Home › Microsoft Patch Tuesday › July 2026

Microsoft Patch Tuesday, July 2026

·

Microsoft's July 2026 security release, published July 14, 2026: 69 updates fixing 589 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 4 CVEs from this release are on the Senserva hot list today (as of 2026-10-08), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
69
Updates (KBs)
589
CVEs fixed
6
On the CISA KEV list
34
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2026-50522Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 9.8Exploited Hot now
CVE-2026-58644Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 9.8Exploited Hot now
CVE-2026-55040Microsoft SharePoint Server Security Feature Bypass VulnerabilityCVSS 9.1Exploited Hot now
CVE-2026-56155Active Directory Federation Services Elevation of Privilege VulnerabilityCVSS 7.8Exploited
CVE-2026-56164Microsoft SharePoint Server Elevation of Privilege VulnerabilityCVSS 5.3Exploited Hot now
CVE-2026-32202Windows Shell Spoofing VulnerabilityCVSS 4.3Exploited

Other high-risk CVEs (CVSS 8.8+)

CVE-2026-57092Microsoft Windows VMSwitch Elevation of Privilege VulnerabilityCVSS 9.9
CVE-2026-42990SQL Server ODBC driver Elevation of Privilege VulnerabilityCVSS 9.8
CVE-2026-49172Windows FTP Service Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-50447Windows Message Queuing Service (MSMQ) Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-50518Windows DHCP Server Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-56159DHCP Server Service Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-56188Windows Server Network driver Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-56190Remote Desktop Protocol Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-54990Remote Desktop Client Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-44815DHCP Client Service Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-45657Windows Kernel Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-47291HTTP.sys Remote Code Execution VulnerabilityCVSS 9.8

Products fixed this month

Microsoft Office 2016 (32-bit edition) (4)Microsoft Office 2016 (64-bit edition) (4)Microsoft SharePoint Enterprise Server 2016 (3)Microsoft SharePoint Server 2019 (3)Windows 11 version 26H1 for x64-based Systems (3)Windows 11 Version 26H1 for ARM64-based Systems (3)Windows Server 2012 R2 (3)Windows Server 2012 (3)Windows Server 2012 (Server Core installation) (3)Microsoft SharePoint Server Subscription Edition (2)

Every update in this release

All 66 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5099538 ExploitedCritical9.9312Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5099540 ExploitedCritical9.9326Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5099539 ExploitedCritical9.9314Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5099536 ExploitedCritical9.9389Windows Server 2025 (Server Core installation), Windows Server 2025Support · Catalog
KB5101650 ExploitedCritical9.9380Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based SystemsSupport · Catalog
KB5101649 ExploitedCritical9.9383Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based SystemsSupport · Catalog
KB5099535 ExploitedCritical9.9261Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016Support · Catalog
KB5099444 ExploitedCritical9.9185Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5099445 ExploitedCritical9.9174Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5002891 ExploitedCritical9.839Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002883 ExploitedCritical9.839Microsoft SharePoint Server 2019Support · Catalog
KB5002882 ExploitedCritical9.838Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002880 ExploitedCritical9.830Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002874 ExploitedCritical9.831Microsoft SharePoint Server 2019Support · Catalog
KB5002873 ExploitedCritical9.831Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5099414 ExploitedCritical9.818Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based SystemsSupport · Catalog
KB5095051Critical9.8123Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based SystemsSupport · Catalog
KB5094042Critical9.864Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5094041Critical9.867Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5089548Critical9.862Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for x64-based Systems - extraSupport · Catalog
KB5102338Critical9.84Microsoft SQL Server 2017 for x64-based Systems (GDR)Support · Catalog
KB5102336Critical9.84Microsoft SQL Server 2019 for x64-based Systems (GDR)Support · Catalog
KB5102340Critical9.84Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)Support · Catalog
KB5102339Critical9.84Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackSupport · Catalog
KB5102337Critical9.84Microsoft SQL Server 2017 for x64-based Systems (CU 31)Support · Catalog
KB5102334Critical9.84Microsoft SQL Server 2022 for x64-based Systems (GDR)Support · Catalog
KB5102333Critical9.87Microsoft SQL Server 2025 for x64-based Systems (GDR)Support · Catalog
KB5102335Critical9.84Microsoft SQL Server 2019 for x64-based Systems (CU 32)Support · Catalog
KB5103215Critical9.611Microsoft Exchange Server 2016 Cumulative Update 23Support · Catalog
KB5103212Critical9.611Microsoft Exchange Server Subscription Edition RTMSupport · Catalog
KB5103213Critical9.611Microsoft Exchange Server 2019 Cumulative Update 15Support · Catalog
KB5103214Critical9.611Microsoft Exchange Server 2019 Cumulative Update 14Support · Catalog
KB5104032High8.817.NET 8.0 installed on Windows, .NET 8.0 installed on Mac OS, .NET 8.0 installed on LinuxSupport · Catalog
KB5104033High8.817.NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on WindowsSupport · Catalog
KB5104034High8.814.NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on WindowsSupport · Catalog
KB5002886High8.832Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB37864969High8.81Microsoft Configuration Manager 2509Support · Catalog
KB38232642High8.81Microsoft Configuration Manager 2603, Microsoft Configuration Manager 2503Support · Catalog
KB5002887High8.423Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002892High8.422Microsoft SharePoint Enterprise Server 2016Support · Catalog
KB5002885High8.422Microsoft SharePoint Server 2019Support · Catalog
KB5101007High8.117Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation), Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based SystemsSupport · Catalog
KB5101011High8.117Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5101008High8.117Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5101009High8.117Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation)Support · Catalog
KB5101010High8.117Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)Support · Catalog
KB5101006High8.117Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5100989High8.117Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019Support · Catalog
KB5100990High8.117Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)Support · Catalog
KB5100991High8.117Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5101005High8.117Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022Support · Catalog
KB5101000High8.117Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based SystemsSupport · Catalog
KB5100998High8.117Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based SystemsSupport · Catalog
KB5101004High8.117Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for x64-based SystemsSupport · Catalog
KB5101001High8.117Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5101014High8.111Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 26H1 for x64-based Systems, Microsoft .NET Framework 3.5 on Windows 11 version 26H1 for x64-based SystemsSupport · Catalog
KB5101002High8.117Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 26H1 for x64-based Systems, Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based SystemsSupport · Catalog
KB5100984High8.111Microsoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation)Support · Catalog
KB5100985High8.111Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 3.5 on Windows Server 2012 R2Support · Catalog
KB5101003High8.11Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025Support · Catalog
KB5002890High7.812Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)Support · Catalog
KB5002273High7.82Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002867High7.83Microsoft PowerPoint 2016 (32-bit edition), Microsoft PowerPoint 2016 (64-bit edition)Support · Catalog
KB5002748High7.82Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002830High7.81Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5099415High7.81Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2Support · Catalog
Take this release to your AI

Composed from the July 2026 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.