// 2 CRITICAL · 8 ZERO-DAY · 6 CVE · 8 EXPLOIT · 1 ADVISORY IN THE LAST 24H
Microsoft's July 2026 Patch Tuesday sets an all-time high with 622 CVEs patched, including two actively exploited zero-days in SharePoint and AD FS. The release underscores why CVSS scores alone can no longer drive patching priorities.

Microsoft released its largest Patch Tuesday ever on July 14, 2026, addressing 622 vulnerabilities\u2014more than triple the previous record of roughly 200 CVEs set in June 2026. Two zero-days are already under active exploitation in the wild, both carrying only Moderate or Important CVSS base scores, proving that base severity ratings are no longer sufficient for prioritizing patches.

Key Takeaways
  • 622 total CVEs in the July 2026 Patch Tuesday: an all-time record, per the Microsoft Security Update Guide cited by Red Hot Cyber and confirmed by The Hacker News and DigitalWorld Italia
  • Two actively exploited zero-days: CVE-2026-56164 in SharePoint Server (missing authentication, network-accessible) and CVE-2026-56155 in AD FS (insufficient granularity of access control, local access required)
  • Both zero-days carry Moderate/Important base CVSS scores (5.3 and 7.8) despite confirmed in-the-wild exploitation; official MSRC release notes mark "Exploitation Detected" for both
  • SharePoint Server 2016 and 2019 reach extended support end on July 14, 2026, with no ESU program available

The Two Zero-Days That Defy CVSS Scores

CVE-2026-56164 affects Microsoft Office SharePoint and is rated Moderate with a base score of 5.3 per official MSRC data. The attack vector is remote, requires no authentication or user interaction: "Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network," reads the vendor's official page. The "Exploitation Detected" flag confirms active exploitation. The vulnerability was reported by Mandiant and the Google FLARE team.

CVE-2026-56155 targets Active Directory Federation Services and is rated High with a base score of 7.8. Here the attacker must already have local access and limited privileges, but the impact is total: "An attacker who successfully exploited this vulnerability could gain administrator privileges," according to MSRC. The "Exploitation Detected" flag is also active. Microsoft's DART team discovered this flaw.

"Sort by what is being exploited, using KEV, EPSS, and Microsoft's exploited flag, not by score, and patch faster than you used to. The number on the box is only going up." \u2014 The Hacker News

Record Volume Overwhelms Security Teams

The previous month, June 2026, had already set a record with approximately 200 CVEs. July 2026 more than triples that count. According to source tallies, Windows alone accounts for 416 vulnerabilities with 95 RCEs, while Office adds 82. Edge contributes 46 CVEs. DigitalWorld Italia reports 58 critical vulnerabilities, a figure not independently verified against official Microsoft release notes.

The highest score in the release, CVSS 9.9, belongs to CVE-2026-57092 in VMSwitch\u2014another RCE, but with no confirmed active exploit. This is precisely the paradox that makes traditional triage obsolete: a Critical vulnerability without in-the-wild exploitation risks drawing more attention than a Moderate one already being weaponized.

BitLocker, Kerberos, and the End of Legacy SharePoint Support

A third zero-day, CVE-2026-50661 with a base score of 6.1, involves a BitLocker bypass requiring physical device access. Per Red Hot Cyber and The Hacker News, this vulnerability has been publicly disclosed but is not actively exploited at the time of publication.

The July 2026 patch permanently removes RC4 compatibility in Kerberos. Microsoft had signaled on July 9 an increase in patch volume linked to AI via the MDASH system, without specifying the exact split between CVEs generated by automated scanning and those from traditional methods.

On the same day as the patch release, SharePoint Server 2016 and 2019 reach extended support end with no ESU program available. Legacy installations are left without a safety net.

The Rapid7 Chain Not Fully Closed

The Hacker News flags an additional vulnerability, CVE-2026-55040 in SharePoint, a JWT authentication bypass discovered by Rapid7. The full fix for the associated RCE component is slated for August, per the same source, but Microsoft has not confirmed a specific date in available materials.

What to Do Now

  • Immediately apply patches for SharePoint Server and AD FS, the two surfaces with confirmed active exploits
  • Scan your environment for CVE-2026-56164 and CVE-2026-56155, prioritizing the "Exploitation Detected" flag over base CVSS scores
  • \li>Plan migration from SharePoint Server 2016/2019 given the end of extended support with no ESU program
  • Audit Kerberos RC4 dependencies before the permanent removal breaks authentication

FAQ

Why is a Moderate vulnerability with active exploitation more dangerous than an unexploited Critical?

Because CVSS base scores measure technical severity without accounting for exploitation status. CVE-2026-56164 scores 5.3 but is already exploited in the wild against enterprise-critical SharePoint systems, while an unexploited Critical 9.9 represents a potential, not immediate, threat.

Are the two zero-days in the CISA KEV catalog?

No. According to Red Hot Cyber and The Hacker News, neither CVE-2026-56164 nor CVE-2026-56155 appears in the CISA KEV catalog at the time of publication, despite Microsoft's "Exploitation Detected" flag.

How many of the 622 CVEs originate from AI-driven MDASH scanning?

The dossier does not specify the exact breakdown. Microsoft indicated on July 9 that the MDASH system would increase patch volume, but did not quantify how many CVEs in the July 2026 release stem from this source.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. redhotcyber.com
  2. thehackernews.com
  3. digitalworlditalia.it
  4. tomshw.it
  5. nvd.nist.gov
  6. msrc.microsoft.com
  7. cisa.gov