Microsoft released its most extensive Patch Tuesday to date in July 2026, delivering an unprecedented volume of security updates that address 622 unique Common Vulnerabilities and Exposures (CVEs) within its product ecosystem. This staggering figure more than triples the previous high of approximately 200 CVEs patched in June, signaling a significant shift in the company’s vulnerability management strategy. Of paramount concern are two critical zero-day vulnerabilities, actively exploited in the wild, which demand immediate attention from organizations globally. These include an elevation-of-privilege flaw in on-premises SharePoint Server (CVE-2026-56164) and another in Active Directory Federation Services (AD FS) (CVE-2026-56155), both posing substantial risks despite not being classified as remote code execution (RCE) flaws.
The Unprecedented Scale of July 2026 Patch Tuesday
The sheer volume of security fixes released this month marks a historical high for Microsoft. Typically, July is considered one of the quieter periods on Microsoft’s update calendar, making this record-setting release particularly noteworthy. The 622 CVEs cover a broad spectrum of Microsoft products and services, with Windows alone accounting for 416 of these vulnerabilities. The drastic increase in reported flaws is, in part, attributed to Microsoft’s evolving vulnerability management strategies, including the enhanced use of artificial intelligence in discovery, as detailed in a July 9 blog post. While a high volume of patches is indicative of a proactive security posture, it simultaneously presents significant challenges for IT departments tasked with rapid deployment and prioritization.
Critical Zero-Days Under Active Exploitation: An Urgent Call to Action
The most pressing concern from this colossal update are the two zero-day vulnerabilities already being leveraged by attackers. These flaws highlight a crucial trend: the focus for security teams must shift from solely high-severity RCEs to any vulnerability actively exploited, regardless of its initial CVSS score or type.
CVE-2026-56164: SharePoint Server’s Remote Elevation of Privilege
This critical vulnerability affects on-premises SharePoint Server installations, allowing an unauthenticated attacker to escalate privileges over the network. The ability for an attacker to gain elevated access without requiring any credentials or user interaction, and from a remote location, makes this flaw exceptionally dangerous. Microsoft has credited Mandiant’s incident responders and Google’s FLARE team for its discovery, strongly indicating that the vulnerability was identified during active attack campaigns. Although Microsoft has not publicly disclosed specifics regarding the nature of the exploits or the identities of the attackers, the involvement of prominent incident response firms underscores the severity and active nature of the threat.
The urgency to patch this particular vulnerability is further compounded by a critical timeline convergence: July 2026 also marks the end of extended support for SharePoint Server 2016 and 2019. Unlike some other Microsoft enterprise products, these SharePoint versions do not offer a paid Extended Security Update (ESU) program, leaving organizations running unpatched versions completely exposed to this and any future vulnerabilities. Beyond immediate patching, Microsoft’s advisory suggests enabling AMSI (Antimalware Scan Interface) in Full Mode on SharePoint servers as an additional mitigation measure. SharePoint has historically been a prime target for adversaries, with notable attack chains like the "ToolShell chain" in 2025 devastating unpatched servers, cementing its status as a high-value asset for attackers.
CVE-2026-56155: Active Directory Federation Services (AD FS) Local Privilege Escalation
The second actively exploited zero-day, CVE-2026-56155, is an Active Directory Federation Services (AD FS) flaw. This vulnerability allows an already-authenticated attacker to elevate their privileges locally through weak access controls. While classified as "local" and requiring prior authentication, its impact should not be underestimated. AD FS plays a pivotal role in enterprise identity management, acting as the central authority that signs authentication tokens for federated services across an entire IT estate. A compromise of AD FS, even via a local privilege escalation, can grant attackers profound control over user identities and access rights, effectively undermining the entire security perimeter. Microsoft’s own DART (Detection and Response Team) incident-response unit is credited with discovering this flaw, again pointing to its identification within an active threat landscape. Details on the specific privileges granted or the methods used by attackers remain undisclosed, but the strategic importance of AD FS mandates immediate remediation.

Immediate Action and Discrepancies in Threat Prioritization
It is critical for organizations to prioritize patching these two actively exploited zero-days without delay. While neither CVE had appeared on CISA’s Known Exploited Vulnerabilities (KEV) catalog at the time of this writing, Microsoft’s own exploitability rating unequivocally marks both as exploited. This discrepancy underscores the need for security teams to rely on multiple threat intelligence sources and not solely wait for KEV listings to validate urgency. Furthermore, Microsoft’s relatively low severity rating for the SharePoint bug serves as a stark reminder that conventional severity labels may not accurately reflect the real-world risk posed by actively exploited vulnerabilities. The presence of an active exploit should always supersede a theoretical severity score.
Other Noteworthy Vulnerabilities and Looming Threats
Beyond the immediate zero-day threats, the July Patch Tuesday includes several other significant fixes that warrant attention.
The Publicly Disclosed BitLocker Bypass (CVE-2026-50661)
A third zero-day, CVE-2026-50661, addresses another BitLocker bypass vulnerability. This flaw, while publicly disclosed, is not currently under active attack. It requires physical access to the device, making it less of an immediate remote emergency but still a significant concern for endpoint security. This vulnerability continues a concerning trend of BitLocker bypasses, following previous incidents like "bitskrieg" and "YellowKey" earlier this year. Organizations should patch this to maintain the integrity of their device encryption, especially for mobile devices or those in less secure physical environments.
SharePoint’s Unfolding Threat: The Rapid7 Pwn2Own Chain (CVE-2026-55040)
SharePoint also received another notable fix for CVE-2026-55040, a JWT authentication bypass. This vulnerability was publicly disclosed by Rapid7 Labs, who successfully chained it with a separate remote code execution (RCE) bug to achieve unauthenticated RCE against a vulnerable server during Pwn2Own Berlin. While the JWT bypass is patched in July, the crucial RCE component of the chain is not slated for a fix until August. This means that while the "bypass" element is now mitigated, the full RCE chain remains a potential threat until next month’s updates. The severity rating for this bug itself has been a point of contention, with Rapid7 assigning it a 5.3 (medium) and Microsoft also labeling it as medium, while ZDI’s independent analysis reads the release as Critical at 9.1. This four-point spread on a single vulnerability further illustrates the subjective nature of severity scores and reinforces the need for a comprehensive risk assessment beyond a single numerical rating.
Long-Term Security Changes: Kerberos RC4 Hardening Culminates
This Patch Tuesday also marks a significant milestone in Microsoft’s multi-year effort to harden Kerberos authentication protocols by deprecating RC4. The July update definitively removes the RC4DefaultDisablementPhase rollback switch, which has served as an emergency escape hatch for administrators since the crackdown began in January. Moving forward, RC4 will only function for accounts explicitly configured to allow it.
This change carries substantial implications: any service account in an environment that still requests RC4 Kerberos tickets risks immediate authentication failure once the update is applied. To prevent widespread service disruptions, organizations must undertake a meticulous auditing process before deploying the July patches. This involves utilizing the RC4 audit events that Microsoft introduced in January to identify all accounts relying on RC4. Following the audit, administrators must rotate the passwords on all flagged service accounts to ensure Windows generates stronger AES keys for them. Password rotation alone will address accounts that simply lack AES keys. However, any legacy clients or configurations explicitly pinned to RC4 will require a dedicated fix or upgrade prior to the update. This particular change, while not a direct security breach vector, can cause significant operational outages, underscoring the importance of proactive change management.
Deeper Dive: Breakdown of Vulnerabilities by Product Family

The July 2026 Patch Tuesday’s record-breaking 622 CVEs are distributed across various Microsoft product families, each presenting its own set of risks:
- Windows (416 CVEs): This category hosts the AD FS zero-day (CVE-2026-56155) and the publicly disclosed BitLocker bypass (CVE-2026-50661). Noteworthy within Windows is a VMSwitch RCE, CVE-2026-57092, which boasts the highest CVSS score of the release at 9.9. Additionally, five DHCP RCEs and 21 NTFS and ReFS driver bugs, which ZDI analysis suggests may share a common root cause, were addressed.
- Office (82 CVEs): Microsoft lists these 82 vulnerabilities once, but they are also counted again under a separate Office 2016 track, leading some outlets to report 164. These typically include various security feature bypasses, information disclosure, and remote code execution vulnerabilities across the Office suite.
- Microsoft Edge (46 CVEs): ZDI independently counts 21 of these as Microsoft’s own vulnerabilities, distinct from Chromium re-listings, indicating specific Edge-related security enhancements.
- Developer Tools (27 CVEs): This category includes security feature bypasses across Visual Studio, VS Code, and GitHub Copilot, predominantly addressing injection and path traversal vulnerabilities that could impact development workflows and code integrity.
- SharePoint Server (17 CVEs): Beyond the actively exploited zero-day (CVE-2026-56164) and Rapid7’s chain bypass (CVE-2026-55040), SharePoint received fixes for a critical RCE pair, including CVE-2026-50522, rated at 9.8.
- Azure (11 CVEs): While no vulnerabilities were flagged as immediately urgent within this release, these patches contribute to the ongoing security hardening of Microsoft’s cloud platform.
- SQL Server (8 CVEs): This includes an RCE pair, CVE-2026-54117 and CVE-2026-54118, both rated at 8.8, which could allow attackers to execute arbitrary code on affected SQL servers.
- Defender (5 CVEs): Two critical RCEs were addressed in Microsoft Defender, highlighting the continuous need to secure endpoint protection solutions themselves.
- Exchange Server (5 CVEs): A significant fix here is a stored XSS (Cross-Site Scripting) vulnerability in Outlook Web Access, CVE-2026-55008, rated at 9.6. Microsoft categorized it under spoofing, which security experts argue undersells its true impact, as stored XSS can lead to credential theft and session hijacking.
- Other (5 CVEs): This residual category includes various other product fixes, none of which were flagged as urgent in this cycle.
These counts are derived from Microsoft’s Security Update Guide, which aggregates 622 unique CVEs. ZDI’s independent analysis closely aligns, reporting 621, and provides valuable per-family insights.
The Role of AI in Vulnerability Discovery and its Double-Edged Sword
The extraordinary volume of patches this month can be partly understood in the context of Microsoft’s recent disclosures regarding its advancements in vulnerability discovery. In a July 9 post on the Windows Experience blog, Microsoft informed customers to anticipate a "higher volume of security updates included in each security release" as artificial intelligence increasingly assists in uncovering more issues. This effort includes initiatives like MDASH (Multi-Model Agentic Scanning System), Microsoft’s AI-powered system, which independently identified 16 bugs in May’s Patch Tuesday alone. While Microsoft has not specified how many of July’s 622 CVEs originated from this AI pipeline, the implication is clear: AI is accelerating the pace of vulnerability detection.
However, this increased automation presents a double-edged sword. While it enables vendors to find and fix vulnerabilities faster, it also inadvertently shortens the window of opportunity for defenders. Once a patch is released, threat actors can "diff" the updated software against the previous build to quickly identify the specific code changes that address a vulnerability. This process allows them to reverse-engineer the flaw and develop a working exploit much faster than before, often leading to what is colloquially known as "Exploit Wednesday" – exploits appearing mere days after Patch Tuesday. This phenomenon effectively erodes the traditional "wait a week" cushion that many organizations previously relied upon for testing and deployment, demanding a significantly accelerated patching cadence.
Evolving Patching Strategies: Beyond CVSS Scores
The July 2026 Patch Tuesday serves as a definitive turning point for cybersecurity strategies. With a release comprising over 600 CVEs, many of which are rated "High" or "Critical" by traditional CVSS metrics, the simple act of sorting by severity becomes an impractical and ineffective triage method. When everything is "critical," nothing truly stands out.
This month’s two actively exploited zero-days vividly illustrate this point: neither is a headline-grabbing 9.8 RCE, yet both are mid-tier privilege escalation flaws that are already being actively leveraged by attackers. Security teams must fundamentally re-evaluate their prioritization frameworks. The paramount focus should now be on vulnerabilities that are demonstrably exploited in the wild. This requires diligent monitoring of sources such as CISA’s Known Exploited Vulnerabilities (KEV) catalog, the Exploit Prediction Scoring System (EPSS), and vendor-specific "exploited" flags. Relying solely on numerical severity scores, particularly for such a high-volume release, is no longer sufficient or safe.
In conclusion, the July 2026 Patch Tuesday is not merely a record-breaking update; it is a critical inflection point for enterprise security. It underscores the accelerating pace of vulnerability discovery, the persistent threat of actively exploited zero-days, and the urgent need for organizations to adopt more agile, intelligence-driven patching strategies. The message is clear: prioritize based on active exploitation, integrate advanced threat intelligence, and patch with unprecedented speed. The cybersecurity landscape is evolving rapidly, and the "number on the box" – the sheer volume of vulnerabilities – is only projected to increase.
