Trinetri logo
Updated monthly

Microsoft Patch Tuesday
July 2026

Microsoft's July 2026 Patch Tuesday fixes 596 vulnerabilities across Windows, Microsoft Office and Developer Tools - 76 rated Critical, 1 publicly disclosed before the patch shipped, 3 already exploited in the wild. Patch CVE-2026-58644 first.

Released July 14, 2026, 10:00 PT3 actively exploited1 publicly disclosed67 KB articles to deploy

July 2026 Patch Tuesday at a glance

596
Microsoft CVEs
excl. Edge & Azure Linux
76
Critical
13% of the release
3
Actively exploited
CVE-2026-58644
1
Publicly disclosed
known before the patch
10.0
Highest CVSS
CVE-2026-66803
67
KB articles
what you actually deploy

Why this number differs from other roundups. Microsoft's July 2026 release document lists 2,005 entries. 473 are Azure Linux (Mariner) OS package updates and 936 are republished Chromium fixes for Edge - neither is a Microsoft product vulnerability. The 596 above is the real Patch Tuesday set. See the breakdown →

The numbers

What’s in this release

Where the 2,005 entries actually come from

Most roundups quote a single number. These are three unrelated release streams.

596 Microsoft products473 Azure Linux (Mariner)936 Edge (Chromium)

Severity

Microsoft channel only · 596 CVEs

July 2026 severity breakdown
Critical76
Important517
Moderate3
Low0

Impact type

What an attacker gains if it works

July 2026 impact breakdown
Elevation of Privilege263
Remote Code Execution151
Information Disclosure103
Denial of Service35
Spoofing18
Security Feature Bypass17
Tampering9

Most-affected components

Where this month’s fixes concentrate - filter by any of them in the table below

Microsoft Office Excel35Windows Kernel35Microsoft Office27Windows NTFS24Microsoft Office SharePoint18Windows Runtime17Windows Media15Windows RDP13Microsoft Office Word12Windows Win32K12Active Directory Federation Services (AD FS)11Windows Resilient File System (ReFS)11
Every patch

Browse all 2,005 entries

Sorted by risk by default: exploited first, then publicly disclosed, then severity, then CVSS. Search by CVE, title, component or KB number.

Showing 596 of 596
596 Microsoft vulnerabilities in the July 2026 Patch Tuesday, sortable by severity, CVSS and exploit status.
TitleStatusKB
CriticalCVE-2026-58644Microsoft SharePoint Remote Code Execution VulnerabilityRCE9.8ExploitedMicrosoft Office SharePoint5002873 +2
ImportantCVE-2026-56155Active Directory Federation Services Elevation of Privilege VulnerabilityEoP7.8ExploitedActive Directory Federation Services (AD FS)5099444 +5
ModerateCVE-2026-56164Microsoft SharePoint Server Elevation of Privilege VulnerabilityEoP5.3ExploitedMicrosoft Office SharePoint5002882 +2
ImportantCVE-2026-50661Windows BitLocker Security Feature Bypass VulnerabilityBypass6.1DisclosedWindows BitLocker5099535 +6
CriticalCVE-2026-50518Windows DHCP Server Remote Code Execution VulnerabilityRCE9.8More likelyWindows DHCP Server5099444 +5
CriticalCVE-2026-50522Microsoft SharePoint Remote Code Execution VulnerabilityRCE9.8More likelyMicrosoft Office SharePoint5002882 +2
CriticalCVE-2026-55010Minecraft Bedrock Dedicated Server Remote Code Execution VulnerabilityRCE9.8More likelyMinecraft Bedrock Dedicated Server
CriticalCVE-2026-55944Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution VulnerabilityRCE9.8More likelyMicrosoft Dynamics NAV
CriticalCVE-2026-56188Windows Server Network driver Remote Code Execution VulnerabilityRCE9.8More likelyWindows Server Network driver5099444 +8
CriticalCVE-2026-55008Microsoft Exchange Server Spoofing VulnerabilitySpoofing9.6More likelyMicrosoft Exchange Server5103212 +3
CriticalCVE-2026-55040Microsoft SharePoint Server Security Feature Bypass VulnerabilityBypass9.1More likelyMicrosoft Office SharePoint5002882 +2
CriticalCVE-2026-50370DHCP Server Service Remote Code Execution VulnerabilityRCE8.8More likelyWindows DHCP Server5099444 +5
CriticalCVE-2026-54128Windows DHCP Client Remote Code Execution VulnerabilityRCE8.4More likelyWindows DHCP Client5099444 +8
CriticalCVE-2026-54992Microsoft Message Queuing Queue Manager Remote Code Execution VulnerabilityRCE8.4More likelyWindows Message Queuing Queue Manager5099444 +8
CriticalCVE-2026-50327Windows Media Remote Code Execution VulnerabilityRCE7.8More likelyWindows Media5099536 +2
CriticalCVE-2026-50655Microsoft Windows Media Foundation Remote Code Execution VulnerabilityRCE7.8More likelyWindows Media5099535 +6
ImportantCVE-2026-49798Windows Kernel Elevation of Privilege VulnerabilityEoP9.3More likelyWindows Kernel5099444 +8
ImportantCVE-2026-49795Windows Kernel Elevation of Privilege VulnerabilityEoP8.8More likelyWindows Kernel5099536 +5
ImportantCVE-2026-50489Win32k Elevation of Privilege VulnerabilityEoP8.8More likelyWindows Win32K5099444 +8
ImportantCVE-2026-49170Windows StateRepository API Server file Elevation of Privilege VulnerabilityEoP7.8More likelyWindows StateRepository API5099536 +5
ImportantCVE-2026-50329Microsoft DWM Core Library Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Kernel5099536 +5
ImportantCVE-2026-50332Windows Kernel Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Kernel5099444 +8
ImportantCVE-2026-50343Microsoft Install Service Elevation of Privilege VulnerabilityEoP7.8More likelyMicrosoft Install Service5099536 +5
ImportantCVE-2026-50351Windows Audio Compression Manager (ACM) Elevation of Privilege VulnerabilityEoP7.8More likelyWindows Audio Compression Manager (ACM)5099444 +8
ImportantCVE-2026-50387Windows GDI Elevation of Privilege VulnerabilityEoP7.8More likelyWindows GDI5099444 +8
Your move

What your IT team should do

The same five steps every month, in the order that reduces risk fastest.

Test the known-issue candidates

Check the Windows release health dashboard before promoting past ring 1, and have the rollback path written down before you need it. Kernel, networking and authentication fixes are the ones that historically break things.

12 Patch Management Best Practices for 2026

Verify installed state, then evidence it

Confirm the patch is actually present on each endpoint rather than trusting that "deployment succeeded". Keep the resulting report - it is the artefact auditors ask for, and reconstructing it later is far more work than capturing it now.

Patch Management: The Complete Guide

Trinetri does steps two through five automatically - detecting the 67 KB articles across every endpoint, staging them in rings, verifying installed state and producing the compliance evidence. See patch management →

Patch Tuesday FAQ

Patch Tuesday falls on the second Tuesday of every month, with updates going live at 10:00 a.m. Pacific Time. Microsoft introduced the practice in October 2003, following the Blaster worm, to cut distribution costs and give administrators a predictable cadence instead of patches arriving at random. The 10:00 a.m. timing is deliberate: it leaves a full working week to remediate before the weekend. Internally Microsoft calls it the "B" release; optional "C" and "D" preview releases follow later in the month. The next Patch Tuesday is September 8, 2026.

Microsoft fixed 596 vulnerabilities in July 2026, across Windows, Microsoft Office, Developer Tools and Azure. 76 are rated Critical, 1 were publicly disclosed before the patch shipped, and 3 were already being exploited. Note that Microsoft's release document lists 2,005 entries in total, but 473 of those are Azure Linux package updates and 936 are republished Chromium fixes for Edge, which is why other sources sometimes quote a much larger number.

Exploit Wednesday is the day after Patch Tuesday. Attackers compare the newly released patches against the previous version to locate the flaw each one fixes, then build working exploits from that difference - often within 24 to 48 hours. It is the reason the deployment window matters as much as the patch itself: every hour a Critical remote code execution fix sits undeployed is an hour of measurable exposure.

A workable target for most organisations: actively exploited vulnerabilities within 24 hours, publicly disclosed ones within 72 hours, remaining Critical fixes within seven days, and everything else within the month. CISA's Known Exploited Vulnerabilities catalogue sets binding deadlines for US federal agencies and is a reasonable benchmark for everyone else. Stage the rollout in rings rather than deploying everywhere at once, so a regression is caught on a pilot group instead of in production.

An out-of-band update is a patch released outside the monthly cycle because the risk will not wait for the next Patch Tuesday. Microsoft issues them for actively exploited flaws with no mitigation - most famously during the WannaCry outbreak in 2017, when it took the unusual step of patching versions of Windows that were already out of support.

Yes. Adobe aligned its releases with Patch Tuesday in November 2012, and both SAP's Security Patch Day and Oracle's quarterly Critical Patch Updates are coordinated to the same week. Part of the reason is defensive: staggered releases let attackers reverse-engineer one vendor's patch to find the same underlying flaw in another's still-unpatched product. For IT teams it means the second Tuesday is rarely just a Microsoft problem.

Edge is built on Chromium, so most of its security fixes originate with the Chromium project and are republished by Microsoft under their own CVE identifiers. They ship on Chromium's cadence rather than the Patch Tuesday cycle, and they are delivered by Edge's own updater rather than Windows Update. Counting the 936 Edge entries alongside Microsoft product fixes would inflate the headline number and imply work for your Windows Update rings that does not exist.

Stop the sprawl. Eliminate the guesswork.

Ready to See Autonomous Endpoint Management in Action?

Experience how Trinetri transforms endpoint chaos into clarity. Try the 30 minute demo session, our experts will walk you through how AI-powered automation, real-time visibility, and unified control can secure your entire hybrid environment, without the overhead.