Recommendation for the July 2026 Regular Security Updates for the Microsoft Product Family

Recommendation for the July 2026 Regular Security Updates for the Microsoft Product Family

Overview

Microsoft has released its July 2026 regular security update, which addresses vulnerabilities in various products it provides. The update covers a wide range of product families, including Apps, Azure, Developer Tools, Device, ESU, Microsoft Office, Open Source Software, SQL Server, System Center, and Windows. Users should update to the latest version.

Key Points

  • This update addresses 57 Critical and 511 Important vulnerabilities.
  • Affected products include Microsoft 365 Copilot for Android, Microsoft 365 Copilot for iOS, Microsoft Bing Search for iOS, Microsoft PC Manager, Windows Terminal, Azure Active Directory, Azure CycleCloud, Azure Monitor Agent Metrics Extension, Azure Spring Apps, .NET 8.0/9.0/10.0, Microsoft .NET Framework, Visual Studio 2022, Visual Studio Code, Microsoft Surface, Microsoft Exchange Server, Microsoft Dynamics NAV 2018, Microsoft Office, SharePoint, Windows Subsystem for Linux (WSL2), SQL Server, Windows Defender, Windows, Windows Admin Center, and Windows Remote Help.
  • The main vulnerability types include remote code execution (RCE), privilege escalation, information disclosure, denial of service, spoofing, tampering, and security feature bypass.

Notable Items

  • A critical-rated remote code execution vulnerability (CVE-2026-48561) in Microsoft Copilot has been fixed.
  • A critical privilege escalation vulnerability (CVE-2026-58617) in Microsoft 365 Copilot for iOS and a critical spoofing vulnerability (CVE-2026-58595) in the Microsoft Bing App for iOS have been fixed.
  • Critical or high-severity vulnerabilities have been addressed in Microsoft Exchange Server, Microsoft Dynamics NAV, Microsoft Office Excel/Word/PowerPoint/SharePoint, Windows DHCP Client/Server, Windows DirectX, Windows Media Foundation, Windows Print Spooler Components, Windows TCP/IP, Windows Hyper-V, Windows RDP, Windows SMB Server, and many other core components have had critical or high-severity vulnerabilities resolved.
  • Several vulnerabilities have also been fixed in core components of Microsoft Windows, including the Kernel, NTFS, DNS, AD CS, AD FS, Secure Boot, BitLocker, HTTP.Sys, Win32K, RPC Runtime, WSL2, and Windows Admin Center.

Deployment and Action

  • Patches for each product were provided through the July 14, 2026, update.
  • Instructions were provided for automatic installation using the Windows Update feature or manual installation by referring to the URLs listed in each product’s information.