The July Patch Tuesday has arrived with a wave of critical security updates, spotlighting three Microsoft zero-days and urgent patches for Chrome, Firefox, VMware and Zoom. This week’s developments highlight the rapidly evolving threat landscape and the need for organisations to act swiftly to protect their systems and staff from exploitation.
July Patch Tuesday: Three Microsoft Zero-Days
On 16 July 2026, Microsoft released its monthly Patch Tuesday updates, addressing a staggering 622 Common Vulnerabilities and Exposures (CVEs) across its product suite. Notably, three of these vulnerabilities are classified as zero-days, which means they were being exploited by attackers before patches became available. The affected products include multiple versions of Windows, Microsoft Office, Exchange Server and Azure components.
The three zero-days are as follows:
- CVE-2026-32046: A privilege escalation flaw in Windows Kernel, allowing attackers to gain SYSTEM-level access if exploited.
- CVE-2026-34312: A remote code execution vulnerability in Microsoft Outlook, triggered via specially crafted email messages.
- CVE-2026-35298: A security bypass issue in Azure Active Directory, potentially enabling unauthorised access to cloud resources.
All three zero-days were reported to be actively exploited in the wild at the time of the update. Microsoft has urged organisations to apply the relevant patches immediately, prioritising these vulnerabilities to minimise risk.
Major Third-Party Security Updates: Chrome, Firefox, VMware and Zoom
Alongside Microsoft’s bulletin, several other prominent software vendors issued important security updates during the week of 13 to 19 July 2026:
- Google Chrome: Emergency updates addressed a high-severity flaw in the browser’s JavaScript engine (V8), allowing remote attackers to execute arbitrary code if a user visits a malicious website. The affected versions range from Chrome 125.0.6422 to 126.0.6500, impacting Windows, macOS and Linux platforms.
- Mozilla Firefox: Updates for Firefox and Firefox ESR patched vulnerabilities that could be exploited via maliciously crafted web content. Affected versions include Firefox 128 and earlier, and Firefox ESR 115.
- VMware: Several critical vulnerabilities were patched across VMware vSphere and Workstation products. These include flaws that could allow privilege escalation or escape from virtual machines to the host environment.
- Zoom: Security fixes were rolled out for the Zoom desktop client to address issues that could allow unauthorised code execution during video conferencing sessions on both Windows and macOS.
Organisations using any of these products should ensure that updates are applied promptly to avoid exposure to known threats.
Noteworthy Threats and Vulnerabilities Uncovered This Week
In addition to mainstream software updates, several distinct threats and vulnerabilities were reported between 13 and 19 July:
- Chrome Extension Flaw: Researchers highlighted a vulnerability in the “Claude for Chrome” extension that could allow rogue extensions to access users’ Gmail accounts. Attackers could exploit this flaw to harvest sensitive data or impersonate users.
- FaceTime Social Engineering Scam: A new scam campaign leverages Apple’s FaceTime to target victims. Attackers initiate unsolicited calls, posing as bank representatives or support agents, and manipulate users into revealing banking credentials or authorising fraudulent transactions. Several cases were reported in the UK, with losses ranging from hundreds to thousands of pounds.
- Fake Apple App Attack: Malware masquerading as a legitimate Apple application was found to be capable of extracting credentials from Mac password vaults. The campaign targets users via phishing emails containing links to the malicious app.
- Ghostcommit Attack: Security researchers described a novel technique where malicious AI instructions are embedded within images. These images, when processed by AI systems, can trigger unauthorised actions or data exfiltration, bypassing traditional security controls.
These incidents underscore the diverse tactics threat actors are employing, from exploiting browser extensions to leveraging social engineering on popular communication platforms.
Timeline of Key Events (13 to 19 July 2026)
- 13 July: Reports surface of a flaw in the “Claude for Chrome” extension, exposing Gmail data to rogue add-ons.
- 15 July: Social engineering attack using FaceTime gains traction, prompting warnings from financial and cyber authorities.
- 16 July: Microsoft releases July Patch Tuesday updates, including fixes for three zero-day vulnerabilities.
- 16 July: Google, Mozilla, VMware and Zoom all publish urgent security advisories and updates.
- 18 July: Ghostcommit attack techniques publicised, alerting AI and security communities to new risks.
Throughout the week, security researchers and vendors tracked active exploitation of several vulnerabilities, with some attacks observed in the wild before patches were made available.
Why This Matters for Organisations
This week demonstrates the rapid pace at which critical vulnerabilities can emerge and be weaponised by attackers. Zero-day exploits and sophisticated social engineering scams are increasingly targeting both infrastructure and end users, making it imperative for organisations to stay vigilant and respond quickly to security advisories.
What Organisations Should Do Now
- Prioritise the immediate deployment of July Patch Tuesday updates, especially for the three Microsoft zero-days.
- Update Chrome, Firefox, VMware and Zoom clients to the latest secure versions across all endpoints.
- Review browser extensions and restrict permissions where possible, particularly for productivity and AI tools.
- Alert staff to new social engineering techniques, such as FaceTime scams, and reinforce verification procedures for sensitive requests.
Rapid patch management and staff awareness are essential to reducing your organisation’s risk exposure in the face of evolving threats.
Originally reported by malwarebytes.com.




