Microsoft has released its monthly security update on Monday, addressing a staggering 570 vulnerabilities in Windows 11. This marks over a fourfold increase compared to July 2025, which saw only 137 vulnerabilities resolved. This remarkable rise is attributed to new AI-powered detection tools capable of identifying coding errors at unprecedented speeds.
AI Scanners Uncover Vulnerabilities at Breakneck Speed
The significant increase in vulnerabilities identified is driven by an internal system known as MDASH. More than 100 AI agents comb through the Windows codebase searching for security loopholes. As early as May 2026, the tool identified 16 critical zero-day vulnerabilities, including remote execution flaws in the TCP/IP stack and the IKEv2 protocol.
Since July, MDASH has been in a private preview within Microsoft Security Exposure Management. The system automates security audits in conjunction with Defender, GitHub, and Azure DevOps. Concurrently, Microsoft is preparing a commercial version called Project Perception, set to launch later this month, utilizing multi-model routing from Microsoft, OpenAI, and Anthropic. This robust tool is expected to compete heavily with high-priced security platforms.
The statistics are impressive: Between January and July 2026, Microsoft patched a total of 1,308 vulnerabilities, nearly doubling the number from the same period last year (680). The upward trend continues, with company representatives predicting that future update packages will remain substantial as the AI consistently uncovers new errors.
New Recovery Features and Productivity Updates
However, the July patch brings more than just security fixes. With the July 14, 2026 update, a myriad of new features has debuted in Windows 11:
- Point-in-Time Restore is now widely available. This system leverages the Volume Shadow Copy Service (VSS) to automatically create recovery points every 24 hours, retaining them for 72 hours. A prerequisite is that the Windows partition must be larger than 200 gigabytes. Users with smaller drives will need to enable the feature manually.
- Windows Search has received a complete overhaul. Local results now take precedence over MSN web content, and intrusive advertisements have been removed.
- File Explorer: The ‘This PC’ search now supports substring searches, requiring as few as two characters to generate a results list.
- Edge Browser can now summarize PDF documents using AI, enhancing user efficiency.
- Accessibility features a new “Screen Tint” mode for better visual comfort. A new calendar system allows users to postpone updates for up to 35 days.
Emergency Patches and Active Exploits
Following the regular Patch Tuesday, Microsoft had to issue additional updates. On July 18 and 19, the emergency update KB5121767 was released to address stability issues on several Dell professional laptops, including the Precision models 5470 to 5490 and XPS-17 devices.
Two vulnerabilities are currently being actively exploited: CVE-2026-56155 relates to a privilege escalation issue in Active Directory Federation Services (AD FS), while CVE-2026-56164 concerns an authentication gap in SharePoint Server. Moreover, security researchers discovered a new exploit called LegacyHive on July 17 that targets the Windows user profile service.
Copilot Becomes Standard: Outlook for the Coming Months
Microsoft is accelerating the integration of its AI assistant, Copilot. Following the release of Outlook 16.111 for Mac on July 14—which allows Copilot to process over 30 different file types—the company announced that Copilot will be considered standard equipment in Outlook by the end of 2026.
Starting August 2026, Microsoft Teams will introduce AI-driven meeting archives. Session files will be stored directly in SharePoint for licensed users, and the previous “Outlook Meeting Insights” function will be discontinued in September 2026, replaced by Copilot-generated summaries. Older authentication methods in Exchange Online PowerShell will remain available until December 2026.

