Patch Tuesday cycleJuly 2026 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

July 2026 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 135 operational patch records link 682 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

135Patch recordsStable operational entries, not CVE duplicates
682Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
12Accelerated actionsOut-of-band action
4Revised entriesCanonical history remains visible

July 2026 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
135 matching recordsPage 1 of 7
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
MicrosoftDeploy Microsoft Apps update for Microsoft PC ManagerMSRC-2026-07-apps-release-notes · Updated 2026-07-14
Product and releaseMicrosoft PC Manager3.21.6.0, 3.22.1.0
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft PC Manager.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-apps-release-notes
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Windows Terminal for Windows 10MSRC-2026-07-apps-release-notes · Updated 2026-07-14
Product and releaseWindows Terminal for Windows 101.24.11321.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Terminal for Windows 10.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-apps-release-notes
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Windows Terminal for Windows 11MSRC-2026-07-apps-release-notes · Updated 2026-07-14
Product and releaseWindows Terminal for Windows 111.24.11321.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Terminal for Windows 11.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-apps-release-notes
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Microsoft Bing Search for iOSMSRC-2026-07-apps-release-notes · Updated 2026-07-14
Product and releaseMicrosoft Bing Search for iOS33.4.440529002
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Bing Search for iOS.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-apps-release-notes
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Microsoft 365 Copilot for iOSMSRC-2026-07-apps-release-notes · Updated 2026-07-14
Product and releaseMicrosoft 365 Copilot for iOS2.111.4
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft 365 Copilot for iOS.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-apps-release-notes
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Connected Machine AgentMSRC-2026-07-azure-release-notes · Updated 2026-07-14
Product and releaseAzure Connected Machine Agent1.65
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Connected Machine Agent.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Spring AppsMSRC-2026-07-azure-release-notes · Updated 2026-07-14
Product and releaseAzure Spring Apps7.3.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Spring Apps.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.2
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Active DirectoryMSRC-2026-07-azure-release-notes · Updated 2026-07-14
Product and releaseAzure Active Directory5.7.1, 7.7.3, 8.19.2
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure Active Directory.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure CycleCloud 8.9.1MSRC-2026-07-azure-release-notes · Updated 2026-07-14
Product and releaseAzure CycleCloud 8.9.18.9.1
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure CycleCloud 8.9.1.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Browser update for Microsoft Edge Copilot for AndroidMSRC-2026-07-browser-release-notes · Updated 2026-07-14
Product and releaseMicrosoft Edge Copilot for AndroidFixed release detail requires source review
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Edge Copilot for Android.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-browser-release-notes
Platform
Browser
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.6
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Browser update for Microsoft Edge Copilot for IOSMSRC-2026-07-browser-release-notes · Updated 2026-07-14
Product and releaseMicrosoft Edge Copilot for IOSFixed release detail requires source review
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Edge Copilot for IOS.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-07-browser-release-notes
Platform
Browser
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.6
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5099535KB5099535 · Updated 2026-07-14
Product and releaseMicrosoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2016, plus 1 more2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0
Review linked CVEs (17) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2016, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5099535
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5100984KB5100984 · Updated 2026-07-14
Product and releaseMicrosoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation)2.0.50727.8983 & 3.0.30729.8978
Review linked CVEs (11) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 11 linked CVEs for Microsoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5100984
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (11)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5100985KB5100985 · Updated 2026-07-14
Product and releaseMicrosoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation)2.0.50727.8983 & 3.0.30729.8978
Review linked CVEs (11) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 11 linked CVEs for Microsoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5100985
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (11)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5100989KB5100989 · Updated 2026-07-14
Product and releaseMicrosoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, plus 2 more2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0
Review linked CVEs (17) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, plus 2 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5100989
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5100990KB5100990 · Updated 2026-07-14
Product and releaseMicrosoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)4.7.4143.0
Review linked CVEs (17) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5100990
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5100991KB5100991 · Updated 2026-07-14
Product and releaseMicrosoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)4.7.4143.0
Review linked CVEs (17) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5100991
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5100998KB5100998 · Updated 2026-07-14
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0
Review linked CVEs (17) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5100998
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5101000KB5101000 · Updated 2026-07-14
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0
Review linked CVEs (17) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5101000
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5101001KB5101001 · Updated 2026-07-14
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0
Review linked CVEs (17) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5101001
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.