A record Patch Tuesday fixes a 9.6 Copilot bug as Microsoft credits AI for the flood
An AI assistant that a malicious web page can turn into a remote-code vector, in the same release AI made the biggest in the program's history. The tool and the threat are the same technology.
- Microsoft's July 2026 Patch Tuesday is the largest in the program's history, with 570 flaws fixed by Krebs on Security's count and 622 total by TechRadar's, nearly triple June's record.
- The AI headline item is CVE-2026-48561, a CVSS 9.6 remote-code-execution flaw in Microsoft Copilot: a malicious website can make Edge for Android auto-send crafted prompts to Copilot.
- Microsoft attributes the ballooning patch counts to AI-assisted vulnerability discovery across the Windows codebase; three zero-days, two already exploited, were also fixed.
The July Patch Tuesday is a two-sided AI story, and both sides are unsettling. It is the largest release in the program's history, with 570 security flaws fixed by Krebs on Security's count and 622 by TechRadar's, nearly triple June's own record. Microsoft says the volume is exploding because AI is now finding vulnerabilities faster than humans ever could.
An assistant as an attack vector
The item for this beat is CVE-2026-48561, a remote-code-execution flaw in Microsoft Copilot rated CVSS 9.6. An attacker who hosts a malicious website can cause Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the page, turning the AI assistant into a network-reachable code-execution vector. It shipped alongside roughly 60 critical flaws, about 250 privilege-escalation bugs, and three zero-days, two of them already exploited. The other side of the release is the cause: "The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code," Microsoft EVP Pavan Davuluri said. Dark Reading framed the result as a triage-overload problem, since AI can now surface flaws faster than security teams can patch them.
The tool and the threat are one technology
Put the two halves together and you get the shape of agent-era security. The same capability that makes Copilot useful is what a crafted prompt weaponizes, exactly the lesson from the Claude for Chrome flaw where autonomy turned a High into a Critical. And the same capability that lets defenders find bugs faster lets attackers do the same, which is why 99.9 percent of fixable AI vulnerabilities sit unpatched: discovery is scaling, remediation is not. A record patch pile is not reassurance that the system is working. It is evidence the volume has outrun the humans, and the assistants finding the flaws are also, occasionally, the flaws.