Active, Exploits

Active Exploits and a Record Patch Haul: Microsoft and Zoom Push Urgent Security Fixes

Published on 07/16/2026 at 13:16 | Redaktion boerse-global.de

Zoom patches a critical 9.8-rated bug; Microsoft fixes over 570 vulnerabilities including two zero-days under active attack. Update now.

Zoom and Microsoft Release Urgent Security Patches for Critical Flaws
Active Exploits and a Record Patch Haul: Microsoft and Zoom Push Urgent Security Fixes Illustration mit AI erstellt ĂĽbermittelt durch boerse-global.de

Two of the world’s largest software vendors have released emergency updates in the same week, closing critical vulnerabilities that could allow attackers to seize control of user accounts. While no active exploitation has been reported for the worst of Zoom’s flaws, Microsoft is already fighting two zero-day bugs that are being used in real-world attacks.

Zoom warned customers about a critical vulnerability in its Windows clients, tracked as CVE-2026-53412. The flaw carries a CVSS score of 9.8 — the highest risk rating — and stems from an input-validation error that lets unauthenticated attackers take over accounts over the network. The affected versions include Zoom Workplace prior to 7.0.0, the VDI client before versions 7.0.10, 6.6.15 or 6.5.18, and the Meeting SDK before 7.0.0. In total, Zoom patched four security holes, three of them rated high risk. The company urges users to upgrade immediately to version 7.1.0 or newer. The critical bug was discovered internally; Zoom says there are no signs it has been exploited yet.

On the same day, Microsoft delivered what it calls its largest Patchday ever. The company fixed between 570 and 622 vulnerabilities across its product lineup. Over 400 of those patches target Windows alone, with additional fixes for Office, Edge, SharePoint and Azure.

Three zero-day vulnerabilities were part of the haul, and two of them are already under active attack. One flaw, CVE-2026-56164, affects SharePoint Server and allows privilege escalation without authentication. Another, in Active Directory Federation Services (ADFS, CVE-2026-56155), also carries immediate risk. The third publicly known zero-day is in BitLocker (CVE-2026-50661) but requires physical access to exploit.

Microsoft credited its AI-assisted system, named MDash, with helping to detect the unusually high number of bugs fixed this month.

Alongside the security updates, Microsoft announced the end of support for SharePoint 2016 and 2019. Windows 11 users who install the patches — KB5101650 or KB5099414 — will also receive functional improvements, including point-in-time recovery and enhanced Bluetooth connectivity.

Given the active exploitation in Microsoft’s ecosystem and Zoom’s critical vulnerability, security authorities are pressing both businesses and individuals to update without delay. In professional environments where videoconferencing tools and SharePoint are central to daily operations, failing to patch now risks compromising corporate data.

Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.

en | boerse | 69779573 |