Patch Tuesday July 2026: Microsoft Patches a Historic Record of 570 Vulnerabilities — AI Discovered 500 Flaws Undetected for Years, With Two Actively Exploited SharePoint and AD FS Zero-Days
Eric Serrano Bustos
On 15 July 2026, Microsoft published its monthly security update (Patch Tuesday) with a figure unprecedented in the company’s history: 570 vulnerabilities fixed in a single month, compared to 206 the previous month (itself already a record) and far above the usual pace of 60–120 CVEs per month over recent years. The cause is not that Windows has suddenly become five times less secure than in June: it is that Microsoft has deployed AI-powered code analysis tools (the MDASH system) that are discovering at industrial speed vulnerabilities that had gone undetected for years. Microsoft Executive Vice President Pavan Davuluri confirmed that users “will notice a higher volume of security updates in each monthly release” as a direct consequence of AI accelerating vulnerability discovery. Among the 570 fixes are three zero-days, two of them under confirmed active exploitation: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server. Both appear in CISA’s Known Exploited Vulnerabilities (KEV) catalog. The CISA deadline for SharePoint expires today, 17 July 2026.
What do we know about the record-breaking July 2026 Patch Tuesday?
Facts documented by Qualys ThreatPROTECT, Krebs on Security, BleepingComputer, Tenable, CyberSecurityNews and Decryption Digest:
570 vulnerabilities in a single month: the largest volume in Microsoft history, driven by AI code analysis tools that found a massive backlog of previously undetected vulnerabilities. 59 are critical severity, including 48 remote code execution (RCE) flaws.
Three zero-days: two actively exploited (CVE-2026-56155 and CVE-2026-56164), one publicly disclosed without confirmed exploitation (CVE-2026-50661, BitLocker bypass requiring physical access).
CVE-2026-56155 (CVSS 7.8) — Elevation of Privilege in AD FS: allows a low-privilege local user to escalate to administrator on Windows Server. Active exploitation confirmed before the patch. CISA KEV.
CVE-2026-56164 (CVSS 5.3) — Elevation of Privilege in SharePoint Server: allows an unauthenticated attacker to elevate privileges over the network. Actively exploited before the patch. CISA KEV deadline today, 17 July 2026. Important: Microsoft’s exploitability rating was initially “less likely”, but CISA added it to KEV on 1 July confirming real exploitation. Microsoft’s internal labelling underestimated this risk.
CVE-2026-55944 (CVSS 9.8) — Unauthenticated RCE in Microsoft Dynamics NAV and 365 Business Central: allows a remote unauthenticated attacker to execute arbitrary code on on-premise installations. Requires neither credentials nor user interaction. Highest CVSS of the July cycle.
CVE-2026-58644 (Critical) — SharePoint Server RCE: second critical SharePoint flaw in the same Patch Tuesday. Organisations with on-premise SharePoint have two urgent CVEs to address this cycle.
CVE-2026-58608 (Critical) — Windows Print Spooler RCE: historically one of the preferred attack vectors for ransomware operators and APT groups for lateral movement in Windows networks.
AI as the origin of the record: Microsoft is using its MDASH system to scan its codebase at industrial scale, discovering a massive backlog of long-undetected vulnerabilities. The trend will continue: future Patch Tuesdays will remain high-volume while AI keeps uncovering the historical backlog.
Why this Patch Tuesday is different: AI as the origin of the record
The monthly patch cycle model is under pressure. With 570 patches in July, teams running monthly maintenance windows can no longer keep pace with the same processes. Patch prioritisation cycles must adapt to an environment where volume can multiply fivefold.
Vendor exploitability labelling is no longer sufficient guidance. CVE-2026-56164 was rated “less likely” by Microsoft’s own system, then confirmed in KEV with real exploitation. The correct approach is vendor rating plus KEV status, not just one of the two.
The AI that discovers vulnerabilities also generates them. July’s Patch Tuesday is the institutional counterpart of what the NCSC warned on 23 June: AI models are accelerating vulnerability discovery in existing software. What Microsoft does with MDASH defensively, threat actors do with their own models offensively. The net result is an acceleration of the attack-defence cycle for everyone.
The two actively exploited zero-days: what makes SharePoint and AD FS priority targets
SharePoint Server is the collaboration and intranet platform of reference in Spanish corporates and public administrations. An unauthenticated privilege escalation flaw (CVE-2026-56164) gives an attacker with network access the ability to move laterally with elevated privileges across the SharePoint environment and potentially into Active Directory.
AD FS is the federated identity and SSO layer for most organisations running Microsoft 365 in hybrid mode. Compromising AD FS via CVE-2026-56155 can give an attacker unauthorised SSO capabilities over federated applications: email, Teams, SharePoint Online and integrated SaaS apps.
The combination of both in the same Patch Tuesday is especially dangerous. A low-privilege attacker can chain CVE-2026-56155 (EoP in AD FS) with CVE-2026-56164 (EoP in SharePoint) for a progressive privilege escalation across the organisation’s identity and collaboration infrastructure.
SharePoint Server 2016, 2019 and Subscription Edition — CVE-2026-56164 and CVE-2026-58644. Enable AMSI and set Request Body Scan to Full as a stopgap, but the patch is the only real fix.
Windows Server with AD FS enabled — CVE-2026-56155. Patch immediately. Review AD FS logs for anomalous authentications before the patch.
Priority 2 — Patch this week (CVSS 9.8, no active exploitation confirmed yet):
Microsoft Dynamics NAV (on-premise) and Dynamics 365 Business Central (on-premise) — CVE-2026-55944. Cloud deployments are not affected: risk is specific to on-premise.
Windows Server with Print Spooler enabled — CVE-2026-58608. Disable Print Spooler on servers that do not need it while applying the patch.
Priority 3 — Apply in the next maintenance window:
Windows 11 on portable devices — CVE-2026-50661 (BitLocker bypass, physical access required). Prioritise for laptop fleets that leave the building.
All remaining Windows components — plan the remaining 59 critical and 510 important vulnerabilities for urgent application.
Key lessons: how to manage 570 patches without overwhelming the IT team
Step 1: check KEV status before anything else
CISA’s KEV catalog is the most reliable indicator of real risk. Before reviewing the full list of 570 CVEs, check which appear in KEV. July 2026: CVE-2026-56155 and CVE-2026-56164. Those go first, regardless of Microsoft’s official CVSS.
Step 2: do not rely solely on the vendor’s exploitability index
CVE-2026-56164 was labelled “less likely” by Microsoft then confirmed in KEV with real exploitation. Complement vendor ratings with KEV, Qualys/Tenable/Rapid7 advisories, and INCIBE/CCN-CERT alerts when available.
Step 3: prioritise by critical infrastructure, not just CVSS
CVE-2026-56164 has CVSS 5.3 — a severity many teams would dismiss in a normal cycle. Active exploitation in the organisation’s intranet and collaboration platform makes it urgent regardless. The correct hierarchy: active exploitation + critical infrastructure > high CVSS on non-critical system.
Step 4: review SharePoint and AD FS logs for pre-patch activity
Both CVEs were being exploited before the patch. Patching today does not remove a compromise that may have occurred between 1 July (when CISA added CVE-2026-56164 to KEV) and today. Review SharePoint access logs and AD FS logs for anomalous authentications or privilege escalations during that period.
Cybersecurity as a strategic priority
The July 2026 Patch Tuesday is the first clear signal of a regime change in vulnerability management: AI is accelerating flaw discovery at a pace that monthly patching processes were not designed to absorb. This is not an anomaly: it is the new standard. The Apolo blog has been documenting this trend since June: the NCSC warned that AI models would accelerate vulnerability discovery; Bad Epoll showed that AI can find bugs dormant for years in code but also miss adjacent ones; today Microsoft confirms that systematic AI code analysis produces hundreds of new vulnerabilities per month. For Spanish CISOs and IT managers, July’s question is not “when do I patch”. It is “do I have a prioritisation process that can absorb 570 patches in a month when the next cycle brings another 400?”
Apolo Cybersecurity: prioritisation and urgent application of July 2026 critical patches
At Apolo Cybersecurity we help IT teams manage high-volume patch cycles like July 2026: identification of Patch Tuesday CVEs with active exploitation and CISA KEV presence, prioritisation by critical infrastructure (SharePoint Server, AD FS, Dynamics NAV on-premise), SharePoint and AD FS log review for anomalous activity before the patch, and design of patching processes that can absorb growing volumes without overwhelming maintenance teams.
Do you have SharePoint Server, AD FS or Dynamics NAV on-premise and no confirmation that July patches are applied? We audit patch status and review pre-patch activity logs within 24 hours.