Microsoft patches record 622 vulnerabilities, including two actively exploited zero-days

Published:

spot_img

Microsoft has issued a significant security update, addressing a record 622 vulnerabilities in its products, including two actively exploited zero-day vulnerabilities. This update, part of July’s Patch Tuesday, marks a dramatic increase in vulnerabilities patched compared to previous months, with 62 classified as critical. Organizations using Microsoft products should prioritize applying these patches to mitigate potential risks.

What the advisory covers

This advisory details the extensive patching effort by Microsoft, highlighting the unprecedented number of vulnerabilities addressed in a single month. The update is particularly critical due to the presence of zero-day vulnerabilities that are currently being exploited.

Affected products and versions

  • Microsoft Windows
  • Microsoft Office
  • Microsoft Exchange Server
  • Microsoft Dynamics
  • Microsoft Edge

Severity and exploitation status

Among the 622 vulnerabilities, 62 are rated as critical. Notably, three of these vulnerabilities are zero-days, with two confirmed to be actively exploited in the wild. This situation underscores the urgency for organizations to implement the patches without delay.

Available patches or fixed versions

Organizations should refer to the official Microsoft security update guide for detailed information on the specific patches available for each affected product. It is essential to ensure that all systems are updated to the latest versions to mitigate vulnerabilities.

Recommended actions

  • Immediately apply the latest patches provided by Microsoft.
  • Conduct a thorough review of all systems to identify any that may be vulnerable.
  • Implement monitoring for any unusual activity that may indicate exploitation attempts.
  • Educate staff about the importance of timely updates and the risks associated with unpatched vulnerabilities.

For further details and to access the full advisory, visit Cisco Talos.

spot_img

Related articles

Recent articles

Romania’s Land Registry Agency Works to Restore Services Following Cyberattack Disruption

A cyberattack has disrupted Romania's digital land registry systems, as reported by the National Agency for Cadastre and Land Registration (ANCPI). The agency confirmed...

CVE-2026-56164 and CVE-2026-56155 in Microsoft SharePoint and Active Directory Patches Released Amid Active Exploitation Concerns

On July 20, 2026, Microsoft released critical patches addressing two vulnerabilities, CVE-2026-56164 and CVE-2026-56155, affecting SharePoint Server and Active Directory Federation Services, respectively. These...

Abbott Laboratories Investigates Dual Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Abbott Laboratories is currently investigating two significant cybersecurity incidents affecting its Cancer Diagnostics and Core Laboratory diagnostics businesses. The first incident involves unauthorized access...

Australia needs to address cyber workforce constraints, reveals industry study.

A recent study from the CyberPath Professionalisation Pilot has highlighted significant barriers to expanding the cybersecurity workforce in Australia. Conducted in partnership with Evolved...