Microsoft's July update fixes record 570 bugs, two zero-days exploited
Record 570 Windows flaws patched, including three zero-days — update now.
Microsoft's July Patch Tuesday update breaks all previous records, patching 570 Windows security flaws — more than triple the previous high of 206 bugs fixed in June. Among these are three zero-day vulnerabilities, two of which have already been exploited in active attacks. The exploited flaws target Active Directory and Microsoft SharePoint, making them particularly dangerous for enterprise environments. A third zero-day, affecting BitLocker encryption, was publicly disclosed but not yet exploited; however, it allows physical access attacks on encrypted drives.
Microsoft attributes the surge in patches to its internal AI-powered scanning tool, codenamed MDASH (multi-model agentic scanning harness), which identifies vulnerabilities faster and reduces false positives. The update also includes 61 critical-rated fixes and enhancements to File Explorer and Bluetooth. While the update is automatically delivered via Windows Update, Microsoft has paused it for some Dell devices due to incompatibility issues causing shutdowns and performance problems. Users should reboot immediately to apply the security fixes.
- Record 570 Windows security bugs patched in July, surpassing June's 206.
- Three zero-day flaws fixed; two actively exploited against Active Directory and SharePoint.
- BitLocker bypass vulnerability (publicly disclosed) requires physical access — risk for stolen laptops.
Why It Matters
With exploited zero-days in enterprise systems, this is a critical update for all Windows users.