Microsoft warned customers to expect a sustained rise in Windows security updates as it expands AI-assisted vulnerability discovery, then followed with unusually large Patch Tuesday releases that underscored the shift. The company said its multi-model agentic scanning harness, MDASH, is finding more flaws across the Windows codebase and is being paired with updates to Microsoft’s Secure Development Lifecycle to address AI-enabled attack paths while keeping human validation in the loop. External reporting and national CERT coverage highlighted the broader operational impact for defenders as vulnerability volume increases.
The most dramatic release fixed 570 CVEs in a record Patch Tuesday, including three zero-days and two that were exploited in the wild: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in Microsoft SharePoint Server. Microsoft also patched the publicly disclosed CVE-2026-50661 BitLocker security feature bypass, while the prior month’s update addressed 200 CVEs, including the CVE-2026-49160 "HTTP/2 Bomb" denial-of-service flaw, CVE-2026-50507 in BitLocker, and CVE-2026-45586, a Windows elevation-of-privilege bug that could grant SYSTEM access. Security observers said the spike reflects AI-driven fuzzing, variant hunting, and large-scale static analysis, increasing pressure on organizations to prioritize asset inventory and risk-based patching.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft said Exchange Server Subscription Edition Cumulative Update 1 has been delayed, citing the Exchange team's need to handle a larger volume of vulnerability reports, including issues surfaced by AI-assisted bug-finding. The company said it is prioritizing monthly security fixes and will release CU1 only when the build is stable enough and no urgent security payload takes precedence.
In August 2026, Microsoft released security updates for approximately 398 new CVEs across Windows, Office, Azure, Exchange, SharePoint, Teams, .NET, and other products. The release included one actively exploited flaw, CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock, along with numerous critical remote code execution vulnerabilities affecting services such as DNS, WDS, QUIC, HPC Pack, Exchange, and SharePoint.
Microsoft rolled out the mandatory August 2026 Patch Tuesday update for Windows 11 as KB5121003, advancing Windows 11 25H2 to Build 26200.9165 and 24H2 to Build 26100.9165. The update reportedly patched more than 700 security issues and was also published as offline .msu installers in the Microsoft Update Catalog.
On July 14, Microsoft released security updates for 570 CVEs in an unusually large Patch Tuesday. The release included three zero-days, two of which were exploited in the wild: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in Microsoft SharePoint Server.
In a July 9 blog post, Microsoft warned customers to expect a higher volume of Windows security updates because it is using AI-driven techniques to discover more vulnerabilities. The company described its MDASH multi-model scanning harness and said it is updating its Secure Development Lifecycle to address AI-enabled attack techniques.
Microsoft's June Patch Tuesday release fixed 200 vulnerabilities, including 33 critical CVEs and three publicly disclosed zero-days. The update set included fixes for flaws such as CVE-2026-49160, CVE-2026-50507, and CVE-2026-45586.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcezdnet.fr
Open sourcesecurityweek.com
Open sourcebleepingcomputer.com
Open sourceinfosecurity-magazine.com
Open sourceinfosecurity-magazine.com
Open sourceinfosecurity-magazine.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.