NEWS
CERT-In Flags Microsoft Flaws Inside a Record 570-Bug Patch Tuesday
CERT-In’s high-severity Microsoft advisory follows a record 570-flaw Patch Tuesday, where Microsoft’s own AI scanner is finding bugs faster than teams can patch.
Microsoft patched 570 security flaws on July 14, 2026, its largest Patch Tuesday release ever, and two of them were already being used in attacks before the fixes shipped. Three days later, the Indian Computer Emergency Response Team (CERT-In) singled out one of those flaws in a high-severity advisory covering Windows, Office, Azure, Dynamics and more than a dozen other Microsoft products.
The advisory itself reads like dozens CERT-In has issued before. What is new is the scale behind it. Much of that record flaw count traces back to an AI system Microsoft built to find bugs before attackers do, and the company itself admits it does not yet know how many of July’s vulnerabilities that system actually found.
CERT-In Zeroes In on a Flaw Already Under Attack
CERT-In’s advisory, identified as CIAD-2026-0035 and published on July 17, 2026, warns that successful exploitation of the listed flaws could let attackers run malicious code, escalate privileges, steal data or knock systems offline. The agency flagged ransomware and system compromise as possible outcomes depending on the specific bug and attack scenario.
One flaw got named specifically: CVE-2026-56155, affecting Microsoft Active Directory Federation Services (the single sign-on service that brokers trust between an organization’s directory and its applications). CERT-In described the cause as insufficient granularity of access control, which it said could let an unauthenticated attacker elevate privileges on vulnerable systems.
That description undersells the urgency. Microsoft itself confirmed the bug was already being exploited in the wild as a zero-day before a patch existed, and credited the discovery to its own Microsoft Detection and Response Team (DART, the internal unit that investigates live intrusions). CERT-In’s advisory is a local alarm bell ringing for a fire that started somewhere else, weeks earlier.

Two Zero-Days, Two Very Different Severity Scores
CVE-2026-56155 was not the only flaw already under attack. Microsoft shipped fixes for three zero-days total this Patch Tuesday. Two were being actively exploited, and both landed on the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, the list that sets binding patch deadlines for United States federal agencies.
The second exploited flaw, CVE-2026-56164, hits Microsoft SharePoint Server through a missing authentication check that lets an attacker elevate privileges over a network with no credentials and no user interaction. Its severity score is only 5.3, rated Moderate, a number low enough that some security teams might have quietly deprioritized it if not for the active-exploitation label attached.
A side-by-side of the month’s most consequential bugs shows how little severity scores alone say about real risk:
| CVE | Affected Product | CVSS Score | Status |
|---|---|---|---|
| CVE-2026-56155 | Active Directory Federation Services | 7.8 (Important) | Zero-day, actively exploited, added to CISA’s KEV catalog |
| CVE-2026-56164 | SharePoint Server | 5.3 (Moderate) | Zero-day, actively exploited, added to CISA’s KEV catalog |
| CVE-2026-50661 | Windows BitLocker | 6.1 | Publicly disclosed, no known exploitation yet |
| CVE-2026-57092 | Windows VMSwitch (Hyper-V) | 9.9 (Critical) | Patched, use-after-free enabling a VM-to-host escape |
| CVE-2026-50522 | SharePoint Server | 9.8 (Critical) | Patched, exploit demonstrated live at Pwn2Own Berlin |
The BitLocker bug, CVE-2026-50661, requires physical access to a device and was publicly described before Microsoft shipped a fix, though the company says it has seen no exploitation attempts. The VMSwitch flaw is the month’s most dangerous by the numbers alone. A low-privileged attacker inside a virtual machine can use it to break out and take over the physical host running Hyper-V, a scenario that matters to nearly every organization running virtualized infrastructure.
Microsoft’s Bug Count Just Tripled in a Month
Microsoft’s own tally, counting only what it released on July 14, put the number at 570 flaws, including 59 rated Critical. Tenable’s independent research team logged 569, with 56 critical, 510 important and 3 moderate, tracking almost exactly with Microsoft’s figure. Tenable’s breakdown found elevation of privilege flaws made up 43.8% of everything patched, nearly double the next largest category.
A broader monthly count from Trend Micro’s Zero Day Initiative, which also captures fixes issued earlier in the month across additional products, put the July total at 621 CVEs with 63 rated critical (a figure some outlets rounded to 622). Either way, it dwarfed June, when Microsoft set what was then a record with 206 CVEs patched in a single release.
Microsoft says the jump is not an accident. In a security blog post introducing its new scanning system in May, the company said that month’s Patch Tuesday already included 16 CVEs its engineers found using a tool code-named MDASH, short for multi-model agentic scanning harness. MDASH uses specialized AI agents built for different vulnerability classes to autonomously find, validate and prove that a bug is actually exploitable, rather than just flagging suspicious code for a human to check later.
Pavan Davuluri, Microsoft’s Windows and devices chief, told customers ahead of July’s release to expect a heavier drumbeat of updates as AI accelerates discovery. A July 9 Windows blog post reportedly went further, warning that customers should expect a higher volume of security updates in every release going forward and that Microsoft was updating its Secure Development Lifecycle to account for AI-enabled attack techniques.
What is confirmed:
- Three zero-days shipped in July, two of them already exploited before patches existed, both now sitting in CISA’s Known Exploited Vulnerabilities catalog.
- MDASH found 16 CVEs in its first public showing during May’s Patch Tuesday, a mix of kernel-mode and user-mode bugs.
- MDASH has since moved from a limited private preview into a public preview, reachable through Microsoft Defender’s command line interface and a GitHub connector.
What Microsoft has not confirmed:
- How many of July’s flaws actually came out of the MDASH pipeline versus traditional research or outside reporting.
- Whether the Active Directory flaw CERT-In flagged, CVE-2026-56155, was surfaced by MDASH or found through DART’s incident response work.
Why Did Age of Empires II Make a Security Advisory?
Because CERT-In’s advisory follows Microsoft’s own product list line for line, and that list stretches far past Windows and Office. It names Microsoft Dynamics, Developer Tools, SQL Server, System Center and Extended Security Updates for retired software, then adds two entries that look out of place next to enterprise identity servers: a decades-old real-time strategy game and a dedicated server tool for a block-building game aimed largely at children.
The full spread, drawn directly from CERT-In’s own product list, includes:
- Windows and Windows Server, the operating system lines named first in the advisory
- Microsoft Office, including on-premises SharePoint Server deployments
- Azure and System Center, the company’s cloud and enterprise management platforms
- Microsoft Dynamics and SQL Server, business and database software used across large organizations
- Microsoft Copilot and the GitHub Copilot Plugin for JetBrains IDEs, the company’s AI assistants
- Extended Security Updates, the paid patch program for retired Windows and Office versions
- Minecraft Bedrock Dedicated Server and Age of Empires II: Definitive Edition, two games sharing a page with enterprise identity software
The Copilot entry is not decorative either. Microsoft patched a separate remote code execution flaw in Copilot this month, CVE-2026-48561, carrying a CVSS score of 9.6. Jack Bicer, director of vulnerability research at security firm Action1, flagged it as one to watch, noting that a malicious website could exploit it by causing Microsoft Edge for Android to automatically send crafted prompts to Copilot on a victim’s behalf.
A Near-Identical Warning, One Year Apart
CERT-In’s July 2026 advisory is not a one-off gesture. A CERT-In notice archived on the agency’s own site, CIAD-2025-0025, issued July 11, 2025, carries almost the same severity rating and nearly identical language: multiple vulnerabilities in Microsoft products that could let an attacker gain elevated privileges, obtain sensitive information, run remote code, bypass security restrictions, spoof identities, cause denial of service or tamper with system settings.
Line up the two advisories and the boilerplate is close enough to be a template CERT-In fills in every time Microsoft’s monthly release lands. What has changed in a year is the size of what gets fed into that template. India’s regulator was reacting to a routine Patch Tuesday in 2025. In 2026, it is reacting to the largest one Microsoft has ever shipped, arriving on a schedule that increasingly seems built around AI-assisted discovery rather than a fixed monthly cadence of human research.
A Shrinking Window to Patch
CERT-In’s advice has not changed either: install Microsoft’s latest updates, monitor enterprise environments and apply vendor-recommended mitigations. For SharePoint servers specifically, Microsoft has told administrators that enabling the Antimalware Scan Interface and restricting inbound requests can reduce risk for organizations that cannot patch immediately.
What has changed is how much ground that advice now has to cover in a single month, and how little warning defenders get before a newly disclosed bug is already being used. Two of July’s flaws went from unknown to actively exploited before a patch even existed. Microsoft is not the only vendor stretching security teams this year either. Zoom shipped its own third near-max severity Windows flaw in under a year just weeks before this Patch Tuesday, a separate account-takeover bug that added to the same pile of updates IT teams had to triage.
Microsoft’s July 9 announcement made clear this is not a one-month spike. The company told customers to expect a similar volume of updates going forward as MDASH keeps scanning. For CERT-In, and for every IT administrator who reads its advisories, that means the next high-severity warning is likely already being written.
Frequently Asked Questions
Does CERT-In’s Advisory Mean Systems in India Were Already Breached?
No confirmed India-specific breach is cited in the advisory. CERT-In’s warning is a precautionary alert based on Microsoft’s global disclosure that two flaws, including the Active Directory bug CERT-In named, were already being exploited somewhere in the wild. It is not evidence of a confirmed local incident.
How Is MDASH Different From Microsoft’s Normal Bug-Hunting Process?
MDASH uses multiple AI models with agents built for specific vulnerability classes to autonomously discover, validate and prove that a flaw can actually be exploited, rather than surfacing suspicious code patterns for engineers to manually confirm. It moved from a limited private preview in May to a public preview this month, accessible through Microsoft Defender’s command line interface and a GitHub connector.
Was Any July Flaw Demonstrated Publicly Before It Was Patched?
Yes. CVE-2026-50522, a SharePoint Server remote code execution flaw scoring 9.8 on the CVSS scale, was demonstrated live at the Pwn2Own Berlin hacking competition before Microsoft’s patch shipped, meaning a working exploit existed in public view ahead of the fix.
What Should an Organization Do If It Cannot Patch Immediately?
Microsoft recommends prioritizing internet-facing Active Directory Federation Services and SharePoint Server deployments first, since both host this month’s actively exploited zero-days. Enabling the Antimalware Scan Interface on affected SharePoint servers and monitoring authentication logs for anomalies are the interim steps Microsoft and CERT-In both point to until patches are fully deployed.
-
NEWS2 months agoCall of Duty Warzone Delisted on Xbox One and PS4 June 4
-
AZURE1 month agoMicrosoft’s MAI Models Signal a Five-Year Bet on AI Independence
-
NEWS1 month agoXbox Games Showcase 2026: Start Time, Expected Games, What to Watch
-
AZURE1 month agoMicrosoft IQ Gives Enterprise AI Agents a Shared Memory
-
NEWS2 months agoMicrosoft Build 2026 Skips Windows 12 for the AI Bet That Counts
-
AZURE2 months agoAnthropic Hits $965B, and Microsoft Profits Either Way
-
MICROSOFT 3651 month agoSatya Nadella Rebukes Scout VP Over ‘Make People Addicted’ Memo
-
NEWS1 month agoModern Warfare 4 DMZ Returns with What the 2022 Beta Was Missing
