July Patch Tuesday: 570 Fixes and Two Zero-Days

Microsoft’s July 2026 security update, released on the second Tuesday of the month as part of the regular “Patch Tuesday” cycle, is the largest in the company’s history. More than 570 vulnerabilities have been addressed, including two that were already being exploited by attackers before the patch was released. If your business runs Windows or uses Microsoft 365 services, this update matters.

Patch Tuesday is the name given to Microsoft’s monthly security update release, which lands on the second Tuesday of every month. It is the main mechanism by which Microsoft distributes security fixes across Windows, Office, and its wider product range.

What happened

On 8 July 2026, Microsoft released security patches covering more than 570 individual vulnerabilities across Windows, Windows Server, Microsoft 365 services, Active Directory, SharePoint, and other products. The total is more than double the typical monthly volume and represents a record for a single Patch Tuesday release.

Microsoft has attributed part of the unusually high count to an AI-powered vulnerability-scanning system it recently deployed to proactively search its own Windows codebase for security weaknesses. Rather than waiting for external researchers or attackers to find flaws, Microsoft is now surfacing vulnerabilities internally and patching them in bulk. While the volume is striking, the intent is reassuring: better to find and fix quietly than to leave flaws undiscovered.

Of the 570-plus fixes, 57 are rated “critical”, Microsoft’s highest severity level. The majority of those critical entries are remote code execution vulnerabilities, meaning an attacker could potentially run malicious software on a targeted system without needing physical access.

The two actively exploited zero-days

A zero-day vulnerability is a security flaw that is being actively exploited by attackers before the vendor has released a fix. This month’s update includes two:

CVE-2026-56155: Active Directory Federation Services privilege escalation

Active Directory Federation Services (AD FS) is the component that handles single sign-on across many corporate Microsoft environments, allowing users to authenticate once and access multiple systems. CVE-2026-56155 allows an attacker who already has some level of access to a network to escalate their privileges to administrator level through AD FS.

Microsoft’s credit for discovering this flaw goes to its Detection and Response Team (DART), which is the internal team that responds to active cyber incidents at customer organisations. That attribution strongly suggests this vulnerability was found while investigating a real attack rather than in routine testing. It is a serious flaw in a system that many businesses rely on for secure access management.

CVE-2026-56164: SharePoint Server privilege escalation

This vulnerability in Microsoft SharePoint Server allows an unauthenticated attacker to escalate privileges over the network, potentially without any valid credentials. We have covered this flaw in a separate post given its severity and the active exploitation underway. If you have not read that update yet, it is worth doing so alongside this one.

The publicly known BitLocker bypass

A third zero-day was publicly disclosed before this month’s patch, though it has not yet been seen exploited in the wild. This flaw allows an attacker to bypass BitLocker, Microsoft’s full-disk encryption feature. BitLocker is widely used in business environments to protect data on laptops and PCs if they are lost or stolen. A bypass of this protection is worth taking seriously, even if active exploitation has not yet been observed.

Why the record volume matters to your business

A very large update can create a false sense of security: so many patches, surely someone is on top of it? The reality is that volume makes prioritisation harder, not easier. Most organisations cannot test and deploy 570 patches the same day they are released, so IT teams must identify the most critical fixes and get those deployed first.

For this month, the priorities are clear. The AD FS and SharePoint zero-days are being actively exploited now, meaning attackers are already using these vulnerabilities against real targets. Any Windows Server running AD FS or SharePoint that has not been patched this month is at elevated risk.

Beyond those immediate priorities, the critical-rated remote code execution vulnerabilities in Windows itself need to be addressed promptly across all workstations and servers. A delay of even a few weeks after a Patch Tuesday release is long enough for exploit code to circulate publicly.

What we have done for managed clients

For businesses on our managed IT services, patching is handled as part of our regular maintenance cycle. Our team reviews each month’s Patch Tuesday release, identifies priority fixes for our clients’ specific environments, and deploys patches in a controlled window that minimises disruption. For this month’s update, we have prioritised the two actively exploited zero-days alongside the critical Windows fixes.

We also monitor for any known issues with specific patches that can sometimes cause problems after deployment, and hold back any that have been flagged for instability while the situation is resolved.

What to do if you manage your own patching

If your business handles its own Windows updates, here are the steps to take now:

  1. Deploy the July 2026 cumulative updates across all Windows workstations and servers as soon as reasonably possible. These are available via Windows Update, Windows Server Update Services (WSUS), or Microsoft Endpoint Manager depending on how your environment is managed.
  2. Prioritise any servers running AD FS or SharePoint. These are the highest-risk systems given the active exploitation of the two zero-days.
  3. Check your BitLocker posture. If your business relies on BitLocker to protect laptops, verify that the bypass patch has been applied. The fix is included in the July cumulative update.
  4. Review whether Windows Update is actually running. In some managed environments, updates are deferred or paused for testing. Make sure this month’s updates are not stuck behind a policy that was forgotten.
  5. Consider your patch testing timeline. A record-volume update is a good moment to review how long your organisation waits before deploying patches. Waiting more than two weeks for critical and zero-day fixes is difficult to justify.

How System Force IT can help

Keeping up with monthly patching at this scale is one of the core reasons businesses choose to work with a managed IT provider. Our IT support and maintenance service takes the burden of patching off your internal team entirely, with structured monthly cycles, priority triage for critical updates, and reporting so you can see exactly what has been applied and when.

If you have concerns about your current patch status or want to understand whether your environment is exposed to this month’s vulnerabilities, our IT security team can run a rapid assessment. Get in touch</strong< and we will take a look.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name