Patch Tuesday updates

Winsage
July 22, 2026
Approximately 17% of all Windows client devices are still running Windows 10, equating to about one in six machines. Windows 11 accounts for 78% of Windows devices, with third-party trackers indicating it surpassed 70% of desktop share as of February 2026. Official support for Windows 10 ended in October 2025, but Microsoft’s Extended Security Updates (ESU) program will provide patches until October 2027 for eligible devices. A typical Windows 10 device has an average of 1,903 active security vulnerabilities, nearly three times the 652 CVE-tracked flaws found on a Windows 11 machine. 66% of Windows 10 vulnerabilities are classified as "high" or "critical." Small and medium enterprises have 21.4% of their Windows devices still on Windows 10, while larger enterprises have 16.6%. The healthcare and pharmaceuticals sectors have 23% of devices on Windows 10, followed by consumer and retail at 22%, and manufacturing at 18%. Lansweeper is urging organizations to enroll in the ESU program and address reasons for remaining on Windows 10 as 2026 approaches.
Winsage
July 16, 2026
Microsoft has released its July 2026 Patch Tuesday updates, addressing 570 new security vulnerabilities, bringing the total for the month to over 620. The cumulative count of vulnerabilities patched this year has reached 1,380, exceeding the total of 1,250 for the entire year of 2020. Over 400 vulnerabilities are related to various versions of Windows, and the Windows 10 Extended Security Update program has been extended until October 12, 2027. Notable vulnerabilities include CVE-2026-56155 in Active Directory Federation Services, which allows attackers to gain administrator rights, and several critical Remote Code Execution vulnerabilities, including CVE-2026-57092 in Hyper-V and CVE-2026-56190 in Remote Desktop Protocol. Microsoft has also patched 97 vulnerabilities in Office products, with 17 classified as critical RCE vulnerabilities, and four vulnerabilities in Exchange Server, including CVE-2026-55008. The latest Microsoft Edge update addresses 27 vulnerabilities related to Chromium, and a vulnerability in Minecraft Bedrock servers has been patched.
Winsage
July 16, 2026
Microsoft will introduce a new registry policy in Windows 11 in July 2026 that allows IT administrators to enable automatic acceptance of single sign-on (SSO) prompts on managed devices. This policy will streamline user authentication by using Windows sign-in credentials automatically for Microsoft apps or services, reducing the need for manual authentication. The registry path for this policy is HKLMSOFTWAREPoliciesMicrosoftWindowsAAD, with the value AutoAcceptSsoPermission (DWORD) set to 1. It can be deployed using Group Policy Objects (GPO), Intune, Microsoft Configuration Manager, or mobile device management (MDM) tools. This setting is applicable only to Windows 11 versions 25H2 and 24H2 that have received the July 2026 Patch Tuesday updates (KB5101650 and KB5094126) and is designed for managed devices using Entra ID accounts, not personal Microsoft accounts or unmanaged devices.
Winsage
July 15, 2026
Microsoft released its July Patch Tuesday updates, addressing 570 security vulnerabilities in Windows, a record number for the company. This update includes three zero-day vulnerabilities, two of which have been exploited in real-world attacks, affecting Microsoft’s Active Directory and SharePoint, while the third concerns BitLocker encryption. The update also enhances Windows features, including changes to the Widgets app, improvements in File Explorer speed, refined Bluetooth connectivity, and a new feature allowing users to pause updates until a specific date. However, the update has been temporarily halted for certain Dell computers due to compatibility issues, with Microsoft working on a fix.
Winsage
July 14, 2026
Microsoft's July Patch Tuesday update addresses 570 vulnerabilities, including three critical zero-days. The vulnerabilities include 254 elevation-of-privilege flaws, 17 security feature bypasses, 145 remote-code-execution issues, 102 information disclosures, 16 spoofing vulnerabilities, and 35 denial-of-service vulnerabilities. Among these, 59 bugs are classified as "critical." The three zero-days patched are CVE-2026-56155 (elevation of privilege in Active Directory Federation Services), CVE-2026-56164 (elevation of privilege in Microsoft SharePoint Server), and CVE-2026-50661 (security bypass in Windows BitLocker). The update is recommended to be installed as soon as possible, and users can check for updates through the Windows Update settings.
Winsage
July 14, 2026
Microsoft has revised its guidance on Windows updates, urging users to install them within three days due to the rise of AI-driven cyber threats. Jeremy Chapman from Microsoft 365 emphasized the need for timely updates, recommending a maximum deferral period of two days for quality updates. In June, Microsoft patched 206 vulnerabilities, highlighting the importance of these updates to avoid significant risks. AI can help attackers exploit vulnerabilities quickly, making the practice of delaying updates obsolete. Microsoft has also developed an AI tool, MDASH, to identify vulnerabilities in Windows code.
Winsage
July 14, 2026
Microsoft has released the July 2026 Patch Tuesday updates for Windows 11 versions 26H1, 25H2, and 24H2, introducing several key features: - A new recovery feature allows users to revert their PCs to a recent restore point. - The Widgets experience has been revamped to minimize distractions, including no longer opening upon hover and reduced memory usage. - Users can pause Windows updates for up to 35 days and re-pause them as needed. - A new screen tint feature applies a color overlay to reduce eye strain. - Magnifier now offers preset zoom increments and allows specific zoom percentages to be input. - Bluetooth connectivity improvements include quicker pairing for Apple’s AirPods and better reliability for Beats Studio Pro headphones. - Voice access and voice typing features are now available in French, German, and Spanish. - Users can customize the right-click zone size on touchpads with a pressable surface. - The emoji panel now uses GIPHY for GIF content. - Taskbar notification counts and badge visuals will update accurately. For Qualcomm-powered PCs running Windows 11 version 26H1, the KB5101649 update includes the Point-in-time restore feature and introduces new NPU usage metrics in Task Manager, the option to assign a custom user folder name during setup, and allows multiple applications to access the camera stream simultaneously. Improvements have also been made to Windows Hello authentication and Microsoft Store performance, along with enhancements to Windows Search for better file location and prioritization.
Winsage
July 13, 2026
Microsoft has released a guide on the Windows servicing model, detailing monthly security updates, optional preview releases, hotpatch updates, and feature rollout mechanisms. Patch Tuesday occurs every second Tuesday of the month, delivering cumulative security updates to supported Windows versions. For consumers and small businesses, updates are managed through Windows Update, while enterprises can use various tools like Windows Autopatch and WSUS. Hotpatch updates, which focus on security fixes, can be installed without a restart, unlike quarterly baseline updates that require one. Optional non-security preview updates are released in the fourth week of each month for testing upcoming fixes and new features, available only for the latest supported Windows versions. Unmanaged devices can access these updates through Windows Update settings, while IT-managed devices depend on organizational policies. Microsoft also issues out-of-band updates to address urgent issues, which can be deployed through enterprise management tools. New features for Windows 11 are rolled out throughout the year via various channels, with a gradual rollout strategy to monitor quality and compatibility, using the Controlled Feature Rollout approach.
Winsage
July 10, 2026
Microsoft provides various types of Windows updates, including Patch Tuesday updates, which occur on the second Tuesday of each month. An example is the KB5094126 update for Windows 11, released on June 9, which includes both security and non-security content. IT administrators can use tools like Autopatch, Intune, and WSUS to deploy these updates. Hotpatching allows security updates to be applied without restarting devices. Optional non-security preview updates are released in the fourth week of each month for testing purposes and can be accessed by users on non-IT-managed devices. Out-of-band (OOB) updates can be issued at any time to address significant issues or vulnerabilities. Microsoft also enhances Windows 11 through annual updates, monthly updates, and Microsoft Store offerings, utilizing Controlled Feature Rollout (CFR) for feature deployment. Users are encouraged to keep their systems updated and can join the Windows Insider Program for early access to new features.
Search