Microsoft’s latest security updates include a broad set of fixes across Windows, Office, Azure, Exchange, SharePoint, Remote Desktop, and other enterprise products, with several critical issues rated as highly likely to be exploited. Among the most serious is CVE-2026-47291, a critical HTTP.sys flaw with a CVSS 9.8 score that can reportedly allow unauthenticated remote code execution in the Windows kernel-mode HTTP protocol stack, potentially giving attackers SYSTEM-level access. Microsoft also flagged multiple other high-risk issues in core Windows components and network-facing services, including vulnerabilities in DHCP, the NT OS Kernel, NTLM, Remote Desktop Client, and SharePoint.
Separate Microsoft disclosures also detail new Microsoft Edge (Chromium-based) flaws affecting versions earlier than 150.0.4078.48. These include CVE-2026-58281, a deserialization of untrusted data bug that can lead to remote code execution, and CVE-2026-58596, an untrusted pointer dereference issue that can enable elevation of privilege. Both vulnerabilities require user interaction but carry high impact if exploited, reinforcing concerns that browser and internet-exposed Windows components remain priority targets as vendors accelerate patch releases in response to faster vulnerability discovery and exploitation timelines.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft published CVE-2026-55005 in the MSRC Update Guide on July 14, 2026, describing a heap-based buffer overflow in Microsoft Exchange Server that could allow authorized remote code execution. The entry lists affected versions including Exchange Server 2016 CU23, Exchange Server 2019 CU14 and CU15, and Exchange Server Subscription Edition RTM on x64 systems.
A Reddit post highlighted external technical analysis of CVE-2026-47291, describing the Windows HTTP.sys flaw as an integer overflow enabling unauthenticated remote code execution with SYSTEM-level privileges. The discussion referenced reverse engineering details, affected functions, and reproduction information.
The CVE record for CVE-2026-58596 states Microsoft received the report on July 12, 2026. The flaw is an untrusted pointer dereference in Microsoft Edge that could allow elevation of privilege over a network.
A vulnerability entry for CVE-2026-58281 described a deserialization of untrusted data flaw in Microsoft Edge that could allow remote code execution. The entry states affected versions are earlier than 150.0.4078.48 and cites Microsoft as the reference.
A Microsoft Edge security update was published on June 28, 2026, indicating a browser patch release tied to security fixes. The reference provides the publication date but no additional technical details in the supplied content.
Microsoft published its June 2026 security updates covering numerous products and services, including critical flaws such as CVE-2026-47291 in Windows HTTP.sys and several other high-severity vulnerabilities marked as more likely to be exploited.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcecvefeed.io
Open sourcereddit.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.