Microsoft released software updates fixing 570 security vulnerabilities across Windows and other products, nearly tripling the previous month's record-breaking patch count.

The company attributed the dramatic increase to artificial intelligence tools accelerating vulnerability discovery. Nearly 60 bugs earned "critical" severity ratings, meaning attackers could gain remote control of Windows devices with minimal user interaction.

Three zero-day flaws were addressed, including two already exploited in the wild. CVE-2026-56155 affects Active Directory Federation Services, while CVE-2026-56164 targets Microsoft SharePoint. A third zero-day, CVE-2026-50661, bypasses Windows BitLocker encryption protections but requires physical device access.

AI Transforms Security Landscape

Microsoft Executive Vice President Pavan Davuluri said Windows users should expect "higher volume of security updates" as AI finds vulnerabilities faster across more code. The pace of discovery is changing with AI making it possible to identify issues with "new mechanisms that can accelerate both discovery and analysis."

Security researchers highlighted CVE-2026-48561, a remote code execution flaw in Microsoft Copilot scoring 9.6 on the CVSS threat scale. Attackers could exploit this by hosting malicious websites that send crafted prompts to Copilot when users visit via Microsoft Edge for Android.

Anthropic's Red Team research revealed AI's exploit development capabilities, with its Mythos Preview model creating proof-of-concept exploits for 13 of 14 vulnerabilities Microsoft rated as "Exploitation Less Likely" or "Exploitation Unlikely."

Satnam Narang from Tenable argued Microsoft's exploitability index needs updating for the "machine speed of discovery." The SharePoint zero-day initially rated "less likely" was added to CISA's Known Exploited Vulnerabilities list on July 1.

Industry-Wide Acceleration

Other major software vendors are increasing patch frequency. Adobe announced twice-monthly security bulletins, also citing AI acceleration. Cisco, Mozilla, and Oracle ship updates more frequently, while Google's June 2026 patches totaled over 900 security fixes.

Given the unprecedented patch volume, security experts recommend users wait several days before applying updates to avoid potential stability issues that large patch batches can introduce.