
Microsoft Patch Tuesday Breaks Record With 622 CVEs, Two Zero-Days Under Active Exploitation
Microsoft’s July Patch Tuesday patches a record 622 CVEs, including two zero-days that are already being exploited: CVE-2026-56164 in on-premises SharePoint Server (unauthenticated remote privilege escalation) and CVE-2026-56155 in AD FS (local privilege escalation). The release also includes a BitLocker bypass (CVE-2026-50661) and numerous other fixes. Administrators should audit RC4 usage, rotate affected service accounts, and prioritize patches for Windows, SharePoint, and AD FS, noting that SharePoint 2016/2019 reach end of extended support.