Microsoft patched 570 security flaws on Tuesday, a record volume for a single Patch Tuesday release, and the company is crediting AI-assisted vulnerability discovery for the surge. The July 15, 2026 update spans Windows, Office, Windows Server, SharePoint, and other product lines, with at least two of the flaws classified as zero-days already exploited in the wild.
One of the zero-days affects Windows Server and lets attackers escalate from a limited user account to system administrator, a full takeover primitive. A second hits SharePoint, Microsoft's on-premises file-sharing server, and CISA has warned that hackers are actively using it to compromise organizations. Krebs on Security first reported the scope of the release.
The 570 figure is not a fluke. A week before the drop, Microsoft told customers to brace for larger monthly batches on an ongoing basis, tying the increase directly to AI tooling now embedded in its internal security work. The company is effectively warning that Patch Tuesday, a monthly ritual since 2003, is entering a higher-volume era.
Key facts
- 01Microsoft shipped patches for 570 security flaws on July 15, 2026, a record volume for a single Patch Tuesday release.
- 02At least two of the vulnerabilities are zero-days that were exploited before Microsoft learned of them.
- 03CISA warned that hackers were actively exploiting a SharePoint file-sharing bug to compromise organizations.
- 04A separate Windows Server bug lets attackers escalate from a limited user to system administrator.
- 05Microsoft flagged the surge a week earlier, saying AI-assisted defenders would drive higher patch volumes going forward.
Pavan Davuluri, who runs Windows, framed the shift as a defender-side win: AI systems tuned for code analysis are surfacing bugs that human review missed, in some cases dormant for years. Parts of the Windows codebase date back decades, giving modern AI-assisted scanners a large backlog of legacy code to work through.
“As AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release.”— Pavan Davuluri, Windows boss at Microsoft
The dynamic cuts both ways. Security researchers outside Microsoft are running the same class of tooling, and offensive teams — both criminal and state-linked — have access to similar models. The two SharePoint and Windows Server zero-days in this release illustrate the compressed timeline: bugs are being found and weaponized faster than vendors can patch them, and defenders are racing the same clock.
For IT teams, the operational cost of a 570-flaw release is not trivial. Enterprise patching workflows are already stretched by monthly cycles in the low hundreds; a jump of this magnitude forces prioritization decisions about which bugs get fixed this week and which slip to next month. CISA's active-exploitation flag on the SharePoint bug effectively promotes it to the top of every federal agency's queue.
Microsoft has not disclosed which specific AI systems are driving the internal discovery work, nor how many of the 570 patches originated from AI-assisted findings versus traditional human research or external bug bounty reports. That transparency gap matters for customers trying to gauge whether the trend will hold or spike further.
This fits a broader pattern across the AI security beat. OpenAI recently detailed GPT-Red, an internal LLM built to attack its own models, and independent researchers have used frontier models to find real vulnerabilities in production code. The tooling is getting cheaper and more capable each quarter, which shifts the economics of vulnerability research toward volume.
The counterweight is straightforward: a bigger patch list is not automatically a safer product. It signals that more latent bugs are being found, but it also expands the surface area of change that customers must test and deploy. If patch quality slips or if regression rates rise under the higher cadence, the AI-driven discovery pipeline could create new operational risk even as it closes older ones. Neither Microsoft nor CISA has published data yet on regression rates tied to the larger releases.
The story is not that Windows has more bugs — it always did — but that AI is now efficient enough to find them at industrial scale. Expect Apple, Google, and every major open-source project to face the same pressure, with the same public-facing consequence: patch notes that keep getting longer. For AI vendors selling code-analysis products to enterprise security teams, this release is the clearest customer-facing proof point of the year that the category works, and that the volume it generates is now a first-order procurement problem.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




