Agentic market $10.8B and climbing  ·  editor@gaasnews.com
Sections
HomeWhat is GaaS?PlatformsPricingGlossaryOpinionAboutContact
HomeEvaluation & SafetyPatch Tuesday Copilot
Evaluation & Safety

A record Patch Tuesday fixes a 9.6 Copilot bug as Microsoft credits AI for the flood

An AI assistant that a malicious web page can turn into a remote-code vector, in the same release AI made the biggest in the program's history. The tool and the threat are the same technology.

AJ
Andrew Jamerson
Founding Editor
Jul 16, 2026 · 4 min read
Illustration: the patch pile hits a new record. // GaaS News
TL;DR
  • Microsoft's July 2026 Patch Tuesday is the largest in the program's history, with 570 flaws fixed by Krebs on Security's count and 622 total by TechRadar's, nearly triple June's record.
  • The AI headline item is CVE-2026-48561, a CVSS 9.6 remote-code-execution flaw in Microsoft Copilot: a malicious website can make Edge for Android auto-send crafted prompts to Copilot.
  • Microsoft attributes the ballooning patch counts to AI-assisted vulnerability discovery across the Windows codebase; three zero-days, two already exploited, were also fixed.

The July Patch Tuesday is a two-sided AI story, and both sides are unsettling. It is the largest release in the program's history, with 570 security flaws fixed by Krebs on Security's count and 622 by TechRadar's, nearly triple June's own record. Microsoft says the volume is exploding because AI is now finding vulnerabilities faster than humans ever could.

An assistant as an attack vector

The item for this beat is CVE-2026-48561, a remote-code-execution flaw in Microsoft Copilot rated CVSS 9.6. An attacker who hosts a malicious website can cause Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the page, turning the AI assistant into a network-reachable code-execution vector. It shipped alongside roughly 60 critical flaws, about 250 privilege-escalation bugs, and three zero-days, two of them already exploited. The other side of the release is the cause: "The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code," Microsoft EVP Pavan Davuluri said. Dark Reading framed the result as a triage-overload problem, since AI can now surface flaws faster than security teams can patch them.

The tool and the threat are one technology

Put the two halves together and you get the shape of agent-era security. The same capability that makes Copilot useful is what a crafted prompt weaponizes, exactly the lesson from the Claude for Chrome flaw where autonomy turned a High into a Critical. And the same capability that lets defenders find bugs faster lets attackers do the same, which is why 99.9 percent of fixable AI vulnerabilities sit unpatched: discovery is scaling, remediation is not. A record patch pile is not reassurance that the system is working. It is evidence the volume has outrun the humans, and the assistants finding the flaws are also, occasionally, the flaws.

AJ

Andrew Jamerson

Founding Editor, GaaS News

Andrew Jamerson is the founding editor of GaaS News, covering the economics of the agent era. He started the publication to cover Agentic AI as a Service as a dedicated beat and edits every article on the site.

Be on the list when the beat breaks

One email when a platform ships, a round closes, or the ground shifts under the software stack.