Recent security updates from Microsoft and Google fix vulnerabilities that deserve attention, including flaws confirmed as exploited in real attacks. That does not mean every Windows PC, Android phone or browser is exposed to the same zero-day.
Two of Microsoft’s most important July 2026 vulnerabilities mainly affect enterprise infrastructure: Active Directory Federation Services and on-premises SharePoint Server. Google’s recently exploited Chrome flaw is more relevant to everyday browser users. On Android, your exposure also depends on the phone manufacturer, model and security patch level.
Apple should not simply be folded into the same story because older reports discussed Apple, Google and Microsoft security fixes at roughly the same time. Apple released new security updates on July 27, 2026, but the Microsoft and Google vulnerabilities covered here are separate issues.
Quick Answer: What Needs Updating Right Now?
Windows users: Install the current security updates offered for your supported version of Windows. Keep in mind that the biggest Microsoft zero-day headlines are not all ordinary home-PC problems. Organizations running AD FS or on-premises SharePoint Server have a much stronger reason to prioritize the July fixes.
Chrome users: Update Chrome and restart the browser. Google confirmed that an exploit for CVE-2026-11645, a V8 vulnerability patched in June, existed in the wild. Chrome has received newer releases since that fix, so the goal should be to run the latest supported stable version rather than stop at the first patched build.
Android users: Check your Android version and security patch level. Google’s June bulletin says a 2026-06-05 security patch level or later addresses all vulnerabilities covered by that bulletin. The catch is that manufacturers do not deliver updates to every phone at the same time.
| Platform | Main Current Concern | Who Should Pay Most Attention | What to Do |
|---|---|---|---|
| Windows / Microsoft | July security updates, including exploited AD FS and SharePoint flaws | Windows users, especially affected enterprise administrators | Install applicable Microsoft security updates |
| Google Chrome | CVE-2026-11645 was exploited in the wild | Chrome users | Update Chrome and restart it |
| Android | CVE-2025-48595 showed signs of targeted exploitation | Users of affected Android versions | Check available updates and your security patch level |
| Apple | Separate July 27 security releases | iPhone, iPad and Mac users | Install the latest supported Apple update; do not assume it is part of the same zero-day campaign |
Why These Zero-Day Headlines Matter
What “zero-day” actually means
A zero-day vulnerability is generally a security flaw for which defenders had no effective vendor patch when attackers or the wider security community became aware of it. The term gets attention because defenders may have had little or no time to prepare.
There is still an important distinction to make: not every serious vulnerability is a zero-day, and not every zero-day is confirmed to be actively exploited.
Actively exploited vs publicly disclosed vs critical
These terms describe different things:
- Actively exploited: There is evidence that attackers are using the vulnerability.
- Publicly disclosed: Information about the flaw became public before or around the time a patch became available. That alone does not prove exploitation.
- Critical: A severity rating based on the potential technical impact under defined conditions.
- Zero-day: A vulnerability for which defenders had little or no patching lead time before disclosure or exploitation.
A critical CVSS score does not mean every affected computer is under attack. At the same time, an exploited vulnerability with a less dramatic severity rating can deserve immediate attention on systems that are actually exposed.
Microsoft’s July 2026 Security Update
Why the July patch release is unusually large
Microsoft’s July 14, 2026 Patch Tuesday addressed an unusually large number of security issues across the company’s products. Contemporary security reports gave different totals, ranging from the high 500s to more than 620 vulnerabilities. The difference comes partly from how researchers count Chromium fixes, cloud issues and individual Microsoft components.
For most readers, the exact total is less useful than a simpler question: which affected Microsoft products do you actually use?
Two confirmed exploited vulnerabilities deserve particular attention.
CVE-2026-56155 — Active Directory Federation Services
CVE-2026-56155 affects Active Directory Federation Services, or AD FS. Microsoft’s vulnerability information describes an access-control weakness that can let an authorized attacker elevate privileges locally.
The vulnerability has also been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.
Does this affect a typical home PC? Usually not in the way the headline may suggest. AD FS is enterprise identity infrastructure. Most home Windows users are not running an AD FS server.
For organizations that do use it, the confirmed exploitation status gives the issue a much higher patching priority.
CVE-2026-56164 — Microsoft SharePoint Server
CVE-2026-56164 affects versions of Microsoft’s on-premises SharePoint Server. The flaw involves missing authentication for a critical function and can allow an unauthenticated attacker to elevate privileges over a network on affected systems.
It has also been identified as actively exploited.
Again, the product matters. A person using a Windows 11 laptop at home is not automatically running SharePoint Server. Organizations hosting affected SharePoint infrastructure need to treat this as an urgent server-security issue rather than a generic Windows problem.
CVE-2026-50661 — Windows BitLocker
CVE-2026-50661 is a Windows BitLocker security-feature bypass affecting multiple supported Windows configurations. Microsoft’s description involves a physical attack that can bypass a security mechanism.
The vulnerability was publicly disclosed, but it should not be grouped with CVE-2026-56155 and CVE-2026-56164 as one of the two confirmed actively exploited July flaws unless there is evidence supporting that claim.
This is why simply telling readers there were “three zero-days” can be misleading. The exploitation status and affected product matter more than the count.
What ordinary Windows users should do
For a home Windows PC, the response is fairly simple:
- Confirm that your version of Windows is still supported.
- Open Settings > Windows Update.
- Check for available security updates.
- Install the updates offered for your system.
- Restart when Windows asks you to finish installation.
You do not need SharePoint or AD FS fixes on a PC that does not run those products. For home users, Windows Update and Microsoft’s support lifecycle are the more useful guides.
What enterprise administrators should prioritize
Enterprise teams need a more targeted response. Administrators should determine whether their organization runs affected AD FS or on-premises SharePoint Server versions, verify the exact deployments and apply Microsoft’s relevant security updates and mitigations.
Internet exposure, identity-system importance, authentication design and existing patch-management controls all affect how urgent the risk is in a specific environment.
Google’s Recent Chrome Zero-Day Fix
What CVE-2026-11645 affects
Google patched CVE-2026-11645 in Chrome in June 2026. The vulnerability involves out-of-bounds memory access in V8, Chrome’s JavaScript and WebAssembly engine.
Google explicitly said it was aware that an exploit for CVE-2026-11645 existed in the wild.
This makes the issue more relevant to ordinary users than an enterprise SharePoint vulnerability. Chrome processes content from websites during normal browsing, so browser flaws sit much closer to everyday computer use.
Why restarting Chrome matters
Chrome handles much of its updating automatically, but an update is not always active the moment it downloads.
If Chrome asks for a relaunch, restart the browser. That allows the newer browser version to replace the one still running.
To check manually:
- Open Chrome.
- Open the three-dot menu.
- Select Help.
- Select About Google Chrome.
- Let Chrome check for updates.
- Select Relaunch if prompted.
Google’s first June fix for CVE-2026-11645 appeared in Chrome 149, but Chrome has received multiple releases since then. There is little reason to aim for that old minimum version now. Install the latest supported stable build available for your system.
What Edge, Brave and other Chromium users should check
Microsoft Edge, Brave, Opera, Vivaldi and several other browsers use Chromium code, but they are separate products with their own release schedules.
A Chrome update does not mean every Chromium-based browser received the same fix at exactly the same time.
Use the update or About page in the browser you actually use and confirm that its latest security release is installed.
Google’s Android Security Updates
The actively exploited Android issue
Google’s June 2026 Android Security Bulletin included CVE-2025-48595, a high-severity Android Framework vulnerability. Google said there were indications that it may be under limited, targeted exploitation.
CISA later added CVE-2025-48595 to its Known Exploited Vulnerabilities catalog.
Contemporary reports counted 124 vulnerabilities addressed by the June Android security update. For an individual phone owner, though, the more useful question is whether that phone has actually received the relevant patch.
Why Android patch availability varies
Android runs across hardware from many manufacturers. Google publishes Android security fixes, but the timing of an update can still depend on the manufacturer, hardware components, carrier, model support policy and device-specific software.
Google’s June bulletin says a security patch level of 2026-06-05 or later addresses all vulnerabilities covered by that bulletin.
A newer patch level is better because later monthly releases can include additional fixes.
How to check your Android security patch level
The exact menu varies by phone, but on many Android devices you can start with:
Settings > About phone > Android version
Look for entries such as:
- Android version
- Android security update
- Google Play system update
You can also search the Settings app for Security update or System update.
If an older phone no longer offers security updates, check the manufacturer’s support policy for that exact model. A phone that has stopped receiving patches is a different security proposition from one that still receives regular fixes, especially if you use it for sensitive accounts or work.
What About Apple?
Do not confuse older Apple zero-day stories with current reports
Past security stories have described Apple, Google and Microsoft patching exploited vulnerabilities around the same time. Those reports should not be reused as if they describe one coordinated July 2026 event.
The Microsoft AD FS and SharePoint flaws, Google’s Chrome V8 vulnerability and Google’s Android vulnerability discussed here are separate security issues.
Apple released new security updates on July 27
Apple’s official security-release information lists new updates released on July 27, 2026, including iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6 and Safari 26.6, along with updates for other supported Apple platforms.
Those advisories contain numerous security fixes. They do not, however, establish that Apple’s July releases are part of the same Microsoft and Google zero-day story. Exploitation should only be claimed for a specific Apple vulnerability when Apple’s advisory or another authoritative source supports it.
For Apple users, the action is still simple: open Software Update and install the newest release supported by your device.
Does This Security Issue Affect You?
Windows home users
Action: Install your normal Windows security updates and make sure the Windows version you use is still supported.
Do not assume the AD FS and SharePoint headlines mean those enterprise services are installed on your PC.
Microsoft enterprise administrators
Action: Check whether affected AD FS or on-premises SharePoint products are deployed and prioritize Microsoft’s patches and mitigation guidance where they apply.
The two exploited Microsoft vulnerabilities deserve the most attention in environments actually running those services.
Chrome users
Action: Update Chrome and restart it.
Google confirmed that an exploit for CVE-2026-11645 existed in the wild. For ordinary desktop users, completing the browser update is one of the clearest actions to take.
Android users
Action: Check both available system updates and your Android security patch level.
Your phone model matters. Google publishing a patch does not mean every manufacturer delivered it to every supported handset that same day.
Apple users
Action: Check for Apple’s July 27 or later security releases supported by your hardware.
Treat Apple’s current advisories separately rather than assuming they describe the same vulnerabilities affecting Microsoft or Google products.
What You Should Do Now
1. Install supported operating-system updates
Start with the vendor’s own security update. If a patch is available, it fixes the vulnerable software itself rather than trying to work around the problem with another product.
2. Update and restart browsers
Browsers regularly process untrusted content from websites, which makes timely patching especially important. Check Chrome or the Chromium-based browser you use and complete any required relaunch.
3. Check support status, not just the version number
A device can still work normally after it has stopped receiving security patches. This applies to older Windows installations, aging Android phones and Apple hardware that has fallen outside current support.
4. Prioritize exposed enterprise services
Organizations running AD FS, SharePoint Server or other internet-accessible Microsoft infrastructure should review July Patch Tuesday with those deployments in mind. Confirm the exact versions in use, their exposure and Microsoft’s guidance.
5. Do not replace patching with a purchase
Antivirus software, a new router or another security product does not remove a vulnerability from an unpatched operating system, browser or server.
When the vendor has released a fix, applying that fix is the primary response.
What These Updates Cannot Guarantee
Installing a security update closes the vulnerabilities addressed by that update. It does not prove that the device was never compromised before the patch was installed.
That distinction matters most for organizations that have signs of suspicious activity or systems exposed to a vulnerability known to be exploited. In those cases, patching may need to be followed by log review, endpoint investigation, credential review or a broader incident-response process.
For ordinary users with no signs of compromise, there is little reason to panic. Keep supported software current, restart when updates require it, remove obsolete software you no longer use and avoid leaving browser or operating-system security updates pending for long periods.
FAQ
What is a zero-day vulnerability?
A zero-day is a security vulnerability for which defenders had little or no effective patching lead time before the flaw became known or was exploited. It does not automatically mean every device using software from that vendor is affected.
Which Microsoft zero-days were exploited in July 2026?
Two important vulnerabilities confirmed as actively exploited are CVE-2026-56155, affecting Active Directory Federation Services, and CVE-2026-56164, affecting Microsoft SharePoint Server.
CVE-2026-50661, involving Windows BitLocker, was publicly disclosed but should not be described as one of those two confirmed exploited vulnerabilities without additional evidence.
Does Microsoft’s July 2026 update affect ordinary Windows users?
Yes. July’s security updates cover Windows and many other Microsoft technologies, so supported Windows PCs should be kept updated. The two most prominent exploited vulnerabilities, however, concern AD FS and SharePoint Server, which are primarily enterprise technologies rather than services installed on every home computer.
Has Google patched an actively exploited Chrome zero-day in 2026?
Yes. Google confirmed that an exploit for CVE-2026-11645, an out-of-bounds memory-access vulnerability in Chrome’s V8 engine, existed in the wild. Google patched the issue in June 2026.
How do I check whether Chrome is fully updated?
In Chrome, open Menu > Help > About Google Chrome. Chrome will check for updates automatically. Relaunch the browser if requested. Since Chrome has received newer releases since the original zero-day fix, use the latest supported stable version rather than comparing only against the first patched build.
Are Microsoft Edge and other Chromium browsers affected by Chrome vulnerabilities?
Chromium-based browsers share a substantial amount of underlying code, so some Chromium vulnerabilities can affect several browsers. Edge, Brave, Opera, Vivaldi and others still have their own release schedules. Check the update status of the browser you use rather than assuming a Chrome update also updated another browser.
How do I check my Android security patch level?
On many phones, open Settings > About phone > Android version and look for the Android security update or security patch level. Menu names vary by manufacturer. Google’s June 2026 bulletin says patch level 2026-06-05 or later addresses all issues covered by that bulletin.
Does antivirus software protect me from an unpatched zero-day?
Security software may detect or block some malicious activity, but it is not a substitute for an available vendor patch. Detection tools and vulnerability fixes address different parts of the problem. When an operating-system, browser, application or server update is available, install it.
Final Takeaway
Apple, Google and Microsoft are not dealing with one giant shared zero-day attack.
Microsoft’s July 2026 updates include two confirmed exploited vulnerabilities that matter most to organizations running AD FS and on-premises SharePoint Server. Google’s CVE-2026-11645 Chrome zero-day is more directly relevant to everyday browsing. On Android, CVE-2025-48595 is another reason to check the security patch level your phone has actually received.
Apple released a separate set of security updates on July 27, 2026. Install them where applicable, but do not treat them as part of the Microsoft and Google zero-day story without vulnerability-specific evidence.
The practical rule is straightforward: identify the product you use, check that it is still supported, install the vendor’s available security update and complete any required restart.
A large vulnerability count tells you that a patch cycle was busy. Your own software and device inventory tells you what actually needs attention.