HomeMicrosoft Patch Tuesday › July 2026

Microsoft Patch Tuesday, July 2026

·

Microsoft's July 2026 security release, published July 14, 2026: 69 updates fixing 533 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 5 CVEs from this release are on the Senserva hot list today (as of 2026-08-10), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
69
Updates (KBs)
533
CVEs fixed
4
Actively exploited
24
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2026-50522Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 9.8Exploited Hot now
CVE-2026-58644Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 9.8Exploited Hot now
CVE-2026-56155Active Directory Federation Services Elevation of Privilege VulnerabilityCVSS 7.8Exploited Hot now
CVE-2026-56164Microsoft SharePoint Server Elevation of Privilege VulnerabilityCVSS 5.3Exploited Hot now
CVE-2026-32202Windows Shell Spoofing VulnerabilityCVSS 4.3Exploited Hot now

Other high-risk CVEs (CVSS 8.8+)

CVE-2026-57092Microsoft Windows VMSwitch Elevation of Privilege VulnerabilityCVSS 9.9
CVE-2026-42990SQL Server ODBC driver Elevation of Privilege VulnerabilityCVSS 9.8
CVE-2026-49172Windows FTP Service Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-50447Windows Message Queuing Service (MSMQ) Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-50518Windows DHCP Server Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-56159DHCP Server Service Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-56190Remote Desktop Protocol Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-56188Windows Server Network driver Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-54990Remote Desktop Client Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-45657Windows Kernel Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-47291HTTP.sys Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-44815DHCP Client Service Remote Code Execution VulnerabilityCVSS 9.8

Products fixed this month

.NET 8.0 installed on Windows (22).NET 10.0 installed on Windows (18).NET 8.0 installed on Mac OS (18)Windows 10 Version 1809 for 32-bit Systems (14)Windows 10 Version 1809 for x64-based Systems (14)Windows Server 2019 (14)Microsoft SQL Server 2022 for x64-based Systems (CU 25) (10)Microsoft SQL Server 2025 for x64-based Systems (CU6) (10)Microsoft SQL Server 2017 for x64-based Systems (GDR) (10)Microsoft Office 2019 for 32-bit editions (10)
Take this release to your AI

Composed from the July 2026 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.