CVE Tools

Microsoft Patches a Record 570 Security Flaws

Krebs on SecurityBy BrianKrebs

Reported exploitedWindowsActive Directory Federation Services

Our summary

Microsoft has issued a record-breaking 570 security patches this month, addressing critical vulnerabilities in Windows, Active Directory Federation Services, SharePoint, BitLocker, and Copilot. Among these are three actively exploited zero-day flaws, including two elevation of privilege bugs such as CVE-2026-56155 and CVE-2026-56164. Nearly 60 of the patched issues were deemed 'critical' due to their potential for remote code execution or system takeover without user interaction. The surge in patch counts is attributed to AI-driven vulnerability discovery, prompting concerns about the need for updated exploitability assessments that account for AI's accelerating threat landscape.

Read at Krebs on Security

Krebs on Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store