Microsoft Security Updates — July 2026
Roundup of Microsoft security advisories published in July 2026.
CVE search metadata
CVE search record: CVE-2026-47302. Severity: high. CVSS: 7.5. EPSS: 1.03%. KEV: no. Brief: Microsoft Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-microsoft-security-updates/
CVE search record: CVE-2026-50318. Severity: high. CVSS: 7.8. EPSS: 0.26%. KEV: no. Brief: Microsoft Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-microsoft-security-updates/
CVE search record: CVE-2026-50313. Severity: high. CVSS: 7.8. EPSS: 0.43%. KEV: no. Brief: Microsoft Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-microsoft-security-updates/
CVE search record: CVE-2026-50361. Severity: high. CVSS: 7.8. EPSS: 0.18%. KEV: no. Brief: Microsoft Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-microsoft-security-updates/
CVE search record: CVE-2026-58630. Severity: critical. CVSS: 10.0. EPSS: 0.86%. KEV: no. Brief: Microsoft Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-microsoft-security-updates/
CVE search record: CVE-2026-58278. Severity: medium. CVSS: 5.4. EPSS: 0.28%. KEV: no. Brief: Microsoft Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-microsoft-security-updates/
CVE search record: CVE-2026-40422. Severity: medium. CVSS: 5.5. EPSS: 0.30%. KEV: no. Brief: Microsoft Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-microsoft-security-updates/
CVE search record: CVE-2026-50460. Severity: high. CVSS: 8.1. EPSS: 0.51%. KEV: no. Brief: Microsoft Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-microsoft-security-updates/
CVE search record: CVE-2026-50650. Severity: high. CVSS: 7.8. EPSS: 0.29%. KEV: no. Brief: Microsoft Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-microsoft-security-updates/
CVE search record: CVE-2026-50669. Severity: high. CVSS: 7.0. EPSS: 0.15%. KEV: no. Brief: Microsoft Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-microsoft-security-updates/
What's new
- 1. poc_available; added CVE-2026-40422 +4; microsoft edge version < 150.0.4078.48 Aug 10, 14:37 via exploit-db
- 2. added CVE-2026-47302 +4 Aug 10, 13:30 via the-hacker-news
- 3. new IOCs Aug 5, 09:12 via risky-biz
- 4. added CVE-2026-42982 +4 Jul 31, 15:31 via reddit-blueteamsec
- 5. added CVE-2026-47300 +3 Jul 30, 21:31 via nvd
Aggregated Microsoft security advisories for July 2026. CVEs from this cycle are folded into the list below as they are published.
Recommendation
Review affected products and apply Microsoft's July 2026 security updates.
Indicators of compromise
75
domain
7
12
hash_md5
3
hash_sha256
4
ip
126
url
| Type | Value |
|---|---|
| url | https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ |
| url | https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html |
| url | https://app.any.run/tasks/cf1245de-06a7-4366-8209-8e3006f2bfe5/ |
| url | https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/ |
| url | https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/import_applocker_policy/windows-powershell-xml2.log |
| url | https://devblogs.microsoft.com/scripting/automating-quser-through-powershell/ |
| url | https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/log_off_user/pwh_quser_logoff.log |
| url | https://sploitus.com/exploit?id=816BFD0D-57FA-5C9C-B54C-3F0F88BD2C84 |
| domain | sharepoint.local |
| url | http://127.0.0.1:8080 |
| domain | graph.windows.net |
| url | https://github.com/andreisss/Ghosting-AMSI |
| domain | nvd.nist.gov |
| domain | msrc.microsoft.com |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57983 |
| nvd@nist.gov | |
| soc@us-cert.gov | |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58288 |
| url | https://nvd.nist.gov |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58292 |
| domain | nist.gov |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58297 |
| url | https://microsoft.com/devicelogin |
| url | https://login.microsoftonline.com/{tenant}/oauth2/v2.0/devicecode |
| url | https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token |
| url | https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf |
| url | https://twitter.com/pr0xylife/status/1585612370441031680?s=46&t=Dc3CJi4AnM-8rNoacLbScg |
| url | https://thedfirreport.com/2023/06/12/a-truly-graceful-wipe-out/ |
| url | https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_wermgr2/sysmon_wermgr2.log |
| url | https://github.com/its-a-feature/bifrost |
| url | https://any.run/malware-trends/tycoon/ |
| domain | pool.supportxmr[.]com |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58525 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-58525 |
| url | https://sploitus.com/exploit?id=833581E3-D09A-5C85-BB3D-46DA43EDAF50 |
| url | https://api.github.com/repos/stamparm/maltrail/commits/62bcccbdb75b98a64c49f74282b0942f4661fb2a |
| url | https://x.com/suyog41/status/2075572390315311333 |
| url | https://www.virustotal.com/gui/file/372226c831de35186e1c96ec28c9ca8ceb02d69c9fe718e21d35b2e921ccf1de/detection |
| hash_sha256 | 372226c831de35186e1c96ec28c9ca8ceb02d69c9fe718e21d35b2e921ccf1de |
| url | https://www.virustotal.com/gui/file/5ef25d162827195f2fbdc80fd5c6d119ff41dd16f980692a8c4308465d88c554/detection |
| hash_sha256 | 5ef25d162827195f2fbdc80fd5c6d119ff41dd16f980692a8c4308465d88c554 |
| url | https://x.com/volrant136/status/2076012175685287991 |
| domain | download-msoffice.com |
| domain | bdnavy.download-msoffice.com |
| domain | cabinet-division-gov-pk.download-msoffice.com |
| domain | ceh.download-msoffice.com |
| domain | docx2a2e3e78e76bcc759905da3f1532a4b8c2word.download-msoffice.com |
| domain | mm.download-msoffice.com |
| domain | portmin.download-msoffice.com |
| domain | training.docx2a2e3e78e76bcc759905da3f1532a4b8c2word.download-msoffice.com |
| domain | word.download-msoffice.com |
| domain | mail-bcc-gov-bd.vercel.app |
| url | https://sploitus.com/exploit?id=8D8B971C-F5EE-53DF-AAC5-417AF3B19481 |
| url | https://github.com/gabe-k/themebleed |
| url | https://github.com/fortra/impacket/blob/master/impacket/smbserver.py |
| url | https://github.com/TalAloni/SMBLibrary/blob/master/SMBLibrary/NTFileStore/Enums/NtCreateFile/ShareAccess.cs |
| url | https://jnns.de/posts/cve-2023-38146-poc/ |
| url | https://github.com/Jnnshschl/ThemeBleedReverseShellDLL |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58596 |
| domain | logfriend.com |
| domain | 334thribetlhkyo977gqrcht1k7bvdj2.oastify.com |
| url | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56164 |
| url | https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk |
| url | https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk |
| url | https://nvd.nist.gov/vuln/detail/CVE-2026-56164 |
| url | https://www.mandiant.com/resources/blog/tracking-evolution-gootloader-operations |
| url | https://www.crowdstrike.com/blog/weaponizing-disk-image-files-analysis/ |
| url | https://attack.mitre.org/techniques/T1204/002/ |
| url | https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/gootloader/partial_ttps/windows-sysmon.log |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49162 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49171 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50293 |
| us-cert@us-cert.gov | |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54993 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58595 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50306 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50317 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50321 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50348 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50357 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50390 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50397 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50406 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50423 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50425 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50449 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50476 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50478 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50479 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50510 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50665 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50673 |
| url | https://sploitus.com/exploit?id=AC8BA49C-6B0C-5FC3-A311-C5C14C8864A6 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50338 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117 |
| url | https://johannes-moeller.dev/blog/cve-2026-50338-spring-cloud-azure-b2c-cross-issuer |
| url | https://github.com/Azure/azure-sdk-for-java/pull/49252 |
| url | https://github.com/Azure/azure-sdk-for-java/pull/49033 |
| url | https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/reference-azure-monitor-sign-ins-log-schema |
| url | https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/ |
| url | https://pushsecurity.com/blog/consentfix |
| url | https://github.com/secureworks/family-of-client-ids-research |
| url | https://sploitus.com/exploit?id=E845E4F1-345B-599F-A195-00B7604EBC69 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58635 |
| url | https://nvd.nist.gov/vuln/detail/CVE-2026-58635 |
| url | https://support.microsoft.com/help/5101650 |
| url | https://brltty.app/ |
| url | https://github.com/tylerdotrar/SigmaPotato |
| hash_sha256 | EC68A6BF7F104A815BD21E27E73A8DFB8AFCB282D4997BEBE9ECCD6C89259506 |
| url | https://sploitus.com/exploit?id=EE91804C-7619-5280-A1EA-CD09C9E65284 |
| ip | 112.213.124.132 |
| domain | hurgadatour[.]shop |
| domain | codebasecode[.]com |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58598 |
| url | https://sploitus.com/exploit?id=2CC212A7-032B-5922-B8BE-86F87D50EA33 |
| domain | sploitus.com |
| url | https://sploitus.com/exploit?id=0136FBFD-5983-5F81-959C-30B22846A9AA |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56171 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62826 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-56171 |
| url | https://www.cve.org/CVERecord?id=CVE-2026-62826 |
| url | https://app.any.run/tasks/d078f430-c3cc-44e8-a809-5506205049c3?utm_source=anyrunblog&utm_medium=article&utm_campaign=kali365-phishing-targeting-us&utm_term=210726&utm_content=linktoservice |
| domain | cloudlanecdn[.]com |
| domain | windiam.com |
| url | http://vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion/n/windiam |
| domain | vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion |
| domain | mybmtbgd7aprdnw2ekxht5qap5daam2wch25coqerrq2zdioanob34ad.onion |
| domain | brain4zoadgr6clxecixffvxjsw43cflyprnpfeak72nfh664kqqriyd.onion |
| domain | 77nrxelcwh47yikvpaz2rvtsten4sen2elybo5r5st6wlxsbitv255qd.onion |
| domain | p6wmotxzvg34tdmpwm4beqgrcyp5iys43snkccsahnw74la3k3xx6pad.onion |
| domain | zktnif5vckhmz5tyrukp5bamatbfhkxjnb23rspsanyzywcrx3bvtqad.onion |
| domain | 4ldgw2wuidqu5ef3rzx4byonf3y7rdnh43jiw2z4sbtjiwic6gkov7yd.onion |
| domain | cuuhrxbg52c5agytmtjpwfu7mrs4xtaitc4mukkiy2kqdxeqbcmuhaid.onion |
| brain.dataleak@cyberfear.com | |
| brain.decrypt@cyberfear.com | |
| brain.support@cyberfear.com | |
| ibrain.support@cyberfear.com | |
| hash_md5 | 0da1f4ede654e83241eaad7719a708a0 |
| hash_md5 | 41050b2b9f619cdd9916e3bdd5b9f2f9 |
| hash_md5 | 448f1796fe8de02194b21c0715e0a5f6 |
| hash_md5 | 523c501118ef5d7957ce54aee86d9b1d |
| hash_md5 | 714b31629c37dee57038ca4e52ef65ac |
| hash_md5 | 71c109f3bf4da2fc0173b9bcff07e979 |
| hash_md5 | 8b3a45ebb7f2331e90ac57a2a20536fd |
| hash_md5 | 8dbd57b042bc63b9ecdc9e3e5506ce85 |
| hash_md5 | 9c5698924d4d1881efaf88651a304cb3 |
| hash_md5 | a0efa7fb6dff1e035510ec1f42e083e4 |
| hash_md5 | b32a8951fc4c2e4c2d63d17200ca0032 |
| hash_md5 | f94d17b5f232e9cfd2255ca9823cb18a |
| url | https://sploitus.com/exploit?id=1994C25F-7EC9-5173-B572-042AF6615038 |
| url | https://sploitus.com/exploit?id=B4E1D3A6-7173-5883-9366-19658411A20B |
| domain | .ru |
| url | https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ |
| url | https://twitter.com/pr0xylife/status/1590394227758104576 |
| url | https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ |
| url | https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/executables_suspicious_file_path/exec_susp_path2.log |
| url | https://learn.microsoft.com/en-us/powershell/module/scheduledtasks/?view=windowsserver2022-ps |
| url | https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/atomic_red_team/pwsh_scheduledtask.log |
| url | https://attacker.example/x.sh |
| url | https://sploitus.com/exploit?id=FBD3DBC5-71EE-57F6-A156-58C2288B70BD |
| url | https://sploitus.com/exploit?id=411122DF-F525-5EBC-9FBF-47D3F8CA07B7 |
| url | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522 |
| url | https://vulners.com/cve/CVE-2026-50522 |
| url | https://nvd.nist.gov/vuln/detail/CVE-2026-50522 |
| url | https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522 |
| url | https://www.zerodayinitiative.com/advisories/ZDI-26-412/ |
| url | https://digital.nhs.uk/cyber-alerts/2026/cc-4818 |
| url | https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/ |
| url | https://censys.com/advisory/cve-2026-50522-cve-2026-58644/ |
| domain | githubusercontent.com |
| domain | anonfiles.com |
| domain | cdn.discordapp.com |
| domain | ddns.net |
| domain | dl.dropboxusercontent.com |
| domain | ghostbin.co |
| domain | glitch.me |
| domain | gofile.io |
| domain | hastebin.com |
| domain | mediafire.com |
| domain | mega.nz |
| domain | onrender.com |
| domain | pages.dev |
| domain | paste.ee |
| domain | pastebin.com |
| domain | pastetext.net |
| domain | privatlab.com |
| domain | send.exploit.in |
| domain | sendspace.com |
| domain | storage.googleapis.com |
| domain | storjshare.io |
| domain | supabase.co |
| domain | temp.sh |
| domain | transfer.sh |
| domain | trycloudflare.com |
| domain | ufile.io |
| domain | w3spaces.com |
| url | https://attack.mitre.org/techniques/T1553/005/ |
| url | https://github.com/nmantani/PS-MOTW#remove-motwps1 |
| url | https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1553.005/mark_of_the_web_bypass/possible-motw-deletion.log |
| url | https://blog.talosintelligence.com/2018/02/olympic-destroyer.html |
| url | https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/olympic_destroyer/sysmon.log |
| domain | sequrityupdate.top |
| domain | scan-security.top |
| domain | system-online.top |
| domain | system-connect.top |
| domain | corp-connect.top |
| domain | info-secure.top |
| domain | supportsoft.top |
| domain | update-syscontrol.top |
| domain | sequpdate.top |
| domain | service-clien.top |
| domain | service-corporation.top |
| domain | scansequrity.top |
| domain | service-help.top |
| domain | it-service.top |
| domain | sequritycheck.top |
| domain | upsecscan.top |
| ip | 94.140.114.192 |
| ip | 94.140.115.18 |
| ip | 94.140.115.129 |
| url | https://sploitus.com/exploit?id=C28553BE-4C45-5EF1-858E-239BEE31A10F |
| url | https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC |
| url | https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/ |
| url | https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db |
| url | https://therecord.media/north-korea-hackers-ransomware |
| url | http://localhost:8080 |