Table of Contents
Microsoft’s Historic July 2026 Patch Tuesday: 622 Vulnerabilities and 2 Active Zero-Days Addressed

Microsoft’s July 2026 Patch Tuesday is officially the largest security update in the company’s history. This massive release addresses a staggering 622 vulnerabilities across the Windows ecosystem, Office, Azure, and SharePoint. Most importantly for IT and security teams, the update includes critical fixes for two zero-day vulnerabilities that were already being actively exploited in the wild before the patches were made available.
Why Are There So Many Vulnerabilities This Month?
The record-breaking volume of this update represents a significant shift in how vulnerabilities are found. Microsoft has attributed the steep increase in vulnerability disclosures to its use of a new artificial intelligence system known as MDASH (Multi-Model Agentic Scanning Harness). This AI-assisted vulnerability discovery tool has rapidly accelerated the identification of flaws across the Windows networking and authentication stack. Microsoft has indicated that organizations should expect these larger security update volumes to become the new normal as AI helps defenders identify more issues earlier in the lifecycle.
The Two Actively Exploited Zero-Days You Must Patch Immediately
While triaging over 600 vulnerabilities is a daunting task, security teams must prioritize the two actively exploited flaws that sit at the center of enterprise trust chains:
- CVE-2026-56164 (Microsoft SharePoint Server Elevation of Privilege): This critical flaw affects on-premises Microsoft Office SharePoint Server deployments. It allows an unauthorized attacker to elevate privileges over a network due to missing authentication for a critical function. Microsoft recommends enabling Antimalware Scan Interface (AMSI) integration as a mitigation step to scan for and detect malicious POST requests.
- CVE-2026-56155 (Active Directory Federation Services Elevation of Privilege): This vulnerability is caused by insufficient access control restrictions within AD FS. An authorized threat actor could exploit this flaw to elevate their privileges and gain administrator access on the vulnerable system.
Other Notable Critical Flaws in the Release
Beyond the zero-days, several other critical vulnerabilities demand urgent attention depending on your infrastructure:
- CVE-2026-57092 (Hyper-V VMSwitch): Carrying a near-perfect CVSS score of 9.9, this vulnerability in the Windows Virtual Machine Switch could allow a threat actor to break out of a virtual machine and escape to the host environment.
- CVE-2026-50661 (Windows BitLocker Bypass): This publicly disclosed security feature bypass allows an attacker to circumvent BitLocker encryption. While it requires physical access to the target device, it represents the fourth distinct BitLocker bypass technique disclosed in just five weeks.
- DHCP Server Remote Code Execution: The update addresses multiple critical buffer overflow vulnerabilities (such as CVE-2026-50518 and CVE-2026-56159, both scoring 9.8) that are exploitable simply by sending malicious DHCP packets.
Action Plan for IT Teams
The traditional approach of waiting a week before deploying patches is no longer safe for a release of this scale. Attackers can quickly compare the new builds against the old ones to identify the changed code and develop working exploits. Organizations should immediately prioritize patching internet-exposed SharePoint environments and AD FS servers to close the actively exploited zero-days, before working through the remaining critical vulnerabilities.
Aditya Raj
Aditya Raj is a technology writer and the founder of TechRadar360. He covers smartphones, laptops, GPUs, AI tools, and consumer tech, with a focus on hands-on reviews and honest comparisons. When he is not testing devices, he is tracking the latest industry launches and leaks.


