Microsoft just dropped 622 security fixes in a single update — the biggest Patch Tuesday in the company’s history. Two of those flaws are already being used by attackers.
Microsoft’s July 2026 Patch Tuesday landed with 622 CVEs — more than triple June’s count, and a new all-time record. Of those, 59 are rated Critical. Two zero-day vulnerabilities are confirmed as actively exploited in the wild.
What’s being targeted
The two zero-days hit SharePoint Server (CVE-2026-56164) and Active Directory Federation Services (CVE-2026-56155). The SharePoint flaw allows privilege escalation with low attack complexity — an attacker already inside your network can rapidly gain access to sensitive documents and data. The ADFS bug targets your identity infrastructure: the system that controls who logs into what across your environment.
A third SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) bypasses authentication entirely and is expected to see active exploitation soon.
Who’s affected
Any business running Microsoft 365, SharePoint, Windows Server, or Active Directory — which covers most Australian organisations. The 622 CVEs span Windows, Office, Azure, and multiple server products.
What to do now
Patch SharePoint and ADFS first — those are the ones attackers are already hitting. For cloud-hosted Microsoft 365 environments, confirm with your provider that July updates have been applied across all tenants.
Here’s what we’re seeing across our managed client base: patching volumes have roughly doubled year-on-year, and July’s dump sets a new high-water mark. If your team is spending more time patching than progressing projects, that’s a sign managed IT support should be handling the operational load.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
