Web_Logo
Remote Support
Microsoft Windows: Critical Patches for Exploited Bugs
Home » Microsoft Updates  »  Microsoft Windows: Critical Patches for Exploited Bugs

Microsoft Windows: Critical Patches for Exploited Bugs

Microsoft's July security update is its largest ever, fixing more than 570 vulnerabilities across Windows, Office and related services, including two flaws that were already being used by attackers before the fix was released.

  • What it is: Two "zero-day" vulnerabilities in Active Directory Federation Services and SharePoint Server were exploited before Microsoft could patch them. A separate critical flaw in Windows Hyper-V (VMSwitch) allows an attacker with limited access to take full control of a virtual machine host.
  • Who is affected: Businesses running on-premises Windows Server infrastructure, particularly Active Directory Federation Services, SharePoint Server, or Hyper-V virtualisation.
  • The risk: Unpatched systems can be taken over by attackers already exploiting these flaws in the wild.
  • What to do: Confirm Windows Update or your patch management process has applied the July 2026 updates as a priority, especially on servers running AD FS, SharePoint or Hyper-V.

We recommend confirming with your IT provider that these patches have been applied across all affected servers this week.