Microsoft’s July 14 Patch Tuesday was the largest security update in the company’s history: 628 CVEs fixed per the MSRC release notes, with around 60 rated critical. Most headlines cite at least 570 flaws, a narrower count that excludes some Edge and republished entries; either number roughly triples a typical month.
Three zero-days lead the batch, two already exploited in the wild: an Active Directory Federation Services privilege escalation and a SharePoint Server privilege escalation, plus a publicly disclosed BitLocker bypass. If you run on-premises SharePoint or AD FS, this is a patch-now release.
What to patch first
The actively exploited pair are CVE-2026-56155 (AD FS elevation of privilege) and CVE-2026-56164 (SharePoint elevation of privilege), and MSRC also flags a SharePoint remote code execution bug, CVE-2026-58644, with exploitation detected. CVE-2026-50661, the BitLocker security feature bypass, was public before the patch. Windows accounts for 416 of the fixes, with the remainder spread across Office, Edge, SharePoint, Azure and SQL Server. The pattern is familiar: identity infrastructure and collaboration servers, the systems that sit between attackers and everything else, keep absorbing the worst of it, just as BeyondTrust’s twin 9.2 authentication bypasses did in January.
Why the number keeps growing
Microsoft has acknowledged that AI-assisted vulnerability discovery is contributing to the volume, and the Zero Day Initiative called July the largest single-month release on record. Finding bugs is getting cheaper faster than fixing them is, on both sides of the fight. That asymmetry is one reason security remains the software budget nobody dares cut, and why exploitation now routinely begins before patches ship, as it did with Adobe’s 10.0-severity ColdFusion flaw.
The signal
A 628-CVE month is not a one-off, it is the new baseline forming. AI tooling is industrializing bug discovery, and vendors’ patch pipelines are becoming the bottleneck. For defenders the practical read is unchanged but more urgent: exposure windows are compressing, exploited-in-the-wild now ships in the release notes themselves, and patch latency, not zero-day exotica, is what actually gets organizations breached.
AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.
