Back to Blog

Microsoft Released 622 Security Fixes Last Tuesday. Start With the Two That Attackers Are Already Using.

Every second Tuesday of the month, Microsoft ships security updates. Most months it’s 100 to 200 fixes, IT teams triage them, and everything moves on. Last Tuesday was different. The July 2026 Patch Tuesday dropped 622 CVEs, nearly triple any previous month and the most in Microsoft’s history.[1] Included in that pile are three zero-day vulnerabilities, two of which were already being used to break into real systems before any patch existed.[2]

622 is an overwhelming number for anyone who isn’t a full-time security engineer. But here’s the thing: you don’t need to care about all 622. You need to care about two of them, and you have a week to act on one before a government-set remediation deadline hits.

Why the Number Is So High This Month

Microsoft explained the surge. They deployed an internal AI-driven scanning system called MDASH that’s dramatically accelerating how fast they find vulnerabilities in their own products.[1] Faster discovery is a good thing. The uncomfortable side effect is a much bigger monthly workload for everyone responsible for keeping Windows machines updated. This probably isn’t a one-time spike. Expect the volume to stay elevated.

The AD FS Zero-Day (CVE-2026-56155)

Active Directory Federation Services, or AD FS, is the component that handles single sign-on in many business environments. If your employees log in once and automatically get access to SharePoint, email, your line-of-business apps, and other services without re-entering a password, there’s a decent chance AD FS is involved in that process.

CVE-2026-56155 lets an attacker with low-level access inside your network escalate to administrator on your AD FS server.[3] From there, they can forge authentication tokens. A forged token is basically a master key. The attacker can present themselves as any user in your organization, including the CEO and whoever manages your finances, and every connected service believes them. No password required. Microsoft’s own incident response team, DART, found this vulnerability while investigating live intrusions, which means it was being used against real targets before the fix was available.[3]

CISA added it to their Known Exploited Vulnerabilities catalog on July 14 and gave federal agencies until July 28 to patch it.[4] That deadline is eight days from today. It’s reasonable to treat it as your deadline too.

The SharePoint Zero-Day (CVE-2026-56164)

If you’re on Microsoft 365, you’re running SharePoint whether you think of it that way or not. Teams stores files in SharePoint. OneDrive is SharePoint-based. CVE-2026-56164 is a missing authentication check in SharePoint Server that lets attackers elevate their privileges over the network.[2] Like the AD FS bug, this one was exploited before the patch dropped. It’s in the same CISA alert, same July 28 deadline.

A third zero-day (CVE-2026-50661, a BitLocker bypass) was publicly disclosed before the patch but hasn’t been confirmed as actively exploited yet. Worth patching, but not the one I’d lose sleep over first.

One More Thing: SonicWall

On the same day as Patch Tuesday, CISA also added two SonicWall SMA1000 vulnerabilities to the KEV catalog.[5] One of them is a CVSS 10.0 server-side request forgery flaw. When chained with the second, attackers can run arbitrary commands with administrator privileges, and the federal remediation deadline for those already passed on July 17. If your business uses a SonicWall SMA1000 appliance for remote access, that conversation with your IT team needs to happen today, not next week.

What to Do Right Now

Run Windows Update on every machine in your environment, starting with servers. If you have Windows Server machines running AD FS or SharePoint, those are the priority. The July 2026 patches are what you’re looking for, released July 14.

If you manage IT yourself, this is a straightforward update cycle, just a bigger one than usual. If you work with an IT provider, ask them to confirm the July patches have been applied and that your AD FS configuration has been reviewed. Given that DART found the CVE-2026-56155 during actual incident response work, attackers already know what to look for. Systems sitting unpatched right now are live targets.

The July 28 CISA deadline isn’t set for small businesses, technically, but the vulnerability doesn’t care what size your company is.

If you’re not sure whether your systems are patched or need help reviewing your AD FS setup, reach out here or give us a call at (412) 307-8313. This one’s time-sensitive.

Share
  1. Malwarebytes, “July 2026 Patch Tuesday Fixes 622 Microsoft CVEs, Including Three Zero-Days,” malwarebytes.com
  2. The Hacker News, “Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack,” thehackernews.com
  3. Bytevanguard, “AD FS Zero-Day CVE-2026-56155 Hits CISA KEV,” bytevanguard.com
  4. CISA, “CISA Adds Four Known Exploited Vulnerabilities to Catalog,” cisa.gov
  5. Help Net Security, “SonicWall SMA Appliances Targeted in Zero-Day Attacks (CVE-2026-15409, CVE-2026-15410),” helpnetsecurity.com