Microsoft just dropped its largest security update batch on record. The July release tackled 575 vulnerabilities across 29 product families. Sixty-three rated critical. Two already exploited in the wild. One publicly disclosed before patches landed.
Security teams stared at the numbers. Then they sighed. This wasn’t just another Patch Tuesday. It marked a shift. AI tools now flood researchers with potential flaws at speeds no human team could match. The result? A deluge that feels endless. Yet many of these bugs stay confined to labs. For now.
Sophos analysts captured the mood perfectly. Their July analysis noted the “AI deluge” driving 575 CVEs and 479 Edge advisories. They pointed to unusual patterns. Multiple CVEs credited to 10 or more researchers. One PowerShell remote code execution flaw, CVE-2026-40400, listed 15 contributors. A single anonymous handle, 0ccbbf129444eb66344ccafb92b00df4, claimed credit for 47 bugs. Mostly in Office.
But here’s the surprise. These bugs aren’t tearing through networks. Not yet. Sophos observed that the share of publicly disclosed or actively exploited issues has dropped over recent months. Even Microsoft’s own assessment flags fewer as likely to see exploitation soon. The heat map tells a story. Volume up sharply. Immediate internet threats? Not so much.
So what explains this surge? Four months into what some call the AI-finder era, patterns emerge. Researchers build coalitions or tools that spot issues simultaneously. Bug totals per finder have ballooned. A dozen credits in one month? Routine now. This month topped previous highs.
Elevation of privilege led the pack. Two hundred fifty-four such flaws. Remote code execution followed with 143. Information disclosure added 102. Denial of service hit 35. The numbers dwarf June’s output. CrowdStrike reported Microsoft addressed 137 vulnerabilities in July 2025. More than double the prior month. Their breakdown showed elevation of privilege at 38 percent. A shift from remote code execution’s lead in June.
Rapid7 took a closer look too. Their July 2025 review highlighted one publicly disclosed zero-day in SQL Server. CVE-2025-49719 allowed information disclosure. Unauthenticated attackers could grab uninitialized memory. Microsoft rated it important. Not critical. Yet it stood out. Rapid7 analysts stressed that older SQL Server versions without patches faced tough choices. Extended Security Updates only cover critical flaws.
Tenable counted 128 CVEs that same year. Twelve critical. One zero-day. One hundred fifteen important. Their report flagged elevation of privilege at over 41 percent. Remote code execution near 31 percent. Tenable’s post zeroed in on SQL Server again. The same CVE-2025-49719. Exploitation deemed less likely. Small comfort for database admins.
Fast forward to 2026. The scale exploded. Qualys documented over 140 flaws in one summary. Fourteen critical. Their review listed fixes for Windows Kernel, Remote Desktop Client, Hyper-V, BitLocker and more. Spoofing, denial of service, elevation of privilege, information disclosure, remote code execution. The usual suspects.
Recent chatter on X amplified the urgency. One post from security researcher Haifei Li celebrated two of his Office bugs patched. CVE-2026-55032 in Word. CVE-2026-47642 in Excel. Microsoft recognized him as a Most Valuable Researcher again. Others flagged active exploitation. A critical SharePoint remote code execution, CVE-2026-50522, drew attention after a public proof of concept appeared. WatchTowr reported it under attack. The Hacker News covered the details. Their article warned administrators to patch immediately.
Another X user pointed to CVE-2026-57092. A Hyper-V VMSwitch bug with severity 9.9. It could let attackers jump from virtual machine to host. Virtualization teams took note. SharePoint flaws appeared repeatedly. Two zero-days in the 2026 batch involved active exploitation. CVE-2026-56164 in SharePoint Server. CVE-2026-56155 in Active Directory Federation Services. Both enabled privilege escalation.
The Record reported Microsoft fixed 622 vulnerabilities in July 2026. The largest monthly release ever. That coverage confirmed the two exploited flaws. It also noted AI accelerating vulnerability discovery. Security teams can’t keep pace with manual methods. Automated remediation gains traction.
Yet Sophos pushed back on panic. Their protections table listed detections for dozens of CVEs. Signatures for Intercept X, Endpoint IPS and XGS Firewall. CVE-2026-50518 in DHCP Server. CVE-2026-50522 in SharePoint. CVE-2026-58644, another SharePoint remote code execution. These six stood out. Microsoft judged them more likely to see exploitation within 30 days. Critical or not. They advised starting there.
Office drew special scrutiny. Sixteen CVEs tied to Preview Pane. Most critical. All rated less likely to see quick attacks. Still. Opening a malicious file in Outlook or Word could trigger them. Sophos listed 16 specific identifiers. Admins who disable Preview Pane buy breathing room. Not a permanent fix.
Edge advisories piled up. Four hundred thirty-five of them. Almost all Chromium related. Patched ahead of Tuesday. Thirty-one important flaws from Microsoft’s own Kugelblitz researcher. Many required two sequential taps. Autofill scenarios. The image of repeated testing drew wry smiles from analysts. Automation at work. Human endurance tested.
Even games weren’t spared. Minecraft Bedrock Dedicated Server. Age of Empires II. Remote code execution flaws in both. Nostalgia met modern threats. Patching childhood favorites became mandatory.
Windows absorbed the bulk. Over 700 CVEs when counting overlaps. Thirty-one critical. The product family list stretched long. .NET, Azure, Copilot, Defender for Mac, Dynamics, Entra, Exchange, Fabric, Power BI, SQL, Surface, Visual Studio. SharePoint alone saw 38. Office 78. Excel 31.
CVSS scores told part of the story. Twenty-one flaws at 9.0 or above. One hundred three at 8.0 or higher. Yet exploit likelihood remained tempered. Microsoft tagged only 44 as expected to see attacks within 30 days. Two confirmed in the wild. Neither critical. A small mercy amid the flood.
Security operations centers adjusted routines. Spreadsheets replaced dense blog appendices. Sophos released an Excel workbook. Multiple sheets. Sort by severity. Filter by product. Pivot tables for the data hungry. PT_Summary. PT_PriSevImp. PT_ByProduct. PT_Windows. No one wanted to scroll through 1,000-plus entries.
The trend worries some. AI bug hunting cleans code. It also surfaces flaws faster than patches can deploy. Coalitions of finders. Simultaneous discoveries. Handles racking up dozens of credits. These signal tools at scale. Whether the wave subsides after a grand cleanup, no one knows. Interesting times ahead.
Administrators face hard choices. Prioritize the six flagged CVEs. Apply browser updates immediately. Test patches in stages. Watch for known issues. Microsoft listed some. The usual warnings about restarts and compatibility.
One thing feels clear. Patch Tuesday no longer arrives as a manageable list. It lands like a wave. Security teams paddle harder. They scan for the critical few that matter today. They automate where possible. And they hope the lab-bound bugs stay there.
Recent coverage reinforces the point. Ground News highlighted a record 570 flaws in one summary. Three zero-days. Their aggregation captured the scale. Another piece noted end-of-support collisions. AI driving faster discovery. Teams turning to automated remediation to close gaps.
Malware News rounded out the picture. Six hundred twenty-two patches. Two exploited zero-days. WordPress updates mentioned in passing. The focus stayed on Microsoft. Privilege escalation via SharePoint and Active Directory Federation Services. Patch now. Questions later.
Industry watchers expect more of the same. Next month may bring another spike. Or a plateau. Either way, the old cadence feels broken. Security leaders rethink strategies. They budget more time. They invest in tools that match the speed of discovery. They accept that endless may be the new normal.


WebProNews is an iEntry Publication