• Sources: Tenable analysis, HN 48913190
  • Summary: Microsoft's July 2026 Patch Tuesday on 2026-07-14 addressed 569 CVEs, the largest monthly release in its history and well past the prior record of 198, with 56 rated critical, 510 important, and 3 moderate. Two flaws were exploited in the wild as zero-days before a fix shipped: CVE-2026-56155, a privilege-elevation flaw in Active Directory Federation Services, and CVE-2026-56164, a privilege-elevation flaw in SharePoint Server. Both were added to the CISA Known Exploited Vulnerabilities catalog the same day. A third flaw, CVE-2026-50661 in Windows BitLocker, was publicly disclosed before a patch but requires physical device access.
  • Why it matters: The two exploited zero-days hit identity and collaboration infrastructure that many organizations expose to the network, and the record CVE volume raises the patch-testing and deployment load for every Windows fleet this month.

send feedback on this story