Microsoft released its monthly security update this week, fixing a record number of flaws, including two that hackers are already exploiting.
- What it is: The July update addresses hundreds of security flaws, with 59 rated critical. Two of the vulnerabilities were already being used in real attacks before the fix was released.
- Who is affected: Businesses running Windows Server, Active Directory Federation Services (AD FS), SharePoint Server, or using BitLocker disk encryption on Windows devices.
- What the risk is: The most serious flaws could let an attacker take control of a server remotely, gain elevated access, or bypass BitLocker disk encryption on a stolen or lost device.
- What action is needed: Install this month's Windows updates as soon as possible, particularly on any on-premises servers running AD FS or SharePoint.
We recommend prioritising this update over routine patching cycles given the number of critical and actively exploited flaws involved.