LIVE · cybersecurity feed
Live wire
zero-day

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs were identified in the Security Updates Guide. Interestingly, only two CVEs were reported as exploited zero-days and only one as publicly disclosed, but we’ll get back to that later in this artic

zeroday.news ·

Microsoft's July 2026 Patch Tuesday saw an unprecedented volume of security updates, with over 600 Common Vulnerabilities and Exposures (CVEs) addressed across nearly all products in its portfolio. Windows 11 and Server 2025 accounted for 405 CVEs, while Windows 10 and its server counterparts had 337. Record numbers of CVEs were also reported for Microsoft SharePoint and Office, alongside updates for SQL Server, Exchange Server, and the .NET framework. Even gaming titles like Age of Empires and Minecraft Server received security patches.

Despite the high volume, only two CVEs were confirmed as exploited zero-days, and one was publicly disclosed. However, the sheer number of vulnerabilities has prompted Microsoft to recommend a three-day turnaround for patching critical issues, with a two-day grace period, to counter "AI-accelerated" threats. This recommendation has sparked debate among industry experts, who acknowledge the growing threat but highlight the challenges large enterprises face with testing, change control, and compatibility requirements within such a tight timeframe.

One critical vulnerability from the July updates, CVE-2026-50522, a remote code execution flaw in SharePoint, is now confirmed by Microsoft as actively exploited. Attackers can leverage this vulnerability to steal machine keys, maintaining access even after systems are patched, and execute arbitrary code on the SharePoint system.

Another significant vulnerability, dubbed "LegacyHive" by researcher Nightmare Eclipse, affects the Windows User Profile Service. This flaw allows a standard non-administrator user to mount any other user's registry hive with full access, enabling them to access stored secrets or modify registry values to influence subsequent login executions. Microsoft has acknowledged this vulnerability and is developing a fix, though a CVE ID has not yet been assigned.

Microsoft has also introduced targeting improvements in the latest Windows 11 24H2 and 25H2 preview patches, designed to increase coverage for devices eligible to receive new Secure Boot certificates, addressing issues with outdated certificates on edge systems.

Several Microsoft products are approaching their End of Servicing under the company's Modern Policy, meaning continuous updates and extended support will cease. Windows 11 Version 24H2 will reach End of Servicing on October 13, 2026. On November 10, Windows 11 Version 23H2 Enterprise and Education Editions, along with Windows 11 IoT Enterprise 23H2, will also reach End of Servicing. Additionally, Microsoft announced an extended six-month period for ESU support for Exchange Server 2016/2019, which will conclude this October without further extensions.

Looking ahead to August 2026, Microsoft has indicated that the trend of high CVE volumes will persist due to AI's role in identifying more vulnerabilities. While the number of updates might not reach July's record, a substantial set of new CVEs is anticipated, with most Microsoft products expected to receive updates.

Beyond Microsoft, other vendors also released security updates in the past month. Adobe issued a small set of releases on July 28 for Format Plugins, Bridge, and Campaign Classic. Potential updates for Photoshop, InCopy, InDesign, and Acrobat Reader are considered likely for the upcoming August cycle, as these products did not receive updates in July.

Apple's last major releases were on July 27, covering macOS Tahoe 26.6, macOS Sequoia 15.7.8, and macOS Sonoma 14.8.9, which included a large number of CVEs, with Tahoe alone addressing 128 unique vulnerabilities. A minor update on August 6 addressed CVE-2026-65400, a screen sharing vulnerability, across these macOS versions.

Google released Chrome Desktop 151.0.7922.108 for Windows on August 6, addressing 41 CVEs. While Google typically releases weekly security updates, a minor update with fewer CVEs is expected next week. Mozilla is also likely to release minor updates for Thunderbird and Firefox, following major releases for Firefox and Thunderbird 153, Firefox ESR 115.38, and Firefox ESR 140.13 on July 21.

zero-daypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
surveillance

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety, a company known for its public safety cameras, reportedly pitched a plan to utilize dashcams from rideshare and delivery vehicles to collect license plate data. This initiative, which did not proceed, would have involved a partnership with Nexar, a dashcam manufacturer, and potentially involved drivers without their knowledge. Separately, a former Flock employee alleged the company provided direct camera access to ICE and CBP through a pilot program, contradicting internal statements.

email securityhigh

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.

breach

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered […]

malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

ai

OpenAI pledges to add Astra security as Anthropic loosens Fable's leash

Or how I learned to stop worrying and love dangerous AI