security

Critical Print Spooler Flaw Fixed in July 2026 Patch Tuesday

Valley Printer Pros Team
7 min read

Microsoft's record July 14, 2026 Patch Tuesday fixed CVE-2026-58608, a Critical Windows Print Spooler flaw that any logged-in, low-privilege user could exploit over the network. It wasn't exploited at release. Confirm July's update is installed on every PC, especially the one that shares your printers, and protect staff accounts from phishing.

Key takeaways

  • Microsoft's July 14, 2026 Patch Tuesday was the largest on record, with roughly 570 to 620 vulnerabilities depending on how they're counted.
  • It fixed CVE-2026-58608, a remote code execution flaw in the Windows Print Spooler that Microsoft rates Critical with a CVSS score of 8.8.
  • Any logged-in, low-privilege user could exploit the flaw over the network with no user interaction, which is why a single phished staff account matters.
  • The Print Spooler flaw wasn't publicly disclosed or exploited at release; July's exploited zero-days were in AD FS and SharePoint Server.
  • Confirm the July update, such as KB5101650 on Windows 11 24H2 and 25H2, is installed on every PC and on any machine that shares printers.
Share:
#printer security#windows#patch tuesday#print spooler#vulnerabilities

Microsoft's July 14 Patch Tuesday was the largest on record, and one fix in it deserves special attention from any office that shares a printer. CVE-2026-58608 is a remote code execution flaw in the Windows Print Spooler, the Windows service that manages print jobs, and Microsoft rated it Critical, its highest severity rating.

The good news: Microsoft says the flaw hadn't been publicly disclosed or exploited when the fix shipped. The catch: anyone with an ordinary, low-privilege Windows login could reach it over the network, with no one clicking anything. Here's what the flaw is, why a single phished account matters, and how to confirm your office is covered.

How big was July's Patch Tuesday?

It was a record. BleepingComputer called it record-breaking, The Record called it the largest Patch Tuesday on record, and The Register reported that it topped June's record.

The exact total depends on who's counting, but it lands between roughly 570 and 620 vulnerabilities. Tenable counted 569, BleepingComputer 570, the Zero Day Initiative 621 and SecurityWeek 622. The gap comes mainly from whether you include the CVEs Microsoft published earlier in July, most of them for its Chromium-based Edge browser.

Of the vulnerabilities released on Patch Tuesday itself, 145 were remote code execution flaws and 48 of those were rated Critical, according to Qualys and BleepingComputer. As for why the months keep getting bigger, Microsoft had warned customers that AI-assisted vulnerability discovery would mean busier Patch Tuesdays, The Register reported on July 10, and Help Net Security and Malwarebytes tied the July record to AI-driven bug hunting.

What is the Print Spooler flaw, CVE-2026-58608?

It's a memory bug in how the spooler cleans up printer handles. Microsoft's July 2026 Security Update Guide describes a race condition that leads to a use-after-free: by creating and then closing a printer handle without a related notification handle being properly invalidated, an attacker can make the spooler use memory it has already freed and potentially run code on the system. CrowdStrike and Action1 describe the same mechanism.

DetailCVE-2026-58608
ComponentWindows Print Spooler
ImpactRemote code execution
Microsoft severityCritical
Microsoft CVSS score8.8 (High)
What an attacker needsA logged-in, low-privilege account and network access
User interactionNone
Public or exploited at release?No; Microsoft rated exploitation "Less Likely"
Fixed inJuly 14, 2026 security updates (KB5101650 on Windows 11 24H2 and 25H2)

Microsoft scores the flaw 8.8, and the Zero Day Initiative, CrowdStrike and Action1 report the same figure. If you see 7.5 in a vulnerability database such as SentinelOne's, that matches the separate score NIST assigned in the National Vulnerability Database, which lists Microsoft's 8.8 alongside it. Either way, Microsoft's own rating is Critical.

Who can exploit it, and why does a phished account matter?

Anyone who already has a foothold inside your network. Microsoft's scoring says the attacker must be an authorized user, but only a low-privileged one, and the attack works over the network with low complexity. CrowdStrike summarized that the flaw could "allow a low-privileged remote attacker to execute code with no user interaction and low attack complexity."

In a small office, "low-privilege user" describes almost everyone: the receptionist, the part-time bookkeeper, the summer intern. If a phishing email steals one of those passwords, or malware lands on one laptop, that account is the foothold this bug needs. From there, the most attractive target is whichever Windows machine shares printers with the rest of the office, because it's set up to accept print connections from every PC.

That's why stolen credentials and printer security keep showing up in the same stories. Our post on printer pass-back attacks covers one way printers themselves can leak Windows passwords.

Was the Print Spooler flaw one of July's zero-days?

No. Microsoft's Security Update Guide says CVE-2026-58608 was neither publicly disclosed nor exploited at release, a point SentinelOne and Action1 also make. None of July's exploited flaws involved printing.

On July 14, Microsoft flagged two vulnerabilities as exploited in attacks: CVE-2026-56155 in Active Directory Federation Services (AD FS) and CVE-2026-56164 in SharePoint Server, both elevation-of-privilege flaws. CISA added both to its Known Exploited Vulnerabilities catalog that day. A third flaw had been publicly disclosed before the fix, so BleepingComputer counted three zero-days: two exploited and one publicly disclosed.

Then on July 15, Microsoft corrected the "Exploited" flag on CVE-2026-58644, a SharePoint Server remote code execution flaw with a CVSS score of 9.8, and CISA added it to the catalog on July 16. Rapid7 described it as exploited in the wild. That's why some July coverage says two exploited zero-days and some says three. If your business runs SharePoint Server or AD FS on its own servers, those fixes come first.

How do I know if my office is patched?

Check each PC's update history. Microsoft released its July 2026 security updates on July 14, and for Windows 11 versions 24H2 and 25H2 the update is KB5101650. Other Windows versions receive their own July package through Windows Update. Monthly Windows security updates are cumulative, so a later one also includes July's fixes.

What about Dell PCs?

Some Dells got the July update late. Microsoft temporarily withheld KB5101650 from a limited number of Dell PCs that use an Intel Innovation Platform Framework (IPF) driver, then released out-of-band update KB5121767 on July 18 so those PCs could get the July fixes, according to Microsoft's release health page, BleepingComputer and Windows Latest. If a Dell in your office is missing July's update, look for KB5121767.

What this means for San Fernando Valley offices

If your office shares a copier or printer from one Windows PC or a small file server, that machine is effectively your print server, and it's the first one to check. For example, a small accounting or law office where the office manager's PC "hosts" the copier for everyone else should confirm that PC installed July's update before anything else.

Firms with more than one location have more to watch. For example, a firm with one office in Encino and another in Burbank, connected over a VPN, has more logged-in accounts that can reach the same print server, so account hygiene matters as much as patching. If you carry cyber insurance, it's also worth checking what your policy expects about keeping systems patched; our post on cyber insurance and printers explains why printers belong in that conversation.

This was a busy month for Windows printing overall. If you're setting up new PCs, also check which driver Windows picked under its new Windows Ready Print default, and if you have HP DeskJets at the front desk, see last week's post on the HP DeskJet 2800 flaw.

What to do now

  1. Confirm the July 14 update (or later) is installed on every Windows PC and server, starting with any machine that shares printers.
  2. Check your Dell PCs for KB5121767 if they didn't receive July's regular update.
  3. Patch SharePoint Server and AD FS first if your business runs them on its own servers, since those flaws were exploited.
  4. Turn off the Print Spooler where nobody prints. Servers that never print don't need it running. Never turn it off on a PC or server that shares printers or that people print from, because printing stops. This is common hardening advice, not a Microsoft workaround for this specific flaw, so test before you change it.
  5. Shrink the pool of accounts an attacker could use. Turn on multi-factor authentication, remove accounts for people who have left, and don't give everyday users admin rights.
  6. Give Windows updates an owner. A record month is a good reason to automate updates and make one person responsible for confirming they installed.

If nobody in your office clearly owns Windows updates or printer sharing, book a free virtual consultation and we'll help you work out who should, and what to check first.

Frequently asked questions

What is CVE-2026-58608?
CVE-2026-58608 is a remote code execution vulnerability in the Windows Print Spooler, fixed in Microsoft's July 14, 2026 security updates. Microsoft rates it Critical with a CVSS score of 8.8. A race condition leads to a use-after-free, which a logged-in, low-privilege attacker could use over the network to potentially run code on the system.
Was the July 2026 Print Spooler flaw exploited?
Not at release. Microsoft's Security Update Guide says CVE-2026-58608 had not been publicly disclosed or exploited when the July 14, 2026 fix shipped, and Microsoft rated exploitation "Less Likely." July's exploited zero-days were in Active Directory Federation Services and SharePoint Server, not in printing components.
How many vulnerabilities did Microsoft fix in July 2026?
A record number: roughly 570 to 620, depending on how you count. Tenable counted 569 and BleepingComputer 570, while the Zero Day Initiative counted 621 and SecurityWeek 622. The difference is mainly whether CVEs Microsoft published earlier in July, mostly for its Chromium-based Edge browser, are included.
Do I need to patch PCs that just print to a network printer?
Yes. The Print Spooler runs on Windows PCs as well as servers, and July's security updates fix it along with hundreds of other flaws. Install the July 14, 2026 update or a later one everywhere, and start with any Windows machine that shares printers with the rest of the office, since other PCs connect to it.

Sources

Fact-checked : figures and claims in this article were cross-checked against at least three independent published sources. Where a vendor's own documentation is the only authoritative source, the article attributes the claim to that vendor. The main sources are listed below.

  1. July 2026 Security Updates (Security Update Guide release notes) — Microsoft Security Response Center, 2026-07-14
  2. July 14, 2026 - KB5101650 (OS Builds 26200.8875 and 26100.8875) — Microsoft Support, 2026-07-14
  3. Windows 11, version 25H2 resolved issues — Microsoft Learn (Windows release health)
  4. Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days — BleepingComputer, 2026-07-14
  5. Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days — SecurityWeek, 2026-07
  6. Patchpocalypse Now: Microsoft tops last month's record with 622 Patch Tuesday CVEs — The Register, 2026-07-14
  7. Microsoft warns customers AI will mean busier Patch Tuesdays — The Register, 2026-07-10
  8. Microsoft ships largest Patch Tuesday on record — The Record (Recorded Future News), 2026-07
  9. Microsoft's July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164) — Tenable, 2026-07
  10. The July 2026 Security Update Review — Trend Micro Zero Day Initiative, 2026-07-14
  11. Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review — Qualys Threat Research, 2026-07-14
  12. Patch Tuesday analysis: July 2026 — CrowdStrike, 2026-07
  13. Patch Tuesday July 2026 — Action1, 2026-07
  14. July 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days — Malwarebytes, 2026-07
  15. AI-driven bug hunting fuels record Microsoft Patch Tuesday — Help Net Security, 2026-07-15
  16. CISA Adds Four Known Exploited Vulnerabilities to Catalog — CISA, 2026-07-14
  17. CISA Adds Three Known Exploited Vulnerabilities to Catalog — CISA, 2026-07-16
  18. ETR: CVE-2026-58644 Microsoft SharePoint Server unauthenticated remote code execution vulnerability exploited in the wild — Rapid7, 2026-07
  19. CVE-2026-58608 Detail — NIST National Vulnerability Database
  20. CVE-2026-58608 — SentinelOne vulnerability database
  21. Windows 11 KB5121767 released to fix shutdowns, overheating — Windows Latest, 2026-07-19
  22. Windows KB5121767 OOB update fixes shutdowns on some Dell PCs — BleepingComputer, 2026-07

About Valley Printer Pros Team

Our team of printer industry experts brings decades of experience helping small businesses optimize their printing operations. We provide unbiased advice and practical solutions that save money and improve productivity.

Get Expert Advice

Serving San Fernando Valley Businesses

We provide on-site printer consulting, setup, and lease escape support across the Valley:

Related Articles

security
Blurred PDF Invoices With QR Codes: HP Wolf's Quishing Warning

On September 17, HP Wolf Security reported phishing emails with PDF "invoices" blurred behind a QR code that tells staff to scan it with their phone, leading to a fake Microsoft sign-in page. Tell accounts-payable staff never to scan QR codes in unexpected invoices, verify invoices by phone, and protect Microsoft 365 with MFA.

Sep 28, 20266 min read
security
September 2026 Patch Tuesday: Critical Windows Print Flaw Fixed

Microsoft's September 8, 2026 Patch Tuesday fixed a Critical (CVSS 9.8) Windows HTTP Print Provider flaw, CVE-2026-69769, that needs no sign-in or click, plus Print Spooler privilege bugs. None were exploited, and the month's zero-days weren't print-related. Test the September cumulative update on one PC, then install it everywhere.

Sep 14, 20267 min read
security
PaperCut NG/MF Zero-Days Exploited: What Offices Should Check Now

On August 27, PaperCut warned that attackers were exploiting flaws in its NG and MF print-management software, and on August 31 CISA listed both chained bugs as actively exploited. Ask your copier dealer whether you run PaperCut, restrict its admin page to trusted addresses, patch versions 24 to 26, and upgrade anything older.

Aug 31, 20267 min read

Need Help with Your Printer Decisions?

Don't navigate printer purchases, leases, or problems alone. Our experts provide unbiased advice tailored to your specific business needs.