Zero Day Initiative | Blog
Follow
The July 2026 Security Update Review
The July 2026 patch release is described as a significant event, with "nay-sayers" being proven right about potential issues. Adobe has adopted a bimonthly patching schedule, releasing updates on the second and fourth Tuesdays of the month. This month's Adobe release addresses 88 unique CVEs across various products, including ColdFusion, Commerce, After Effects, and Creative Cloud applications. While no Adobe vulnerabilities are currently under active exploit, Cold Fusion and Commerce patches are prioritized due to their high CVSS scores. Microsoft's July release is characterized as exceptionally large, covering over 621 CVEs across a wide range of products. This count significantly exceeds previous years, indicating a record-breaking number of vulnerabilities. Notable Microsoft vulnerabilities being actively exploited include an Elevation of Privilege in Active Directory Federation Services and a SharePoint Server Elevation of Privilege. A critical Windows VMSwitch Elevation of Privilege vulnerability with a 9.9 CVSS score is also highlighted. Several SharePoint Remote Code Execution vulnerabilities, including those demonstrated at Pwn2Own, are also addressed. Other critical patches cover Remote Desktop Protocol, Exchange Server spoofing, and Windows DHCP Server Remote Code Execution. Even Minecraft Bedrock Dedicated Server has a critical vulnerability, emphasizing the widespread nature of these issues.