Microsoft's July 2026 Patch Tuesday fixes a record 570 flaws: two are already under attack
Microsoft's July 2026 Patch Tuesday just dropped a record-breaking 570 security fixes, nearly triple a typical month, including two vulnerabilities already being exploited in the wild and one publicly disclosed.
The Three Zero-Days Worth Your Immediate Attention
CVE-2026-56155 ADFS elevation of privilege: actively exploited
This is an elevation of privilege bug in Active Directory Federation Services (ADFS) that lets an attacker escalate to admin. It was discovered by Microsoft's own incident response team while investigating real attacks, which tells you the kind of damage it enables. If you use ADFS for single sign-on, patch today, not next week.
CVE-2026-56164 On-premises SharePoint missing authentication: actively exploited
A missing-authentication flaw in on-premises SharePoint Server that lets an unauthenticated attacker gain elevated privileges remotely. If you still run on-prem SharePoint, enable AMSI on the server as an interim mitigation and apply the update immediately.
CVE-2026-50661 BitLocker bypass: publicly disclosed
This one could expose encrypted data to someone with physical access to the device. It hasn't been exploited in the wild yet, but the technique is now public. Prioritise this on laptops and portable devices, particularly for staff who travel.
Why 570 Fixes Is a Structural Shift, Not a One-Off
Microsoft has confirmed it's now using AI-powered vulnerability discovery across its Windows codebase, which is why the count jumped from around 200 per month to 570. This isn't a spike that will correct itself next month. It's a new baseline.
We're already seeing this in our own client base. The organisations that had automated patch pipelines in place before July sailed through this month. Those still doing manual approvals are scrambling.
What to Do Right Now
- Patch ADFS immediately if you use it for single sign-on. This one is under active attack and has a confirmed path to admin access.
- Enable AMSI on on-premises SharePoint as an interim step, then apply the update. Don't wait for a maintenance window on this one.
- Prioritise BitLocker-affected devices that leave the office, including laptops, field devices, and executive machines, even though this one hasn't been exploited yet.
- Triage the rest by severity and exposure. Work with your IT provider to identify which of the remaining fixes apply to your environment and sequence them accordingly.
Need a Hand Prioritising 570 Patches?
Our security team can help you triage this month's release against your environment and get the critical fixes in place without disrupting your business.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
