Patch Tuesday July 2026: what Microsoft shipped
Microsoft published its security updates on Tuesday, 14 July 2026.
On the day, the briefing reads Microsoft's advisories and this page lists what carried a flag. It stays here afterwards as the record.
Which flaws were flagged?
3 flagged by Microsoft as exploited at release.
One flagged by Microsoft as publicly disclosed.
5 are in the CISA KEV catalog.
- CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability Exploited at release · In KEV
- CVE-2026-56155 Active Directory Federation Services Elevation of Privilege Vulnerability Exploited at release · In KEV
- CVE-2026-56164 Microsoft SharePoint Server Elevation of Privilege Vulnerability Exploited at release · In KEV
- CVE-2026-50661 Windows BitLocker Security Feature Bypass Vulnerability Publicly disclosed
- CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability In KEV
- CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability In KEV
What PlainSec published
What the last cycles held
June 2026: 4 flagged.
May 2026: 5 flagged.
April 2026: 3 flagged.
We hold 634 CVEs from Microsoft's 2026-Jul document. That is what our records reach, not the size of the release: it grows for weeks after the day.