If Windows Update has been nagging you more than usual this week, there’s a good reason: Microsoft’s July 2026 Patch Tuesday fixed a record-breaking 570 vulnerabilities — the largest single security release in the company’s history — including two zero-days that were already being exploited in the wild before the fix shipped. Most people click “remind me tomorrow” on these updates without a second thought. This month, that’s a genuinely bad habit to keep.
You don’t need to understand what a “security feature bypass” is or read a CVE database to protect yourself. You need to know what to update, in what order, and what to double-check afterward. That’s what this guide covers.
What actually happened on July 14
Security researchers and Microsoft’s own teams flagged 570 distinct vulnerabilities across Windows and related products this Patch Tuesday — up sharply from a typical month, which usually runs somewhere between 100 and 150. Of those, 59 are rated “Critical,” and 48 of those critical bugs allow remote code execution, meaning an attacker could run arbitrary code on your machine without ever touching it physically. The full breakdown: 254 elevation-of-privilege flaws, 145 remote code execution bugs, 102 information disclosure issues, 35 denial-of-service bugs, 17 security feature bypasses, and 16 spoofing vulnerabilities.

Microsoft has attributed part of the unusually high count to a new AI-powered vulnerability-discovery system the company recently deployed internally, which proactively scans the Windows codebase for flaws before attackers find them first. That’s good news for long-term security, but it means big, alarming-looking patch counts like this one may become more common, not less.
The two vulnerabilities you should actually worry about
Out of 570 fixes, two matter most for the average person:
CVE-2026-56164 affects Microsoft SharePoint Server — a missing authentication check that lets an unauthorized network attacker escalate privileges. This one is already being actively exploited, though it primarily threatens organizations running on-premises SharePoint servers rather than home users.
CVE-2026-50661 is a BitLocker security feature bypass. It’s publicly disclosed (meaning attackers know exactly how it works) but requires physical access to your device to exploit — someone would need to have your laptop in their hands. If you travel with a laptop or it ever leaves your sight (checked luggage, a shared office, a repair shop), this is the one to patch immediately.
Step 1: Update Windows first, today
Go to Settings → Windows Update → Check for updates, and install everything offered, including optional driver updates flagged as security-related. If your PC is set to “active hours” that delay restarts, temporarily override that and restart as soon as the update finishes downloading — a patch that’s downloaded but not yet applied through a restart does nothing to protect you.
Step 2: Check your BitLocker status if you use a laptop
Open Settings → Privacy & Security → Device encryption (or search “BitLocker” in the Start menu) and confirm encryption is still active after the update. In rare cases, major cumulative updates can interact oddly with BitLocker configurations, and given that this month’s patch specifically targets a BitLocker bypass, it’s worth the 30 seconds to verify.
Step 3: Update everything else that touches your network
Patch Tuesday only covers Microsoft products, but a record-breaking month is a good prompt to check everything else with an internet connection: your router’s firmware, your browser, and any other software that auto-updates but rarely gets checked manually. If your home network hardware is aging, we’ve covered how to speed up your home Wi-Fi in more detail, and router firmware updates are usually bundled into that same maintenance routine.
Pro tip: don’t rely on “Patch Tuesday” alone
Most people only think about Windows security once a month, on the second Tuesday, because that’s when Microsoft batches its releases. But zero-days like CVE-2026-56164 get discovered and exploited on their own schedule — not Microsoft’s. The single highest-leverage thing you can do is simply turn on automatic updates and stop deferring restarts, so fixes land as soon as they’re available rather than whenever you next remember to check manually. If you’re the type to put off restarts for days because you don’t want to lose open tabs or documents, that habit is exactly what this month’s record patch count is warning against.
If you want extra insurance: back up before you patch
Major cumulative updates carry a small but real risk of installation issues on older or heavily customized systems. Before installing this month’s update, it’s worth backing up anything irreplaceable — photos, documents, project files — to an external drive or cloud storage. If you don’t already have a reliable backup routine, our guide to the best portable SSDs covers drives fast enough that a full backup doesn’t eat your whole evening.
Frequently Asked Questions
Do I need to do anything special, or does Windows Update handle everything?
For most home users, Windows Update handles the actual patching automatically once you check for updates and restart. The manual steps in this guide are about making sure that process actually runs promptly and that specific high-risk settings like BitLocker aren’t affected.
Is my PC at risk if I haven’t updated yet?
Yes, more than usual. With two zero-days already being exploited or publicly known, the window between “patch available” and “patch installed” is the most dangerous time. Update as soon as you can rather than waiting for a convenient moment.
Why was this month’s patch so much bigger than normal?
Microsoft says its new AI-assisted vulnerability scanning found more issues proactively than manual review typically catches in a single month. It’s a sign of more thorough scanning, not necessarily that Windows suddenly became less secure.
Does this affect Mac or Linux users?
No — this specific Patch Tuesday release is Windows- and Microsoft-product-specific. Mac and Linux systems have their own separate update cycles and were not part of this release.
Security news like this rarely stays interesting for long, and that’s kind of the point — the goal is to patch, verify, and move on with your day. The bigger habit worth building isn’t panicking over any single record-breaking month, but making sure updates never sit unapplied for more than a day or two, regardless of how big the headline number is.
Deixe um comentário