Back to Blog

622 patches in a single Tuesday: Microsoft's record and why prioritizing by CVSS is a mistake

Patch Tuesday 07/2026
622 CVEs, 3 zero-days

On July 14, Microsoft shipped the largest Patch Tuesday in its history: 622 vulnerabilities fixed in one go. But the number that bothers us most is not the record. It's that, of the three zero-days in the batch, the one being actively exploited against SharePoint scores 5.3 out of 10 on CVSS. If you prioritize patches by sorting CVSS from high to low —like almost everyone does— that patch would sit somewhere around position five hundred on your list. And it's one of the two or three that cannot wait.

We've spent years managing patching and security for other people's infrastructure, and July 2026 confirms something we'd been warning about: the "one technician reviews the bulletin on Wednesday morning" model no longer scales. Not because anyone is incompetent. Because of volume.

The record's numbers (and why they don't even add up)

Rapid7 and CrowdStrike count 622 Microsoft CVEs in the July batch; BleepingComputer arrives at 570 with its own criteria for what counts. When the specialized press can't even agree on the total, that alone tells you how big the problem is. The rest doesn't fully line up either: 62 critical vulnerabilities according to CrowdStrike, 59 according to BleepingComputer, which also breaks down 254 privilege escalations and 145 remote code executions. The one thing everyone agrees on: it's an all-time record.

The three zero-days, translated

  • 1CVE-2026-56155 — AD FS, elevation of privilege (CVSS 7.8), exploited. A low-privileged local attacker gets to elevate privileges on the server. AD FS is the piece that federates your company's identity with half the world: whoever owns it, owns your SSO. Of the three, the one we would patch first.
  • 2CVE-2026-56164 — SharePoint Server, elevation of privilege (CVSS 5.3), exploited. The flaw is "missing authentication for a critical function": an unauthenticated remote attacker gets to elevate privileges. It sounds bad because it is. The 5.3 is misleading, and that is exactly the problem.
  • 3CVE-2026-50661 — BitLocker, encryption bypass (CVSS 6.1), publicly disclosed. With physical access to the machine, the protection can be bypassed. No confirmed exploitation, but the details are already public before most people have patched. Think of every executive laptop travelling with data on it.

The CVSS trap

CVSS measures technical characteristics of a flaw: vector, complexity, impact. It does not measure the only question you actually care about: how likely is it that someone exploits this against me this week? A 5.3 already being used in real attacks is more urgent than a theoretical 9.8 with no known exploit. And yet most scanners, dashboards and audits still sort the list by the little colored score.

Our order when triaging a bulletin like this one:

  • 1Confirmed exploitation. If the bulletin itself says "exploitation detected", it goes first. The score doesn't matter.
  • 2Exposure. Is that service facing the Internet in your environment? A published SharePoint is not the same as one behind a VPN.
  • 3And only then, severity. With this filter, 622 CVEs come down to a handful of decisions on the same Tuesday. The rest goes into the normal maintenance cycle.

To be clear: this doesn't make the 9.8s ignorable. This month there are two critical RCEs in SharePoint (CVE-2026-50522 and CVE-2026-58644, both CVSS 9.8) that also go to the top of the list if you run SharePoint on-prem. The difference is they go first because SharePoint is in the crosshairs this month, not because the number is high.

What's coming in August already has a CVE number

One detail from Rapid7's analysis almost nobody is talking about: their researcher Stephen Fewer reported CVE-2026-55040, a SharePoint authentication bypass (CVSS 9.1) that forms part of an exploit chain ending in unauthenticated remote code execution. The second half of that chain is embargoed until August. Translation: if you have on-prem SharePoint reachable from the Internet, this month you don't just patch. You seriously ask yourself why it's still reachable from the Internet.

Why 622 and not 150: AI finds flaws faster than you patch

Microsoft attributes part of the spike to its own AI-assisted vulnerability discovery systems proactively combing through the Windows codebase. Rapid7 speaks bluntly of an "AI-fuelled exponential growth of vulnerability reporting and discovery" that has been shaking Microsoft's patch process throughout 2026. Our take: this is not a spike, it's the new baseline. If your patching process barely scaled for the old volumes, it does not scale for 600. And it won't go back: the same tools Microsoft uses to find flaws are available to attackers to find theirs.

What we would do this week with a small IT team

  • AD FS: today. It's identity, it's exploited, and whoever compromises it inherits your SSO.
  • On-prem SharePoint: today as well. The four CVEs mentioned above. And while you're at it, decide whether that server should remain published to the Internet, because August brings the second half of an RCE chain.
  • BitLocker: normal cycle, prioritizing machines that travel. The bypass requires physical access; your datacenter is not the problem, the sales director's laptop is.
  • Everything else: by exposure, not by CVSS order. Internet-facing first, internal after.
  • And one thing that isn't a patch: verify that EDR is deployed and reporting on your AD FS and SharePoint servers. Which is exactly where attackers are already at work.

The uncomfortable part: nobody patches 622 CVEs "in time"

Let's be honest: nobody —including us— applies 622 patches "in time" everywhere. There is always a window between the bulletin and the last patched server, and that window is exactly where incidents happen. The serious answer to that gap is not promising instant patching, which is a lie; it's watching what happens inside while the gap exists. That is what managed EDR/MDR is for: telemetry on endpoints and servers, and someone on watch 24/7 actually looking at it. At everyWAN we run it as a service precisely because an internal team of two or three people cannot patch, watch consoles and handle the daily grind all at once. If that's you, it's not that your team is bad: the volume has moved up a league, and the league is not coming back down.

In short

July's record is not an anecdote: it's a trend with AI behind it. CVSS ranks flaws, not risks: prioritize by real exploitation and by exposure. Patch AD FS and SharePoint now, rethink what you have facing the Internet, and accept that the unpatched window cannot be denied — but it can be watched.

Sources (verified Jul 20, 2026): figures, breakdown and zero-days — BleepingComputer; 622 CVE count, CVSS scores, CVE-2026-55040 and the AI quote — Rapid7; zero-day confirmation and 62 criticals — CrowdStrike. Totals differ between sources depending on counting criteria.

Is your patching plan "whenever we can"?

At everyWAN we manage prioritized patching, EDR/MDR and 24/7 monitoring for companies that cannot dedicate someone to reading 622 CVEs a month. We'll tell you how we would approach your case, no smoke.

Talk to everyWAN

Tags:

Share:

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN