Windows 0-day drops same day Microsoft releases record 570 patches

Microsoft’s July 2026 Patch Tuesday fixed a record 570 security vulnerabilities, but the same day a new Windows zero-day dubbed HiveLegacy was disclosed, described by researchers as a “powerful primitive” capable of enabling further attacks.

The HiveLegacy vulnerability was disclosed by the same threat actor who previously released the LegacyHive zero-day targeting Microsoft systems. Researchers characterized it as an elevation-of-privilege flaw in a core Windows component that could serve as a building block for more dangerous exploits. The disclosure came from what appears to be the same serial tormentor who has been releasing a steady stream of Windows vulnerabilities this year.

The July Patch Tuesday itself was the largest in Microsoft’s history, fixing 570 CVEs across the company’s product ecosystem. Of those, 254 were elevation-of-privilege vulnerabilities, 145 were remote code execution flaws, 102 were information disclosure issues, 35 were denial-of-service bugs, 17 were security feature bypasses, and 16 were spoofing flaws. Fifty-nine vulnerabilities received a Critical severity rating.

Two zero-days were actively exploited before patches were available. CVE-2026-56155 is an elevation-of-privilege flaw in Active Directory Federation Services (AD FS) that allows an authenticated attacker to escalate to administrator level. CVE-2026-56164 affects Microsoft SharePoint Server, where missing authentication for a critical function enables unauthorized remote privilege escalation. Microsoft recommends enabling the Antimalware Scan Interface with Full Request Body Scan mode as a mitigation for the SharePoint flaw.

Behind every article is careful research and verification. Help us continue delivering reliable news.

Keep quality journalism alive

A third zero-day, CVE-2026-50661, is a BitLocker security feature bypass that was publicly disclosed but not yet exploited, allowing an attacker with physical access to a device to read encrypted data.

Microsoft attributed the unprecedented vulnerability volume in part to an AI-powered vulnerability discovery system it recently deployed to proactively scan its Windows codebase for flaws. The company has now patched 1,308 vulnerabilities in the first seven months of 2026, nearly double the same period in 2025.

Security experts warned that the combination of AI-accelerated bug discovery, an aggressive disclosure cadence from external researchers, and the sheer volume of patches being released each month is creating operational challenges for enterprise security teams. Delaying updates now carries significantly greater risk.

Sources: Ars Technica; CyberPress; TechRepublic

Scroll to Top