Patch Tuesday July 2026: 570 Flaws, What SMBs Must Patch First
A record 570 vulnerabilities landed on July 14, 2026. Here's the patching order we recommend for small businesses, zero-days first.
Microsoft's Patch Tuesday July 2026 release is the largest in the company's history. On July 14, 2026, Microsoft shipped fixes for 570 vulnerabilities, including three zero-days, two of them already exploited in active attacks (per BleepingComputer). That total doesn't even count the Edge browser fixes released earlier in the month.
A number like 570 can freeze a small IT team. You can't treat it as one job, and you shouldn't try. What you need is an order of operations: the patches that matter this week, the ones that matter this month, and the long tail your normal update cadence will absorb. This guide lays out that order, in the same spirit as our May 2026 Patch Tuesday breakdown.
Key Takeaways
- Microsoft fixed a record 570 vulnerabilities on July 14, 2026, including three zero-days.
- Patch the AD FS and SharePoint zero-days first; both are exploited in the wild.
- Critical SharePoint RCEs CVE-2026-50522 and CVE-2026-58644 come right after the zero-days.
- 59 flaws are rated Critical; internet-facing servers and identity systems go next.
- August's Patch Tuesday lands August 11, 2026, so don't let this backlog linger.
Patch Tuesday July 2026 by the Numbers
Here's how the 570 fixes break down by category, per BleepingComputer's tally:
- 254 elevation of privilege vulnerabilities
- 145 remote code execution flaws
- 102 information disclosure issues
- 35 denial of service bugs
- 17 security feature bypasses
- 16 spoofing vulnerabilities
Of those, 59 carry a Critical rating, and 48 of the Critical flaws allow remote code execution. The Critical RCEs touch Windows Media Foundation, the Remote Desktop Client, Microsoft Defender, Windows DHCP and SQL Server, among others. The Office suite alone collected more than 30 CVEs across Excel, Word, PowerPoint and SharePoint.
Why so many? Microsoft says it recently deployed an AI-powered system that hunts for flaws in the Windows codebase before attackers can find them. More discovery means more patches. Based on field observations across the tenants we manage, months this size may become the new normal, which makes a repeatable patching process worth more than any single fix.

Start With the Three Zero-Days
Zero-days jump the queue because attackers are already using them, or know enough to start. July brought three.
CVE-2026-56155: Active Directory Federation Services
An elevation of privilege flaw in AD FS, actively exploited. An attacker who already has a foothold can abuse overly coarse access controls to gain higher privileges on the server. If you still run AD FS for single sign-on, patch it now. Then put an Entra ID migration on the roadmap; every federation server you retire is one less emergency patch in your future.
CVE-2026-56164: Microsoft SharePoint Server
Also actively exploited. Missing authentication on a critical function lets an unauthenticated attacker elevate privileges over the network, which is about as bad as an elevation bug gets. It affects on-premises SharePoint Server, not SharePoint Online. If you can't patch immediately, Microsoft recommends enabling the Antimalware Scan Interface (AMSI) integration and setting Request Body Scan to Full as an interim measure. Treat that as a bridge, not a fix.
CVE-2026-50661: Windows BitLocker
A publicly disclosed BitLocker bypass. An attacker with physical access to a device could reach encrypted data. No exploitation has been reported yet, but public disclosure means the details are out there. Prioritize the laptops that leave the office: sales reps, executives, anyone who works from airports and cafés.
Then the Critical SharePoint RCEs
Beyond the zero-day, July patches two Critical remote code execution flaws in SharePoint Server, CVE-2026-50522 and CVE-2026-58644, along with a Critical security feature bypass, CVE-2026-55040.
SharePoint deserves its own tier because of how attackers behave. Once a SharePoint patch ships, threat groups race to reverse-engineer it and scan for unpatched servers, and an on-premises SharePoint box often holds a company's most sensitive documents. If your server is reachable from the internet, patch within 24 to 48 hours or pull it offline until you can. Then ask the harder question: does that workload still need to live on-premises? Moving those document libraries into Microsoft 365 shifts the whole patching burden onto Microsoft, an exercise our Microsoft 365 migration service handles regularly.

Rank the Rest by Exposure
With the top of the list handled, sort everything else by how reachable it is:
- Internet-facing systems. Anything exposed to the outside world goes first: RDP endpoints (the Remote Desktop Client got a Critical RCE), VPN gateways running on Windows, exposed SQL Server instances and web servers.
- Identity and core infrastructure. Domain controllers, Active Directory Certificate Services, Hyper-V hosts and DHCP servers. July includes Critical flaws in several of these, and a compromised identity server means a compromised everything.
- The endpoint fleet. Workstations and laptops running Windows and Office. The Media Foundation RCEs matter here, because opening a malicious media file is all it takes.
- Everything else. Low-exposure servers, isolated systems and the long tail of information disclosure and denial of service fixes can ride your normal monthly deployment.
Deploy with rings (a pilot group first, then broader waves) and 570 patches stops being scary. It becomes a scheduling exercise with a clear finish line.
What Managed Patching Looks Like in a Record Month
For our managed clients, July looked like any other month, just heavier. Intune and Windows Autopatch pushed the zero-day fixes to pilot rings within hours of release, servers followed a tested schedule, and Microsoft Defender watched for exploit behaviour on anything not yet patched. That last part matters. Monitoring buys you time when you can't patch everything at once, because you see attempts against the systems still waiting.
If your July patching is still half done as you read this, that's the signal. The gap between "patch released" and "patch installed" is exactly where ransomware operators live, and managed IT services exist to close it. One more date for the calendar: the next Patch Tuesday lands on August 11, 2026, and nothing suggests it'll be small.
FAQ
How many vulnerabilities did Microsoft patch in July 2026?
Microsoft fixed 570 vulnerabilities on July 14, 2026, the largest Patch Tuesday in its history. The release includes 59 Critical-rated flaws and three zero-days, two of which were actively exploited before the patches shipped. The total excludes Edge browser fixes released separately.
Which July 2026 patches should a small business install first?
Start with the three zero-days: the AD FS elevation of privilege flaw, the SharePoint elevation of privilege flaw and the BitLocker bypass. Follow with the Critical SharePoint remote code execution fixes, then patch internet-facing servers and identity infrastructure before working through the rest.
Is SharePoint Online in Microsoft 365 affected?
No action is needed for SharePoint Online; Microsoft patches its own cloud service. The urgent SharePoint CVEs from July 2026 affect on-premises SharePoint Server only. You should still keep desktop Office applications updated, since the release fixed more than 30 Office-related flaws.
When is the next Patch Tuesday?
The next Patch Tuesday falls on August 11, 2026. Microsoft publishes security updates on the second Tuesday of each month. Aim to finish deploying the July fixes before the August wave arrives, so the backlog doesn't compound.
What if my business can't test 570 patches?
Nobody tests 570 patches one by one. The practical approach is ring-based deployment: a small pilot group receives updates first, and broader groups follow once nothing breaks. A managed services provider runs this process for you, including rollback when an update misbehaves.
Sources
A record month doesn't have to mean a record scramble. If you want an honest read on how quickly your business absorbs a Patch Tuesday like this one, our free IT assessment is a good place to start, and we'll show you exactly where the gaps are.
Related Articles
Back to Work: The 10-Point Post-Vacation Security Checklist
Quebec offices are back from the construction holiday. Learn how a 10-point post-vacation security checklist blocks the attacks that target week one.
Entra SMS MFA Retirement: Your Passkey Migration Playbook
The Entra SMS MFA retirement lands February 1, 2027. Learn how to migrate your users to passkeys and phishing-resistant MFA before the deadline.
OAuth App Attacks Are the New Phishing in Microsoft 365
OAuth app attacks stole CRM data in June 2026, no passwords needed. Learn how to lock down app consent in Microsoft 365 before your tenant is next.