Microsoft Issues Fixes for 622 Vulnerabilities—A New Record—Including Two Actively Exploited Zero-Days
Microsoft rolled out fixes for 622 security flaws this Patch Tuesday—the largest batch in the company's history—including two vulnerabilities that hackers were already exploiting before patches became available.
The first actively exploited bug, CVE-2026-56155, resides in Active Directory Federation Services (AD FS). It gives attackers who already have local access a path to escalate their privileges up to administrator level.
The second, CVE-2026-56164, hits SharePoint Server and is arguably more dangerous: it's remotely exploitable and requires no authentication, also resulting in elevated privileges for the attacker.
Microsoft also flagged a third notable issue, CVE-2026-50661, a BitLocker security bypass that requires physical device access to exploit. This one was already public knowledge before this month's patch cycle began.
Tenable's Satnam Narang suggested a possible link between this BitLocker disclosure and the string of zero-day disclosures attributed to a researcher operating under the name Nightmare-Eclipse (also known as Chaotic-Eclipse), though he noted Microsoft hasn't officially confirmed any connection.
Breaking down the numbers, Windows accounted for the bulk of the fixes at 416 vulnerabilities, with the Office suite responsible for another 164 patches.
Among the standout vulnerabilities this month are two critical Windows VMSwitch flaws, CVE-2026-57092 (CVSS 9.9), and a critical SharePoint bug, CVE-2026-50522 (CVSS 9.8), according to the Zero Day Initiative's analysis.
Other issues worth flagging include a cross-site scripting vulnerability in Exchange Server (CVE-2026-55008), along with several remote code execution bugs: one in Remote Desktop Protocol (CVE-2026-56190), one in Windows DHCP Server (CVE-2026-50518), one in the Windows Server Network driver (CVE-2026-56188), and one affecting Minecraft Bedrock Dedicated Server (CVE-2026-55010).
Beyond these headline bugs, Microsoft's update wave touches a wide range of products—Azure, Defender, Developer Tools, Exchange Server, Edge, and SQL Server among them.
At 622 fixes, this month's rollout puts Microsoft's 2026 cumulative CVE count ahead of prior years' totals. That's not entirely unexpected, though.
Just last week, Pavan Davuluri, the executive vice president overseeing Windows, revealed that artificial intelligence is accelerating how quickly vulnerabilities get discovered, pointing to Microsoft's deployment of its multi-model agentic scanning harness (MDASH) to hunt down bugs across the Windows codebase more efficiently.
"We continue to evolve our internal systems and practices so that vulnerability discovery is not treated as a separate activity, but as part of how we build, review, and improve Windows before new features or updates are released," Davuluri stated.
Separately, on this same Patch Tuesday, Adobe pushed out patches addressing 88 vulnerabilities of its own, with critical-severity bugs found in ColdFusion, Commerce, Experience Manager, and Illustrator.