CVE-2026-50661
published 2026-07-14CVE-2026-50661: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
PriorityP428medium6.1CVSS 3.1
AVPACLPRNUINSUCHIHAN
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.9339 | 10.0.14393.9339 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.9020 | 10.0.17763.9020 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.7548 | 10.0.19044.7548 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.7548 | 10.0.19045.7548 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.8875 | 10.0.26100.8875 |
| microsoft | windows_11_version_25h2 | >= 10.0.26200.0 < 10.0.26200.8875 | 10.0.26200.8875 |
| microsoft | windows_11_version_26h1 | >= 10.0.28000.0 < 10.0.28000.2525 | 10.0.28000.2525 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.9339 | 10.0.14393.9339 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.9020 | 10.0.17763.9020 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.5386 | 10.0.20348.5386 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.33158 | 10.0.26100.33158 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
Hackernews
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
blogs_hackernews·2026-07-15·CVSS 7.8
CVE-2026-56164 [HIGH] Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200 .
Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Serv
Rapid7
Patch Tuesday - July 2026
blogs_rapid7·2026-07-14·CVSS 9.6
CVE-2026-58617 [CRITICAL] Patch Tuesday - July 2026
Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public disclosure for one other. As usual, browser vulns are not included in the Patch Tuesday count above. Rapid7 noted last month that Microsoft no longer enumerates Chromium CVEs in the Security Update Guide. However, Microsoft has now taken the pursuit of minimalism much further, since today’s Security Update Guide no longer lists out even Microsoft vulnerabilities! Instead, we now receive a summary table of vulnerability counts by product family, as well as a new slimline “Notable CVEs” section. All of this only ser
Sans Isc
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
blogs_sans_isc·2026-07-14·CVSS 6.1
CVE-2026-56155 [MEDIUM] Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here
Published: 2026-07-14. Last Updated: 2026-07-14 19:14:58 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This patch Tuesday includes a staggering 622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft's Edge browser. 62 of the vulnerabilities are rated critical. One was disclosed before today, and two have already been exploited.
Given the large number of vulnerabilities, it is difficult to point out "noteworthy" issues.
Already exploited vulnerabilities:
CVE-2026-56155 : Active Directory Federation Services Elevation of Privilege Vulnerability. This is an important (not critical) vulnerablity.
CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege Vulnerability. Micr
Krebs
Microsoft Patches a Record 570 Security Flaws
blogs_krebs·2026-07-14·CVSS 9.6
CVE-2026-56155 [CRITICAL] Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.
Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows syste
Qualys
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
blogs_qualys·2026-07-14
CVE-2026-50661 Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday forJuly2026
Adobe Patch for July 2026
Zero-day Vulnerabilities Patched inJulyPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inJulyPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
Microsoft’s July 2026 Patch Tuesday delivers security updates for a broad range of products and services, including several vulnerabilities that pose significant risks to enterprise environments. As attackers continue to target unpatched systems, the timely deployment of these updates remains one of the most effective defenses against exploitation. This blog provides an overview of the month’s key security fixes, highlights the most critical vulnerabilities, and offers guidanc
Tenable
Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
blogs_tenable·2026-07-14·CVSS 7.8
CVE-2026-56155 [HIGH] Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
## Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
56 Critical
510 Important
3 Moderate
0 Low
Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.
Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June . Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will see a higher volume of security updates included in each security release.”
This month’s upda
2026-07-14
Published