-2026-57087 |
| Windows Active Directory | 4 | CVE-2026-55001, CVE-2026-54119, CVE-2026-54115, CVE-2026-50682 |
| Windows Message Queuing Queue Manager | 2 | CVE-2026-54992, CVE-2026-50439 |
| Windows Resilient File System (ReFS) | 11 | CVE-2026-54109, CVE-2026-49792, CVE-2026-49793, CVE-2026-50318, CVE-2026-50407, CVE-2026-50357, CVE-2026-50441, CVE-2026-50362, CVE-2026-50492, CVE-2026-50501, CVE-2026-58530 |
| Reliable Multicast Transport Driver (RMCAST) | 2 | CVE-2026-54982, CVE-2026-54995 |
| Windows SMB | 4 | CVE-2026-54997, CVE-2026-49801, CVE-2026-50690, CVE-2026-58531 |
| Windows RDP | 13 | CVE-2026-55003, CVE-2026-57979, CVE-2026-50376, CVE-2026-50445, CVE-2026-54126, CVE-2026-56190, CVE-2026-57982, CVE-2026-58533, CVE-2026-58535, CVE-2026-58546, CVE-2026-58539, CVE-2026-58594, CVE-2026-56171 |
| Windows GDI+ | 3 | CVE-2026-54122, CVE-2026-49796, CVE-2026-50380 |
| Microsoft Exchange Server | 4 | CVE-2026-55005, CVE-2026-55006, CVE-2026-55008, CVE-2026-55009 |
| Azure Spring Apps | 1 | CVE-2026-50338 |
| Microsoft Defender | 4 | CVE-2026-55011, CVE-2026-55012, CVE-2026-50657, CVE-2026-50658 |
| .NET Framework | 5 | CVE-2026-50524, CVE-2026-50527, CVE-2026-50646, CVE-2026-50648, CVE-2026-50650 |
| Windows CryptoAPI | 1 | CVE-2026-55144 |
| Microsoft Office SharePoint | 18 | CVE-2026-54108, CVE-2026-56164, CVE-2026-50522, CVE-2026-58644, CVE-2026-55016, CVE-2026-55019, CVE-2026-55020, CVE-2026-55021, CVE-2026-55030, CVE-2026-55034, CVE-2026-55126, CVE-2026-55051, CVE-2026-55040, CVE-2026-55052, CVE-2026-55135, CVE-2026-56157, CVE-2026-58277, CVE-2026-62826 |
| Microsoft Office Excel | 34 | CVE-2026-50675, CVE-2026-50678, CVE-2026-54988, CVE-2026-55899, CVE-2026-55948, CVE-2026-58618, CVE-2026-47642, CVE-2026-48580, CVE-2026-55024, CVE-2026-50408, CVE-2026-55046, CVE-2026-55025, CVE-2026-55031, CVE-2026-55048, CVE-2026-55029, CVE-2026-55039, CVE-2026-55041, CVE-2026-55138, CVE-2026-55136, CVE-2026-55141, CVE-2026-55036, CVE-2026-55044, CVE-2026-55054, CVE-2026-55037, CVE-2026-55058, CVE-2026-55137, CVE-2026-55053, CVE-2026-55122, CVE-2026-55131, CVE-2026-54131, CVE-2026-55898, CVE-2026-55947, CVE-2026-55949, CVE-2026-56156 |
| Windows Admin Center | 7 | CVE-2026-56169, CVE-2026-56185, CVE-2026-57107, CVE-2026-58631, CVE-2026-58643, CVE-2026-56196, CVE-2026-56197 |
| Windows Secure Socket Tunneling Protocol (SSTP) | 1 | CVE-2026-50694 |
| Microsoft Office | 27 | CVE-2026-56193, CVE-2026-47290, CVE-2026-50301, CVE-2026-50314, CVE-2026-50467, CVE-2026-55017, CVE-2026-55018, CVE-2026-55022, CVE-2026-55023, CVE-2026-55125, CVE-2026-55026, CVE-2026-55027, CVE-2026-55028, CVE-2026-55047, CVE-2026-55045, CVE-2026-55049, CVE-2026-55129, CVE-2026-55035, CVE-2026-55057, CVE-2026-55056, CVE-2026-55140, CVE-2026-55042, CVE-2026-55139, CVE-2026-50665, CVE-2026-56192, CVE-2026-56195, CVE-2026-55121 |
| Microsoft XML | 1 | CVE-2026-57097 |
| Azure CycleCloud | 2 | CVE-2026-57969, CVE-2026-58279 |
| Windows Remote Help Defense | 1 | CVE-2026-55014 |
| Windows Storage | 1 | CVE-2026-58526 |
| Microsoft Bing App for IOS | 1 | CVE-2026-58595 |
| Virtual Hard Disk (VHD) Miniport Driver | 1 | CVE-2026-58601 |
| Windows Kernel Mode Driver | 1 | CVE-2026-58602 |
| Windows Print Spooler Components | 4 | CVE-2026-58608, CVE-2026-50383, CVE-2026-50499, CVE-2026-57085 |
| Microsoft Graphics Component | 2 | CVE-2026-58609, CVE-2026-50483 |
| Microsoft Configuration Manager | 1 | CVE-2026-47301 |
| Windows Narrator Braille | 1 | CVE-2026-58635 |
| Window PC Manager | 2 | CVE-2026-58636, CVE-2026-50438 |
| Windows NTFS | 24 | CVE-2026-58640, CVE-2026-49184, CVE-2026-49789, CVE-2026-49797, CVE-2026-50308, CVE-2026-50412, CVE-2026-50386, CVE-2026-50309, CVE-2026-50313, CVE-2026-50341, CVE-2026-50388, CVE-2026-50448, CVE-2026-50471, CVE-2026-50422, CVE-2026-50402, CVE-2026-50461, CVE-2026-50417, CVE-2026-50482, CVE-2026-50494, CVE-2026-50667, CVE-2026-50668, CVE-2026-50672, CVE-2026-56175, CVE-2026-56182 |
| Power BI | 1 | CVE-2026-58647 |
| Azure Active Directory | 2 | CVE-2026-50652, CVE-2026-50653 |
| Windows Backup Engine | 2 | CVE-2026-58598, CVE-2026-50406 |
| Windows File Explorer | 8 | CVE-2026-33842, CVE-2026-40422, CVE-2026-41087, CVE-2026-50473, CVE-2026-50442, CVE-2026-50389, CVE-2026-50456, CVE-2026-57084 |
| Windows Audio Service | 2 | CVE-2026-34328, CVE-2026-50440 |
| Windows PowerShell | 1 | CVE-2026-40400 |
| Windows Event Logging Service | 2 | CVE-2026-34348, CVE-2026-50502 |
| Windows Cryptographic Services | 4 | CVE-2026-44806, CVE-2026-50302, CVE-2026-50352, CVE-2026-50681 |
| Windows Local Security Authority Subsystem Service (LSASS) | 2 | CVE-2026-40378, CVE-2026-49799 |
| Windows Push Notifications | 5 | CVE-2026-44800, CVE-2026-50363, CVE-2026-50434, CVE-2026-50339, CVE-2026-50430 |
| Azure Monitor Agent | 1 | CVE-2026-47632 |
| Windows DHCP Server | 7 | CVE-2026-48564, CVE-2026-50370, CVE-2026-50518, CVE-2026-50685, CVE-2026-50683, CVE-2026-56159, CVE-2026-58627 |
| Microsoft Surface | 1 | CVE-2026-48581 |
| Universal Plug and Play (upnp.dll) | 3 | CVE-2026-49180, CVE-2026-50455, CVE-2026-58547 |
| Windows DHCP Client | 2 | CVE-2026-49181, CVE-2026-54128 |
| Windows Clipboard Server | 2 | CVE-2026-49183, CVE-2026-50689 |
| Windows Secure Boot | 1 | CVE-2026-49783 |
| Windows HTTP.sys | 2 | CVE-2026-49787, CVE-2026-50420 |
| HTTP/2 | 1 | CVE-2026-49788 |
| Windows Universal Disk Format File System Driver (UDFS) | 2 | CVE-2026-49790, CVE-2026-50498 |
| Windows Routing and Remote Access Service (RRAS) | 3 | CVE-2026-49791, CVE-2026-50451, CVE-2026-57096 |
| Windows USB Audio Class driver (usbaudio.sys) | 3 | CVE-2026-49794, CVE-2026-50453, CVE-2026-58528 |
| Windows Web Proxy Auto-Discovery Protocol (WPAD) | 2 | CVE-2026-49800, CVE-2026-50480 |
| Windows Server | 1 | CVE-2026-50311 |
| Windows USB Video Driver | 1 | CVE-2026-49804 |
| Windows Spaceport.sys | 2 | CVE-2026-50333, CVE-2026-50298 |
| Windows AppX Deployment Service | 1 | CVE-2026-49803 |
| Windows Runtime | 17 | CVE-2026-50323, CVE-2026-50452, CVE-2026-50348, CVE-2026-50345, CVE-2026-50322, CVE-2026-50340, CVE-2026-50410, CVE-2026-50449, CVE-2026-50460, CVE-2026-50403, CVE-2026-50385, CVE-2026-50413, CVE-2026-50457, CVE-2026-50486, CVE-2026-50503, CVE-2026-54125, CVE-2026-58527 |
| Windows Audio Compression Manager (ACM) | 1 | CVE-2026-50351 |
| Windows DirectX | 5 | CVE-2026-49807, CVE-2026-50375, CVE-2026-50353, CVE-2026-50382, CVE-2026-58629 |
| Windows MIDI Service Module | 3 | CVE-2026-50342, CVE-2026-56183, CVE-2026-56187 |
| Windows Internal Task Bar | 1 | CVE-2026-50293 |
| Windows Graphics Kernel | 2 | CVE-2026-50296, CVE-2026-50493 |
| Windows Clip Service | 1 | CVE-2026-50384 |
| Windows Trusted Runtime Interface Driver | 1 | CVE-2026-50350 |
| Composite Image File System Driver | 1 | CVE-2026-50381 |
| Windows Key Guard | 2 | CVE-2026-50303, CVE-2026-50378 |
| Windows Server Backup | 1 | CVE-2026-50364 |
| Windows Redirected Drive Buffering | 1 | CVE-2026-50372 |
| Windows Server Update Service | 2 | CVE-2026-50328, CVE-2026-50444 |
| Windows SMB Server | 2 | CVE-2026-50360, CVE-2026-56168 |
| Windows Kernel-Mode Drivers | 2 | CVE-2026-50393, CVE-2026-50396 |
| Windows Notification | 2 | CVE-2026-50337, CVE-2026-50334 |
| Windows Unified Consent System | 1 | CVE-2026-50326 |
| Windows Application Model | 1 | CVE-2026-50331 |
| Microsoft Install Service | 1 | CVE-2026-50343 |
| Windows Data.dll | 1 | CVE-2026-50347 |
| Windows USB Driver | 1 | CVE-2026-50321 |
| Windows Internal System User Profile | 1 | CVE-2026-50425 |
| Windows Image Acquisition | 1 | CVE-2026-50315 |
| Windows Devices Human Interface | 1 | CVE-2026-50310 |
| Windows Operating Systems | 2 | CVE-2026-50335, CVE-2026-50317 |
| Windows Container Isolation FS Filter Driver (unionfs.sys) | 1 | CVE-2026-50428 |
| Microsoft Windows Search Component | 2 | CVE-2026-50373, CVE-2026-50679 |
| Windows LUAFV | 1 | CVE-2026-50371 |
| Windows Group Policy | 1 | CVE-2026-50391 |
| Windows System | 1 | CVE-2026-50418 |
| Windows Cloud Files Mini Filter Driver | 4 | CVE-2026-50401, CVE-2026-50374, CVE-2026-58536, CVE-2026-58613 |
| RPC Runtime | 1 | CVE-2026-50346 |
| Windows Filtering Platform (WFP) | 1 | CVE-2026-50405 |
| Windows GDI | 1 | CVE-2026-50387 |
| Windows OLE | 2 | CVE-2026-50344, CVE-2026-50686 |
| Windows DWM Core Library | 1 | CVE-2026-50437 |
| Windows Remote Desktop Services | 2 | CVE-2026-50369, CVE-2026-58626 |
| Windows Projected File System | 1 | CVE-2026-50469 |
| Windows User Interface Core | 1 | CVE-2026-50454 |
| Windows RPC API | 1 | CVE-2026-50365 |
| Content Delivery Manager | 1 | CVE-2026-50427 |
| Windows Connected User Experiences and Telemetry | 1 | CVE-2026-50421 |
| Windows Sensor Data Service | 2 | CVE-2026-50367, CVE-2026-58619 |
| Windows Virtual Filtering Platform (VFP) | 1 | CVE-2026-50432 |
| Windows Quality of Service (QoS) Packet Scheduler | 1 | CVE-2026-50431 |
| Windows Message Queuing | 2 | CVE-2026-50447, CVE-2026-50505 |
| Microsoft Windows | 1 | CVE-2026-50476 |
| Windows Wireless Wide Area Network Service | 2 | CVE-2026-50450, CVE-2026-50509 |
| Windows Domain Controller | 1 | CVE-2026-50424 |
| Windows Network Policy Server SNMP | 2 | CVE-2026-50470, CVE-2026-50496 |
| Windows USB Hub Driver | 1 | CVE-2026-50479 |
| Windows Clipboard User Service | 1 | CVE-2026-50488 |
| Windows Netlogon | 1 | CVE-2026-50500 |
| Windows Installer | 2 | CVE-2026-50490, CVE-2026-58540 |
| Code Integrity DLL (ci.dll) | 1 | CVE-2026-50491 |
| Windows Remote Desktop Protocol | 1 | CVE-2026-50497 |
| Github Copilot | 1 | CVE-2026-50510 |
| Windows BitLocker | 1 | CVE-2026-50661 |
| Windows Remote Access Connection Manager | 1 | CVE-2026-50666 |
| Windows Telephony Service | 1 | CVE-2026-50669 |
| Active Directory Certificate Services (AD CS) | 1 | CVE-2026-54121 |
| Desktop Window Manager | 3 | CVE-2026-50692, CVE-2026-58633, CVE-2026-58634 |
| Minecraft Bedrock Dedicated Server | 1 | CVE-2026-55010 |
| Microsoft Office Word | 12 | CVE-2026-55050, CVE-2026-55032, CVE-2026-55033, CVE-2026-55124, CVE-2026-55127, CVE-2026-55055, CVE-2026-55038, CVE-2026-55132, CVE-2026-55134, CVE-2026-55142, CVE-2026-55128, CVE-2026-55130 |
| Microsoft Office PowerPoint | 3 | CVE-2026-55043, CVE-2026-55123, CVE-2026-55120 |
| Microsoft Office OneNote | 1 | CVE-2026-55133 |
| Outlook Copilot | 1 | CVE-2026-55145 |
| Microsoft Dynamics NAV | 1 | CVE-2026-55944 |
| GitHub Copilot and Visual Studio | 1 | CVE-2026-41109 |
| Microsoft XML Core Services | 1 | CVE-2026-50359 |
| Windows WebView | 1 | CVE-2026-56173 |
| Windows Win32K - GRFX | 1 | CVE-2026-56176 |
| Windows Schannel | 1 | CVE-2026-56186 |
| Windows Server Network driver | 1 | CVE-2026-56188 |
| Microsoft Defender for Endpoint | 1 | CVE-2026-56178 |
| Microsoft Fabric Data Warehouse | 1 | CVE-2026-56642 |
| Windows Network File System | 4 | CVE-2026-56194, CVE-2026-56648, CVE-2026-56649, CVE-2026-56650 |
| Windows Remote Access Service Infrastructure | 1 | CVE-2026-56647 |
| Microsoft Windows Codecs Library | 1 | CVE-2026-57083 |
| Windows File History Service | 1 | CVE-2026-57091 |
| Windows SMB Server Network Transport Driver (srvnet.sys) | 1 | CVE-2026-57089 |
| Windows VMSwitch | 1 | CVE-2026-57092 |
| Extensible Storage Engine (ESENT) | 1 | CVE-2026-57088 |
| .NET Core | 1 | CVE-2026-57108 |
| Windows Subsystem for Linux | 2 | CVE-2026-57968, CVE-2026-57973 |
| Microsoft Edge for Android | 6 | CVE-2026-58296, CVE-2026-58297, CVE-2026-58299, CVE-2026-58300, CVE-2026-58522, CVE-2026-58523 |
| Windows Bluetooth Service | 1 | CVE-2026-58538 |
| Microsoft NAT Helper Components (ipnathlp.dll) | 1 | CVE-2026-58537 |
| Microsoft Input Method Editor (IME) | 1 | CVE-2026-58534 |
| Windows Management Services | 1 | CVE-2026-58544 |
| Windows DWM | 1 | CVE-2026-58541 |
| Visual Studio | 1 | CVE-2026-47305 |
| Microsoft 365 Copilot for iOS | 1 | CVE-2026-58617 |
| Windows Wireless Networking | 1 | CVE-2026-58628 |
| Windows Client-Side Caching (CSC) Service | 1 | CVE-2026-58637 |
| Windows Boot Loader | 1 | CVE-2026-58638 |
| Windows Network Address Translation (NAT) | 1 | CVE-2026-56181 |
Other Information
At the time of publication, there were no new advisories included with the July Security Guidance.