July 2026 Patch Tuesday: The Largest Release on Record, and It Wasn't Just Microsoft

Microsoft shipped the largest Patch Tuesday in the program's history on July 14, and the exact size depends on who's counting. BleepingComputer and Qualys put it at 570 CVEs. Zero Day Initiative, Rapid7, Cisco Talos, and CrowdStrike land at 622 once you fold in Extended Security Update variants and product entries that get counted differently. Either number is roughly three times June's ~200 and close to five times May's 137. Google separately fixed 468 Chromium flaws that flow into Edge, which nobody rolls into the Microsoft total.

The interesting part isn't the headline number. It's why the number exists. Microsoft has been open that a new AI-assisted discovery pipeline (internally a multi-model agentic scanning harness) is finding vulnerabilities in the Windows codebase faster than the old research cadence ever did, and it has told customers to expect fat releases like this one to become the norm. Adobe said the same thing this month and changed its release schedule because of it. That is the real story of July: discovery has moved to machine speed, and the second-Tuesday remediation model was built for human speed.

The three that can't wait

Two of this month's zero-days were already under active attack before a patch existed, and both sit next to identity infrastructure.

CVE-2026-56155 is an elevation-of-privilege flaw in Active Directory Federation Services, CVSS 7.8, now on CISA's KEV list. It stems from insufficiently granular access control: an attacker who already has a local foothold and low privileges can escalate to administrative control of the AD FS server. Microsoft's own incident-response team (DART) found it, which almost always means they found it inside someone's breach. AD FS issues the tokens that federate authentication for Microsoft 365, Azure, and on-prem apps, so a compromised AD FS box becomes a launchpad for the golden-SAML style pivoting we've watched play out before. Microsoft paired the fix with hardening on the ACL of the Distributed Key Manager container, so read the CVE guidance rather than assuming the cumulative update alone closes it.

CVE-2026-56164 hits on-prem SharePoint Server, and it's the one whose CVSS score will mislead you. Microsoft rates it 5.3, "moderate," yet it is being exploited in the wild right now. It's a missing-authentication flaw that lets an unauthenticated attacker elevate privileges over the network with no credentials and no user interaction. SharePoint EoP bugs have a long history of being chained with an RCE for full server takeover, and this month hands attackers the RCE to chain with: two critical deserialization bugs, CVE-2026-50522 and CVE-2026-58644, both CVSS 9.8. On top of that, Rapid7 disclosed CVE-2026-55040, a critical auth-bypass that is the first half of a two-bug unauthenticated-RCE chain. The second half is embargoed until Microsoft ships its patch in August. If you run SharePoint on-prem, that is three separate reasons to move this cycle, and the AMSI-plus-full-request-body-scan mitigation is a stopgap, not a substitute.

The third zero-day, CVE-2026-50661, is a BitLocker security-feature bypass that was publicly disclosed ahead of the fix but isn't confirmed as exploited. It needs physical access, after which an attacker can bypass device encryption on the system drive. Laptops, kiosks, and field hardware are the exposure. CrowdStrike notes it may be the patch for "GreatXML," one of the bypasses tied to the Nightmare-Eclipse persona we covered earlier this year. If you've been following that thread, it's a reminder that the persona's backlog keeps landing on Patch Tuesday.

Underneath the zero-days

Of the roughly 57 to 62 Critical entries (source-dependent again), 48 are remote code execution. A few worth pulling out of the pile:

  • CVE-2026-57092, a use-after-free in the Hyper-V Virtual Switch (VMSwitch), CVSS 9.9, that lets code inside a guest VM reach across the boundary and elevate on the host. Guest-to-host escape is the case nobody running multi-tenant virtualization wants to read about.
  • CVE-2026-50518, an unauthenticated, network-triggered heap overflow in the DHCP Server service, alongside three more critical DHCP Server RCEs and one in the DHCP client. Core infrastructure, no user interaction.
  • CVE-2026-58608, a Print Spooler RCE, because it wouldn't be Patch Tuesday without one.
  • SQL Server RCEs (CVE-2026-54118 and -54117), a Copilot command-injection RCE (CVE-2026-48561), a pair of Defender RCEs, and the usual heavy Office, Word, Excel, and PowerPoint document-RCE cluster.

It wasn't just Microsoft

What made this week unusual is how much landed everywhere else at the same time.

Adobe had two ColdFusion events inside a fortnight. In early July it pushed an out-of-band emergency fix for seven maximum-severity flaws in ColdFusion and Campaign Classic, six of them CVSS 10.0. One of those, CVE-2026-48282, a path-traversal RCE, was exploited within hours of public disclosure and went straight onto CISA KEV. Then on the 14th Adobe shipped its regular batch, a dozen advisories covering scores of critical bugs across ColdFusion, Commerce, and the media apps, and announced it is moving to twice-monthly security bulletins, explicitly because AI-accelerated discovery has compressed the gap between disclosure and exploitation from days to hours. When a vendor changes its release calendar mid-year, the reason is worth reading closely.

The same week brought SAP's four critical NetWeaver, Commerce Cloud, and AppRouter fixes; Fortinet advisories across FortiOS, FortiProxy, FortiPAM, FortiSASE, and FortiSandbox; Cisco updates spanning Identity Services Engine, Catalyst Center, and ClamAV, plus confirmation that a June ISE bug was being exploited; two critical authentication-bypass flaws in BeyondTrust Remote Support and Privileged Remote Access; seven flaws in VMware's Avi Load Balancer including an auth bypass; and a path-traversal zero-day in Progress ShareFile serious enough that Progress emergency-shut-down its Storage Zone Controllers over it. Add a maximum-severity command-injection bug in Ubiquiti UniFi OS, a Linux-kernel VM escape (dubbed "Januscape"), an auth bypass in the Gitea Docker image, and NVIDIA fixes for its Triton inference server and TensorRT-LLM. That last cluster is its own signal: the AI stack is now in the patch queue like everything else.

The cadence is the problem

None of these individual bugs is unprecedented. What's new is the rate. When Microsoft and Adobe both tell you in the same month that AI is generating more confirmed findings than their old schedules were built to carry, the monthly-batch mental model quietly stops working. A 570-to-622-CVE release is not something a team triages in an afternoon, and the exploited SharePoint and AD FS bugs did not wait for anyone's maintenance window.

The organizations that handle a month like this well aren't the ones with more people. They're the ones who can see exposure per CVE across the fleet in minutes instead of days, rank by real risk instead of raw CVSS (ask the SharePoint 5.3 how meaningful the score was), push validated changes through deployment rings without turning every second Tuesday into a fire drill, and prove afterward what actually got patched. The discovery side of this equation is only going to get faster. The remediation side is the part you still control.

See Patchblox in Action

Unlock the Full Potential of Microsoft Endpoint Management

Request a Demo