IMAGE CREDITS: COREWIRE

Microsoft’s record July Patch Tuesday: 628 flaws, three zero-days, two exploited

Microsoft’s July 2026 Patch Tuesday fixed a record 628 CVEs including three zero-days, two exploited in the wild in AD FS and SharePoint. AI-assisted bug discovery is driving the volume.

Microsoft’s July 14 Patch Tuesday was the largest security update in the company’s history: 628 CVEs fixed per the MSRC release notes, with around 60 rated critical. Most headlines cite at least 570 flaws, a narrower count that excludes some Edge and republished entries; either number roughly triples a typical month.

Three zero-days lead the batch, two already exploited in the wild: an Active Directory Federation Services privilege escalation and a SharePoint Server privilege escalation, plus a publicly disclosed BitLocker bypass. If you run on-premises SharePoint or AD FS, this is a patch-now release.

What to patch first

The actively exploited pair are CVE-2026-56155 (AD FS elevation of privilege) and CVE-2026-56164 (SharePoint elevation of privilege), and MSRC also flags a SharePoint remote code execution bug, CVE-2026-58644, with exploitation detected. CVE-2026-50661, the BitLocker security feature bypass, was public before the patch. Windows accounts for 416 of the fixes, with the remainder spread across Office, Edge, SharePoint, Azure and SQL Server. The pattern is familiar: identity infrastructure and collaboration servers, the systems that sit between attackers and everything else, keep absorbing the worst of it, just as BeyondTrust’s twin 9.2 authentication bypasses did in January.

Why the number keeps growing

Microsoft has acknowledged that AI-assisted vulnerability discovery is contributing to the volume, and the Zero Day Initiative called July the largest single-month release on record. Finding bugs is getting cheaper faster than fixing them is, on both sides of the fight. That asymmetry is one reason security remains the software budget nobody dares cut, and why exploitation now routinely begins before patches ship, as it did with Adobe’s 10.0-severity ColdFusion flaw.

The operational read for defenders

A month this size breaks patch pipelines that were built for a hundred CVEs. The triage logic still holds, it just matters more. The exploited pair, the AD FS and SharePoint elevation-of-privilege flaws, go first, along with the SharePoint remote code execution bug flagged as exploited: in-the-wild status means scanning and exploitation are already underway, so every day of delay is exposure to an active campaign rather than a theoretical one. The BitLocker bypass matters most for laptop fleets and any environment where physical access is part of the threat model.

Elevation-of-privilege bugs rarely operate alone. They get chained: a phishing foothold or a compromised low-privilege account becomes domain-level access. AD FS is a particularly ugly place for that chain to land, because it sits at the front door of identity. A compromised federation service can mint tokens that look legitimate to everything downstream. That is why identity infrastructure keeps appearing at the top of these bulletins, and why the fix cannot wait for a monthly maintenance window.

With 416 of the fixes landing in Windows itself, full deployment means reboot cycles across entire fleets. The practical pattern is ring-based: a pilot ring inside 24 hours for the exploited trio, broad deployment inside the week, and the long tail of moderate-severity fixes on the normal cadence. Speed on three CVEs matters more than completeness on 628.

The signal

A 628-CVE month is not a one-off, it is the new baseline forming. AI tooling is industrializing bug discovery, and vendors’ patch pipelines are becoming the bottleneck. For defenders the practical read is unchanged but more urgent: exposure windows are compressing, exploited-in-the-wild now ships in the release notes themselves, and patch latency, not zero-day exotica, is what actually gets organizations breached.

Get the Signal

AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.

Dr. Joseph Joshua

Dr. Joseph Joshua is the founder and editor of Corewire. A medical doctor by training, he brings the evidence-first discipline of clinical medicine to technology journalism: claims get checked against primary sources before they get published. He has produced technology and B2B content for companies across…

View Bio

Keep Reading