Live Windows Security Brief for July 28, 2026: Microsoft Updates and Identity Risk

Live Windows Security Brief for July 28, 2026: Microsoft Updates and Identity Risk

Live Windows and Microsoft security coverage for Patch Tuesday, identity systems, SharePoint, Exchange, endpoints, servers, and privilege exposure.

Live verification: This briefing was assembled from public CISA, NIST NVD, GitHub, Ubuntu, Microsoft, and other official publisher feeds checked on July 28, 2026 at 6:34 am IST. Existing posts are preserved and repeated source IDs are deduplicated.

Executive summary

The current source set produced 8 relevant updates for this briefing. It includes 1 CISA Known Exploited Vulnerabilities, 3 critical records, 1 high-severity records, and 3 official publisher updates. Severity alone is not treated as proof of exposure: teams should verify products, versions, reachability, privileges, and available mitigations.

Microsoft remediation should connect the Security Update Guide and active-exploitation signals to the specific products and builds deployed across endpoints, servers, identity platforms, and collaboration infrastructure.

Top verified developments

CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

CISA Known Exploited Vulnerabilities | July 22, 2026 | Known Exploited | Microsoft SharePoint

Source summary: Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a…

CISA lists this issue in the Known Exploited Vulnerabilities catalog, which makes confirmed exploitation the leading prioritization signal. Review the catalog due date and required action, then identify exposed assets before normal severity-only backlog work.

CISA due date: 2026-07-25. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Windows Security review: Check supported builds, update installation, restart state, and the current running version.

Read the current source record

CVE-2026-57092: Windows VMSwitch use-after-free privilege escalation

NIST NVD and Microsoft | July 15, 2026 | CRITICAL | CVSS 9.9 | Microsoft Windows VMSwitch

Source summary: Microsoft describes a network-reachable VMSwitch use-after-free that lets an authorized attacker elevate privileges. The Microsoft CNA rates it 9.9 Critical.

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

Windows Security review: Prioritize domain, federation, collaboration, and internet-facing servers before normal endpoint queues.

Read the current source record

CVE-2026-65590: N8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox…

NIST National Vulnerability Database | July 22, 2026 | CRITICAL | CVSS 9.8

Source summary: n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use…

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

Windows Security review: Review privileged access and endpoint telemetry for signs of abuse before and after patching.

Read the current source record

Shescape: Shell injection via unescaped parentheses on Windows with CMD

GitHub Advisory Database | July 25, 2026 | CRITICAL | GitHub Advisory Database shescape

Source summary: ### Impact This impacts users of Shescape on Windows that explicitly configure `shell` to CMD, or `true` with the default…

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

Windows Security review: Check supported builds, update installation, restart state, and the current running version.

Read the current source record

Rethinking security for the age of AI

Microsoft Security Blog | July 27, 2026

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus