Microsoft patches record 622 vulnerabilities, including two actively exploited zero-days

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Microsoft has issued a significant security update, addressing a record 622 vulnerabilities in its products, including two actively exploited zero-day vulnerabilities. This update, part of July’s Patch Tuesday, marks a dramatic increase in vulnerabilities patched compared to previous months, with 62 classified as critical. Organizations using Microsoft products should prioritize applying these patches to mitigate potential risks.

What the advisory covers

This advisory details the extensive patching effort by Microsoft, highlighting the unprecedented number of vulnerabilities addressed in a single month. The update is particularly critical due to the presence of zero-day vulnerabilities that are currently being exploited.

Affected products and versions

  • Microsoft Windows
  • Microsoft Office
  • Microsoft Exchange Server
  • Microsoft Dynamics
  • Microsoft Edge

Severity and exploitation status

Among the 622 vulnerabilities, 62 are rated as critical. Notably, three of these vulnerabilities are zero-days, with two confirmed to be actively exploited in the wild. This situation underscores the urgency for organizations to implement the patches without delay.

Available patches or fixed versions

Organizations should refer to the official Microsoft security update guide for detailed information on the specific patches available for each affected product. It is essential to ensure that all systems are updated to the latest versions to mitigate vulnerabilities.

Recommended actions

  • Immediately apply the latest patches provided by Microsoft.
  • Conduct a thorough review of all systems to identify any that may be vulnerable.
  • Implement monitoring for any unusual activity that may indicate exploitation attempts.
  • Educate staff about the importance of timely updates and the risks associated with unpatched vulnerabilities.

For further details and to access the full advisory, visit Cisco Talos.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Berlin Investigates New Data Breach as Hackers Publish Stolen Login Credentials from Government Network

German authorities are currently investigating a new data breach involving Berlin’s government network, following the publication of stolen login credentials and other sensitive information...

ManageEngine to Highlight AI-Driven Cybersecurity Solutions at GISEC Global 2026 in Dubai

ManageEngine, a division of Zoho Corporation, is set to showcase its advanced cybersecurity solutions at GISEC Global 2026, scheduled for September 16-18 at the...

Toy Ghouls Unveils New Backdoors Utilizing HiveMQ and Element for C2 Communication

Introduction The cybersecurity landscape continues to evolve, with threat actors constantly adapting their tactics. One such group, known as Toy Ghouls (also referred to as...

North Korea commissions second Choe Hyon-class guided-missile destroyer

On Sunday, September 6, 2026, the North Korean Navy commissioned its second 5,000-ton Choe Hyon-class guided-missile destroyer, Kang Kon, in the eastern port city...