
Microsoft Ships Record 570 Patches as AI Accelerates Both Discovery and Exploitation
Microsoft’s July 2026 Patch Tuesday set a new record of 570 fixes driven by AI vulnerability discovery. Technical evidence shows AI is simultaneously shortening exploit development cycles for n-days, outpacing Microsoft’s current exploitability ratings. Other major vendors are adopting higher patch cadences in response.
The July release nearly tripled June’s prior record. Two zero-days enable local privilege escalation via Active Directory Federation Services (CVE-2026-56155) and SharePoint (CVE-2026-56164); a third is a BitLocker bypass (CVE-2026-50661) requiring physical access. Roughly 250 elevation-of-privilege flaws were also addressed. Microsoft attributes the surge to AI-assisted code analysis that surfaces issues faster across larger codebases.
Tenable’s Satnam Narang and Action1’s Jack Bicer documented how the same AI tooling now produces working exploits for flaws Microsoft rated “less likely” to be exploited. CVE-2026-48561 in Copilot carries a 9.6 CVSS score and permits remote code execution via malicious Edge prompts. CISA added the SharePoint zero-day to its Known Exploited Vulnerabilities catalog on 1 July, contradicting Redmond’s initial assessment.
Adobe, Cisco, Mozilla and Oracle have all increased patch frequency in 2026, citing identical AI-driven discovery gains. The pattern indicates a structural shift: defender and attacker tooling are converging on the same acceleration curve, compressing the window between disclosure and weaponization.
Expect Microsoft’s exploitability index to be revised or replaced within six months as n-day exploit generation moves from human to model-driven timelines.
CISA: By December 2026 at least 40 percent of new KEV entries will originate from AI-generated PoCs within 14 days of disclosure.
Sources (3)
- [1]Primary Source(https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/)
- [2]Supporting Source(https://www.tenable.com/blog/microsoft-july-2026-patch-tuesday)
- [3]Supporting Source(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)