Dev.to
7/17/2026

Microsoft patch record, agentic coding tool vulnerabilities, and what to run this week
Original: AI Worked Both Sides of the Security Ledger This Week. Here's What to Actually Run
Short summary
Microsoft shipped a record 570+ CVEs on July Patch Tuesday, with two zero-days under active exploitation (ADFS privilege escalation and SharePoint unauthenticated escalation). The same week exposed critical vulnerabilities in agentic coding tools: Wiz's GhostApproval symlink attack affects Cursor, Amazon, Google, and others, while AI Now Institute's Friendly Fire targets the workflow of pointing agents at untrusted repos. Both break the human-in-the-loop trust model that agentic coding relies on.
- •Two Microsoft zero-days actively exploited: CVE-2026-56155 (ADFS privesc) and CVE-2026-56164 (SharePoint unauth escalation)
- •GhostApproval symlink attack tricks approval dialogs in agentic coding tools (Cursor, Amazon, Google affected)
- •Friendly Fire exploit targets agents reviewing untrusted repos, changing procurement requirements
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



