CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Microsoft security advisory – July 2026 monthly rollup (AV26-698) – Update 3

criticalknown exploitedpublic exploitCVE-2026-56164CVE-2026-56155CVE-2026-58644CVE-2026-50522
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26–698 Date: July 14, 2026 Updated: July 23, 2026 On July 14, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows Age of Empires II: Definitive Edition Game Azure Active Directory Azure CycleCloud 8.9.1 Azure Monitor Agent Metrics Extension Azure Open AI Azure Spring Apps Azure Synapse Fabric Data Warehouse GitHub Copilot Plugin for JetBrains IDEs Microsoft .NET Framework Microsoft .NET Framework 3.5 Microsoft .NET Framework 4.8.1 Microsoft 365 Apps Microsoft 365 Apps for Enterprise Microsoft 365 Copilot Microsoft 365 Copilot for Android Microsoft 365 Copilot for iOS Microsoft Bing Search for iOS Microsoft Defender for Endpoint for Mac Microsoft Dynamics NAV 2018 Microsoft Edge (Chromium-based) Microsoft Entra Provisioning Service Microsoft Excel 2016 Microsoft Exchange Online Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Malware Protection Engine Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac 2021 Microsoft Office LTSC for Mac 2024 Microsoft Office for Android Microsoft PC Manager Microsoft PowerPoint 2016 Microsoft SQL Server 2016 Microsoft SQL Server 2017 Microsoft SQL Server 2019 Microsoft SQL Server 2022 Microsoft SQL Server 2025 Microsoft SharePoint Enterprise Server 2016 Microsoft SharePoint Server 2019 Microsoft SharePoint Server Subscription Edition Microsoft Surface Go 2 Microsoft Surface Go 3 Microsoft Surface Hub Microsoft Surface Hub 2S Microsoft Surface Hub 3 Microsoft Surface Laptop Go Micros

CSIRTS triage

What
Multiple vulnerabilities have been identified across various Microsoft products, including .NET.
Who is affected
Users of .NET 10.0, 8.0, 9.0 on Linux, Mac OS, and Windows, as well as other Microsoft products are affected.
Urgency
Remediation is critical due to active exploitation of these vulnerabilities.
Action
Users should apply the latest security updates provided by Microsoft.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch .NET

Get an email when a new .NET advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-07-23
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-july-2026-monthly-rollup-av26-698

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-56164coverage & exploitation statusNVD · CVE.org
CVE-2026-56155coverage & exploitation statusNVD · CVE.org
CVE-2026-58644coverage & exploitation statusNVD · CVE.org
CVE-2026-50522coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security