All incidents

Microsoft issues record Patch Tuesday update for July 2026 with 622 patches including two exploited zero-days

vulnerabilityclosedJul 14, 2026 — Jul 14, 2026
Microsoft patches record 622 vulnerabilities including two exploited zero‑days

MICROSOFT released its largest Patch Tuesday ever on 14 July 2026, addressing 622 unique CVEs that span Windows, Office, SharePoint and related services.

The update includes two zero day flaws that are already being exploited in the wild, pushing organisations to accelerate their patch cycles.

Administrators now face a deluge of fixes that demands both speed and careful prioritisation.

CVE‑2026-56155, rated CVSS 7.8, affects Active Directory Federation Services and allows an authenticated user with low privileges to raise their access level locally (CISA KEV entry).

CVE‑2026-56164, scored CVSS 5.3, is a missing authentication flaw in Microsoft SharePoint Server that lets an unauthenticated attacker elevate privileges over the network (CISA KEV entry).

Among the critical bugs, CVE‑2026-57092 carries a CVSS score of 9.9 and represents an elevation of privilege in the Windows VMSwitch component that could be chained with other flaws (Microsoft update guide).

The update also patches numerous critical issues in DHCP Server, Remote Desktop Protocol and various Office components, many of which carry CVSS scores above 9.0.

Both CVE‑2026-56155 and CVE‑2026-56164 have been added to CISA’s Known Exploited Vulnerabilities catalogue, confirming active attacks before patches were released.

The ADFS flaw requires a valid session but can be triggered with specially crafted requests, while the SharePoint bug can be exploited remotely without any authentication.

Although no specific threat actor has been named, the presence of these zero days in the KEV list indicates that opportunistic actors are already leveraging them.

The sheer volume of flaws, driven in part by AI assisted discovery tools, has raised the stakes for triage teams who must balance speed with accuracy.

Security analysts stress that focusing on exploitable bugs and critical assets yields better defence than attempting to patch every single CVE.

This month’s release highlights the importance of maintaining asset inventories and integrating threat intelligence into patch management workflows.

Organisations should first apply the patches for the two KEV listed vulnerabilities, then work through the remaining critical ratings in accordance with their internal risk matrices.

Maintaining an up to date inventory of SharePoint farms, ADFS servers and Windows hosts helps ensure that no system is missed during the rollout.

Where immediate patching is not possible, limiting network exposure to SharePoint and enforcing multi factor authentication on ADFS can reduce the attack surface.

Continuous monitoring of the CISA KEV list and subscribing to Microsoft’s security update guidance will help teams stay ahead of future mass patch events.

By coupling rapid deployment with contextual prioritisation, defenders can turn a record breaking patch day into a manageable routine.

Regular review of patch logs and verification of successful installation are essential to close any gaps that attackers might exploit.

Intelligence briefing updated Jul 14, 2026

CVE-2026-57092 9.9
Root sourcewww.zerodayinitiative.com
Timeline Coverage

Swipe to explore timeline