IMAGE CREDITS: COREWIRE

Microsoft’s record July Patch Tuesday: 628 flaws, three zero-days, two exploited

Microsoft’s July 2026 Patch Tuesday fixed a record 628 CVEs including three zero-days, two exploited in the wild in AD FS and SharePoint. AI-assisted bug discovery is driving the volume.

Microsoft’s July 14 Patch Tuesday was the largest security update in the company’s history: 628 CVEs fixed per the MSRC release notes, with around 60 rated critical. Most headlines cite at least 570 flaws, a narrower count that excludes some Edge and republished entries; either number roughly triples a typical month.

Three zero-days lead the batch, two already exploited in the wild: an Active Directory Federation Services privilege escalation and a SharePoint Server privilege escalation, plus a publicly disclosed BitLocker bypass. If you run on-premises SharePoint or AD FS, this is a patch-now release.

What to patch first

The actively exploited pair are CVE-2026-56155 (AD FS elevation of privilege) and CVE-2026-56164 (SharePoint elevation of privilege), and MSRC also flags a SharePoint remote code execution bug, CVE-2026-58644, with exploitation detected. CVE-2026-50661, the BitLocker security feature bypass, was public before the patch. Windows accounts for 416 of the fixes, with the remainder spread across Office, Edge, SharePoint, Azure and SQL Server. The pattern is familiar: identity infrastructure and collaboration servers, the systems that sit between attackers and everything else, keep absorbing the worst of it, just as BeyondTrust’s twin 9.2 authentication bypasses did in January.

Why the number keeps growing

Microsoft has acknowledged that AI-assisted vulnerability discovery is contributing to the volume, and the Zero Day Initiative called July the largest single-month release on record. Finding bugs is getting cheaper faster than fixing them is, on both sides of the fight. That asymmetry is one reason security remains the software budget nobody dares cut, and why exploitation now routinely begins before patches ship, as it did with Adobe’s 10.0-severity ColdFusion flaw.

The signal

A 628-CVE month is not a one-off, it is the new baseline forming. AI tooling is industrializing bug discovery, and vendors’ patch pipelines are becoming the bottleneck. For defenders the practical read is unchanged but more urgent: exposure windows are compressing, exploited-in-the-wild now ships in the release notes themselves, and patch latency, not zero-day exotica, is what actually gets organizations breached.

Get the Signal

AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.

Dr. Joseph Joshua

Dr. Joseph Joshua is the founder and editor of Corewire. A medical doctor by training, he brings the evidence-first discipline of clinical medicine to technology journalism: claims get checked against primary sources before they get published. He has produced technology and B2B content for companies across…

View Bio

Keep Reading