Live Windows Security Brief for July 27, 2026: Microsoft Updates and Identity Risk

Live Windows Security Brief for July 27, 2026: Microsoft Updates and Identity Risk

Live Windows and Microsoft security coverage for Patch Tuesday, identity systems, SharePoint, Exchange, endpoints, servers, and privilege exposure.

Live verification: This briefing was assembled from public CISA, NIST NVD, GitHub, Ubuntu, Microsoft, and other official publisher feeds checked on July 27, 2026 at 6:30 pm IST. Existing posts are preserved and repeated source IDs are deduplicated.

Executive summary

The current source set produced 8 relevant updates for this briefing. It includes 1 CISA Known Exploited Vulnerabilities, 2 critical records, 2 high-severity records, and 3 official publisher updates. Severity alone is not treated as proof of exposure: teams should verify products, versions, reachability, privileges, and available mitigations.

Microsoft remediation should connect the Security Update Guide and active-exploitation signals to the specific products and builds deployed across endpoints, servers, identity platforms, and collaboration infrastructure.

Top verified developments

CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

CISA Known Exploited Vulnerabilities | July 22, 2026 | Known Exploited | Microsoft SharePoint

Source summary: Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a…

CISA lists this issue in the Known Exploited Vulnerabilities catalog, which makes confirmed exploitation the leading prioritization signal. Review the catalog due date and required action, then identify exposed assets before normal severity-only backlog work.

CISA due date: 2026-07-25. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Windows Security review: Check supported builds, update installation, restart state, and the current running version.

Read the current source record

CVE-2026-57092: Windows VMSwitch use-after-free privilege escalation

NIST NVD and Microsoft | July 15, 2026 | CRITICAL | CVSS 9.9 | Microsoft Windows VMSwitch

Source summary: Microsoft describes a network-reachable VMSwitch use-after-free that lets an authorized attacker elevate privileges. The Microsoft CNA rates it 9.9 Critical.

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

Windows Security review: Prioritize domain, federation, collaboration, and internet-facing servers before normal endpoint queues.

Read the current source record

Shescape: Shell injection via unescaped parentheses on Windows with CMD

GitHub Advisory Database | July 25, 2026 | CRITICAL | GitHub Advisory Database shescape

Source summary: ### Impact This impacts users of Shescape on Windows that explicitly configure `shell` to CMD, or `true` with the default…

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

Windows Security review: Review privileged access and endpoint telemetry for signs of abuse before and after patching.

Read the current source record

CVE-2026-57989: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to…

NIST National Vulnerability Database | July 26, 2026 | HIGH | CVSS 7.4

Source summary: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

Windows Security review: Check supported builds, update installation, restart state, and the current running version.

Read the current source record

Email threat landscape: Q2 2026 trends and insights

Microsoft Security Blog | July 23, 2026

Source summary: In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained…

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus