Microsoft Patches Record 570 CVEs, 2 Zero-Days [2026]

Microsoft shipped the largest Patch Tuesday of 2026 on July 14, addressing 570 vulnerabilities across Windows, Office, SharePoint Server, Exchange, SQL Server, and more than a dozen other products. Two of those flaws were already being used in real attacks before the fixes shipped. A third had been sitting in public view.

The two actively exploited zero-days, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server, both landed on the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog on July 14. Federal civilian agencies had until July 28, 2026 to patch or take affected systems offline, a deadline that has now passed. Enterprise security teams that skipped July’s update cycle are already behind.

Google · Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

What Happened: Microsoft’s Record July 2026 Patch Tuesday

Patch Tuesday lands on the second Tuesday of every month, and July 14 delivered Microsoft’s biggest batch of the year. Independent trackers converge on roughly 570 to 622 Microsoft-authored CVEs, though the exact number depends on who’s counting and what they include. Tenable Research put the figure at 569, while BleepingComputer and gHacks both counted 570. Security Affairs and the Zero Day Initiative each logged 621, with Security Affairs calling it the largest single-month release in Microsoft’s history and ZDI noting that 2026’s year-to-date CVE volume already exceeds prior full-year totals. Rapid7 and CrowdStrike reported a broader total of 622, a figure that folds in 468 Chromium-based Microsoft Edge fixes that actually ship on Google’s own release schedule, with Rapid7 flagging a record 416 Windows-specific vulnerabilities inside that count.

Strip out the browser component and the core Windows, Office, and server-side release still dwarfs recent months. CrowdStrike’s Counter Adversary Operations team pegged July’s volume at 622 vulnerabilities in its own analysis, roughly triple June’s total and close to five times May’s, with 62 rated Critical, up from June’s count. CrowdStrike’s breakdown matched the pattern seen elsewhere: two zero-days already under active exploitation and a third that had only been publicly disclosed, meaning Microsoft learned about all three only after they were already circulating or being exploited, rather than through routine internal testing.

Inside the Numbers: 570 CVEs, Three Zero-Days

Two of the three zero-days were being actively exploited when Microsoft patched them. The third had been publicly disclosed but showed no confirmed exploitation. Here’s how the headline vulnerabilities break down by product, severity, and real-world risk.

CVE IDProductCVSS ScoreVulnerability TypeExploited in the WildCISA KEV Status
CVE-2026-56155Active Directory Federation Services7.8 (Important)Elevation of PrivilegeYes, confirmedAdded July 14, deadline July 28
CVE-2026-56164SharePoint Server5.3 (Moderate)Elevation of PrivilegeYes, confirmedAdded July 14, deadline July 28
CVE-2026-50661Windows BitLockerNot publishedSecurity Feature BypassPublicly disclosed, not exploitedNot listed
CVE-2026-50518Windows DHCP Server9.8 (Critical)Remote Code ExecutionNo evidence foundNot listed
CVE-2026-56159Windows DHCP Server9.8 (Critical)Remote Code ExecutionNo evidence foundNot listed

Notice what’s missing from the exploited column: the two 9.8-rated Critical bugs. Attackers went after a 7.8 and a 5.3 instead. That gap between severity score and real-world targeting is the most important story buried inside this release, and it’s worth its own section below.

CVE-2026-56155: The Active Directory Flaw Already Under Attack

Microsoft’s own advisory describes CVE-2026-56155 in blunt terms: insufficient granularity of access control in Active Directory Federation Services lets an authorized attacker elevate privileges locally. In practice, that means someone who already has a foothold, a compromised low-privilege account, a phished credential, can use this flaw to climb to administrator rights inside an organization’s identity infrastructure.

AD FS sits at the center of single sign-on for thousands of enterprises, brokering authentication between on-premises Active Directory and cloud services. A privilege-escalation bug there is not a side issue. It’s a skeleton key. Microsoft credits its own Detection and Response Team, Jeremy Kingston and Scott Clark, with the discovery, which tells you something on its own: DART is an incident-response unit. Its researchers typically find vulnerabilities while responding to active breaches, not while hunting for bugs in a lab. That strongly suggests real customers were already compromised before Microsoft understood what hit them.

CVE-2026-56164: SharePoint’s Second Zero-Day in Six Weeks

SharePoint Server had a rough July before this patch even landed. Just weeks earlier, tech-insider.org covered CVE-2026-45659, a CVSS 8.8 remote code execution flaw that forced an emergency out-of-band patch with a July 4 deadline. CVE-2026-56164 is a separate vulnerability, but the pattern is hard to ignore: on-premises SharePoint has now had two zero-days exploited in the wild inside a single month.

This one is a missing-authentication flaw (tracked under CWE-306) that lets an unauthenticated remote attacker escalate privileges over the network with no user interaction required. It hits SharePoint Server 2019, SharePoint Server Subscription Edition, SharePoint Server 2016, and SharePoint Enterprise Server 2016. The CVSS score, 5.3, sounds almost mild next to the DHCP bugs above. It isn’t. Discovery credit goes to Jayson Frost of Mandiant Incident Response and Genwei Jiang of Google Cloud’s FLARE OTF team, alongside an anonymous researcher, meaning two of the industry’s top incident-response shops found this while cleaning up after real intrusions.

Organizations running SharePoint on-premises rather than SharePoint Online carry the exposure here. Microsoft has spent years pushing customers toward the cloud version, and repeat incidents like this one make that migration pitch easier to justify.

The Quiet Threats: Bugs Below the Zero-Day Headlines

Not every notable flaw in this release made the zero-day list. Two categories of bugs deserve attention precisely because they haven’t been exploited yet.

CVE-2026-50661: A BitLocker Bypass Sitting in Public View

CVE-2026-50661 is a security feature bypass in Windows BitLocker, publicly disclosed by an anonymous researcher but, as of this writing, not confirmed as exploited. Public disclosure without a patch in hand is its own kind of risk: the technical details are out there for anyone to weaponize. Microsoft’s guidance for affected users is straightforward. Install the update, and make sure BitLocker recovery keys are backed up in a Microsoft account or Active Directory rather than stored only on the device itself.

CVE-2026-50518 and CVE-2026-56159: Critical DHCP Server RCEs

These two carry the highest severity scores in the entire release, CVSS 9.8 apiece, and both are heap-based buffer overflow bugs (CWE-122) in Windows DHCP Server. CVE-2026-50518 triggers through malicious domain name data, while CVE-2026-56159 exploits specially crafted packets targeting DHCP’s Option 43 vendor-specific configuration fields. CrowdStrike’s Counter Adversary Operations Advanced Research Team is credited with discovering part of this batch. Neither bug shows evidence of active exploitation yet, but a 9.8 remote code execution flaw in infrastructure most networks run by default is exactly the kind of vulnerability that turns into a mass-exploitation event once proof-of-concept code circulates.

Why Vulnerability Counts Vary by Tracker

Ask six security vendors how many CVEs Microsoft patched in July and you’ll get several different numbers. That’s not sloppiness, it’s methodology. Some trackers count only Microsoft-authored advisories: BleepingComputer landed on 570, including the same two exploited zero-days and one publicly disclosed flaw that every other outlet flagged, while Security Affairs and the Zero Day Initiative each counted 621. Others fold in Chromium-based Edge fixes that ship separately through Google, which is how Rapid7 and CrowdStrike arrive at 622. Some finalize their count the morning of Patch Tuesday, while others keep updating as Microsoft revises advisories in the following days.

TrackerTotal CVEs ReportedCritical-RatedScope
Tenable Research56956Core Microsoft-authored CVEs only
BleepingComputer57059Excludes Edge/Chromium and earlier out-of-band fixes
gHacks / SecurityOnline57057Matches BleepingComputer’s core count
Rapid7 / CrowdStrike62262Includes 468 Edge/Chromium CVEs

The practical takeaway for IT teams: don’t fixate on the headline number from any single source. Pull the full list directly from Microsoft’s Security Update Guide and filter by the products actually running in your environment. The 468-CVE swing between the narrow and broad counts is almost entirely Edge, which most enterprises patch through a separate browser update channel anyway. What’s harder to wave off is the composition of the core release: BleepingComputer counted 48 remote-code-execution bugs among its 59 Critical-rated flaws, and Rapid7 flagged a record 416 Windows-specific vulnerabilities, meaning the Windows and server teams carry most of this month’s real triage load even after Edge is set aside.

CISA’s Known Exploited Vulnerabilities Deadline Hit July 28

CISA added both CVE-2026-56155 and CVE-2026-56164 to its Known Exploited Vulnerabilities catalog on July 14, the same day Microsoft published the fixes. Under Binding Operational Directive 22-01, federal civilian executive branch agencies had to remediate KEV-listed flaws within 14 days by default, which put the deadline at July 28, 2026, a date that has already passed as this article gets its August 2026 update. The NVD entries for CVE-2026-56155 and CVE-2026-56164 both reflect the KEV listing and the same due date.

The KEV catalog is a federal mandate on paper, but it functions as an industry clock in practice. Cyber insurers increasingly reference KEV status when underwriting policies. Compliance frameworks used well outside government, including several state-level regulations, point to the KEV list as a baseline for “known, exploited, and therefore no longer excusable to leave unpatched.” Missing a KEV deadline doesn’t carry a fine for a private company. It does show up in audits, incident post-mortems, and increasingly, breach-disclosure lawsuits that ask why a publicly known, actively exploited flaw sat unpatched for weeks.

How July 2026 Stacks Up Against This Year’s Other Major Disclosures

2026 has not been a quiet year for enterprise software vulnerabilities. July’s Patch Tuesday joins a list that already includes record-setting disclosures from Cisco, Joomla, and Adobe.

IncidentTimingPeak SeverityScale
Microsoft July 2026 Patch TuesdayJuly 14, 2026CVSS 9.8 (unexploited); 7.8 (exploited)570 CVEs, 2 exploited zero-days
SharePoint CVE-2026-45659Early July 2026CVSS 8.8Single emergency out-of-band patch
Windows Netlogon flawJuly 2026CVSS 9.8Single critical elevation-of-privilege bug
Cisco SD-WANJuly 2026CVSS 10.0 (two flaws)7 zero-days disclosed together
Joomla JCEJuly 2026CVSS 10.02.5 million sites at risk
Adobe ColdFusionJuly 2026Zero-day, exploited within 2 hours of disclosureActive exploitation campaign

What stands out is not any single vendor’s failure. It’s the clustering. Six major disclosures across identity infrastructure, collaboration platforms, networking gear, CMS plugins, and application servers, all inside one month. Security teams patching Microsoft’s stack this week are, in many cases, the same teams that scrambled for Cisco SD-WAN and Joomla JCE two weeks earlier.

Historical Context: Patch Tuesday’s Growing Scale

Microsoft has released security updates on the second Tuesday of the month since October 2003, a cadence built to give IT departments a predictable window to test and deploy patches instead of reacting to a constant drip of individual fixes. In the program’s early years, a typical release patched a dozen to two dozen vulnerabilities. That number crept upward through the 2010s as Microsoft’s product surface expanded into cloud services, and it has accelerated sharply since 2024 as the company folded more of its portfolio, from Azure components to Power BI to Defender, into the same monthly cycle.

July 2026’s release is the largest since Microsoft began the modern Patch Tuesday format, according to the vendor trackers covering it, with Security Affairs going further and calling it the largest single-month release in Microsoft’s history outright. CrowdStrike’s comparison to May and June puts the trend in concrete terms: roughly a five-fold jump in patched vulnerabilities over two months. The Zero Day Initiative’s own tally adds a longer-lens data point: at 621 CVEs, its July count pushed 2026’s year-to-date CVE volume above Microsoft’s totals for some entire prior years. That growth curve was hard to explain from the outside — until now. In an August 2026 report, TechCrunch said Microsoft attributed the surge to AI-assisted vulnerability discovery, meaning the company’s own AI tooling is now surfacing flaws faster than traditional testing did. A larger researcher base and Microsoft’s expanding product line probably still play a role, but the company’s own explanation puts automation at the center of the story. What’s not ambiguous is the operational effect: IT teams now treat Patch Tuesday less like a monthly chore and more like a recurring fire drill.

Market Impact: Patch Fatigue and the Vulnerability Management Business

A 570-CVE release is a logistics problem before it’s a security problem. Large enterprises typically run staged deployment: patches hit test rings first, then broader device fleets, over a window of days to weeks. A release this size stretches that process thin, forcing security teams to triage which of hundreds of fixes matter most for their specific environment instead of deploying everything uniformly.

That triage burden is exactly what’s fueling demand for vulnerability management platforms. Tenable, Rapid7, Qualys, and CrowdStrike all published same-day breakdowns of this release, a pattern that has become standard competitive practice among vulnerability management vendors racing to be the fastest, most authoritative source security teams check first each month. For those vendors, a record-setting Patch Tuesday is a marketing moment as much as a research one.

There’s a second-order effect worth watching too. Cyber insurance underwriters increasingly ask policyholders how quickly they remediate KEV-listed flaws, and a growing pile of monthly zero-days makes that a harder bar to clear consistently. Expect renewal conversations this year to lean more heavily on patch cadence metrics than they did in 2025.

Expert Perspectives on the July 2026 Release

Coverage of the release converged quickly on the same headline figures, even as the exact CVE count varied by source. gHacks Tech News reported: “Microsoft has released the July 2026 Patch Tuesday security updates, addressing a record 570 vulnerabilities.” The same report broke down the zero-day count precisely: “This includes two zero-day exploits used in attacks and one zero-day vulnerability that has been publicly disclosed.”

Tenable Research’s write-up offered the most granular severity breakdown available: “Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate.” The near-identical totals from independent trackers, despite different methodologies, is itself a useful signal. When Tenable, BleepingComputer, and gHacks land within one CVE of each other on the core count, the number is solid even if the exact figure varies by a rounding margin.

What IT and Security Teams Should Do This Week

The two exploited zero-days should jump the queue ahead of everything else in this release, including the higher-scoring DHCP bugs, because active exploitation beats CVSS score every time when it comes to prioritization.

For Active Directory and Windows Administrators

Install the July cumulative updates immediately on domain controllers and any server running AD FS. Review administrative access logs for unusual privilege escalation events predating the patch, and verify AD FS federation trust configurations haven’t been altered. Administrators can confirm an update installed with a standard PowerShell check:

Get-HotFix -Id KB5101650
Get-HotFix -Id KB5099414

Windows 10 systems on Extended Security Updates receive the equivalent fix through KB5099539.

For SharePoint Server Administrators

Patch on-premises SharePoint Server immediately given confirmed active exploitation of CVE-2026-56164. Enable the Antimalware Scan Interface on SharePoint servers if it isn’t already active, set Request Body Scan mode to Full, and audit SharePoint access logs for signs of exploitation predating today’s patch. Organizations still running SharePoint Server 2016, which is well past mainstream support, should treat this as a prompt to accelerate migration planning rather than a one-time fix.

5 Predictions for the Rest of 2026

  • Patch Tuesday volumes stay elevated. With July running roughly five times May’s count, a return to sub-100 CVE months looks unlikely through the rest of the year.
  • SharePoint on-premises faces continued scrutiny. Two exploited zero-days in six weeks makes it a more likely target for follow-on research and copycat attacks, and a more likely candidate for Microsoft to push harder toward cloud migration.
  • KEV additions keep arriving same-day. CISA has moved toward listing exploited Microsoft flaws on the same day as the patch, a pattern likely to hold given how both July zero-days were caught through incident response rather than pre-release testing.
  • Vulnerability management vendors compete harder on speed. Expect same-day analysis from Tenable, Rapid7, Qualys, and CrowdStrike to become table stakes rather than a differentiator, pushing vendors toward faster automated triage tools as the real competitive edge.
  • Cyber insurance underwriting leans more on patch-cadence data. As KEV deadlines compress and disclosure volume rises, insurers are likely to request evidence of patch timelines, not just patch policies, during renewals.

Frequently Asked Questions

What is Microsoft Patch Tuesday?

Patch Tuesday is Microsoft’s monthly security update release, published on the second Tuesday of every month since October 2003. It bundles fixes for Windows, Office, and other Microsoft products into a predictable release window instead of shipping individual patches as they’re discovered.

How many vulnerabilities did Microsoft patch in July 2026?

Independent trackers reported 569 to 570 core Microsoft-authored CVEs. A broader count of 622, cited by Rapid7 and CrowdStrike, includes 468 Chromium-based Microsoft Edge fixes that ship on a separate schedule through Google.

What are the two actively exploited zero-days in July 2026’s Patch Tuesday?

CVE-2026-56155, an elevation-of-privilege flaw in Active Directory Federation Services (CVSS 7.8), and CVE-2026-56164, an elevation-of-privilege flaw in SharePoint Server (CVSS 5.3). Both were confirmed as exploited before Microsoft released patches.

Is CVE-2026-56155 in the CISA KEV catalog?

Yes. CISA added CVE-2026-56155 and CVE-2026-56164 to the Known Exploited Vulnerabilities catalog on July 14, 2026, the same day Microsoft published fixes.

What is the deadline to patch CVE-2026-56155 and CVE-2026-56164?

Federal civilian agencies had to remediate both flaws by July 28, 2026 (14 days after the July 14 KEV listing) under CISA’s Binding Operational Directive 22-01, and that deadline has now passed. Private organizations face no legal deadline, but security teams generally treat KEV entries as a benchmark for urgent patching regardless of sector.

Which Microsoft products are affected by the July 2026 updates?

The release spans Windows 10 and 11, Windows Server, Microsoft Office and Word, SharePoint Server, Exchange Server, SQL Server, Power BI Report Server, .NET, ASP.NET Core, Microsoft Defender, Windows Admin Center, and Visual Studio Code, among other products.

What should I do if I run SharePoint Server on-premises?

Patch immediately, enable the Antimalware Scan Interface, set Request Body Scan mode to Full, and review access logs for signs of prior exploitation. Given this is the second exploited SharePoint zero-day in six weeks, treat on-premises SharePoint as a high-priority asset for the rest of 2026.

Related Coverage

Sofia Lindström

Sofia Lindström

Editor-in-Chief

Sofia Lindström is the Editor-in-Chief at Tech Insider, where she leads editorial strategy and oversees coverage across AI, cybersecurity, and enterprise technology. With over a decade in Swedish tech journalism, she previously served as technology editor at Dagens Industri and covered the Nordic startup ecosystem for Breakit. Sofia holds an MSc in Media Technology from KTH Royal Institute of Technology and is a frequent speaker at Web Summit and Slush. She is passionate about making complex technology accessible to business leaders.

View all articles