Particle.news

Microsoft Issues Record July Patch Tuesday With Hundreds of Fixes and Two Actively Exploited Zero‑Days

Security teams must speed deployments because AI is accelerating discovery and CISA listings are shortening federal patch deadlines.

Overview

  • Microsoft published its largest single Patch Tuesday on Tuesday, July 14, 2026, releasing roughly 600-plus fixes with outlets and trackers reporting totals of about 622, 621, or 570 depending on counting methods.
  • Two flaws confirmed exploited in the wild are CVE‑2026‑56155 in Active Directory Federation Services and CVE‑2026‑56164 in SharePoint Server and both have been added to CISA’s Known Exploited Vulnerabilities catalog as top remediation priorities.
  • A BitLocker security‑feature bypass, CVE‑2026‑50661, was publicly disclosed before Microsoft shipped a patch, creating an urgent update need for devices at risk of physical compromise.
  • Microsoft and security agencies say AI tools such as MDASH and third‑party models are surfacing many more bugs and speeding exploit development, so administrators are being urged to shorten update deferral windows and use interim mitigations while they test.
  • Defenders face hard tradeoffs: differing CVE counts and CVSS scores complicate triage, Kerberos RC4 hardening in the update can break legacy service logins if accounts are not rotated, and experts advise prioritizing known‑exploited bugs, internet‑facing services, and high‑value assets while monitoring CISA deadlines.