Patch Tuesday Reaches Breaking Point: 622 CVEs and Two Active Zero-Days
Microsoft Patch Tuesday is a monthly security update cycle in which Microsoft releases fixes for CVE security vulnerabilities across Windows, Office, and related products, and the latest release, containing a record 622 CVEs and multiple zero-day exploits, shows how rapidly growing patch volumes are reshaping enterprise patch management priorities and forcing teams to focus on active exploitation instead of traditional severity scores. Microsoft shipped 622 CVEs in the July Patch Tuesday, more than tripling June’s total and marking the largest update in the program’s history, with the release larger than the previous three months combined. Two actively exploited zero-day exploits are already under attack: CVE-2026-56164, an elevation-of-privilege bug in on-premises SharePoint Server that requires no credentials or user interaction, and CVE-2026-56155, an Active Directory Federation Services elevation-of-privilege flaw. Both sit at mid-tier CVSS scores of 5.3 and 7.8, underscoring that “critical” labels no longer separate what must be patched first when hundreds of CVEs arrive at once.
Identity, Collaboration, and End of Support: Where Risk Is Highest
The most worrying part of this Patch Tuesday is not the raw count of CVEs, but where the worst flaws land. Both exploited zero-days hit core identity and collaboration systems—on‑premises SharePoint Server and Active Directory Federation Services—making them prime targets for attackers seeking privilege escalation across the enterprise. CVE-2026-56164 allows an unauthenticated attacker to elevate privileges over the network on on‑premises SharePoint Server, with no credentials and no user interaction required, which effectively turns a collaboration platform into a launchpad for lateral movement. At the same time, SharePoint Server 2016 and 2019 reached end of extended support on the day of the release, with no paid extended security updates program available, leaving many enterprises facing unsupported, internet‑facing workloads. When identity infrastructure and end‑of‑support collide, “wait and see” is no longer a rational strategy; any organization still running these versions must either patch immediately, accelerate migration, or accept that they are maintaining a permanent high‑risk foothold for attackers.
Volume Has Gone Vertical: Why Old Triage Models Are Failing
The July release is a signal that the threat and discovery landscape has changed more than most enterprise patch management programs have. Windows alone accounts for 416 of the 622 Microsoft fixes, with Office receiving 164 patches—82 unique and double‑counted across tracks—and 58 vulnerabilities rated critical. Yet the two actively exploited zero‑days are not among the highest‑scoring issues, and the top single CVSS rating belongs to a Windows VMSwitch elevation‑of‑privilege bug at 9.9. That mismatch between scores and exploitation is fatal to the traditional approach of sorting patches solely by CVSS. As one Cisco engineer put it when looking across more than 35,000 CVEs in the first half of 2026, “The volume curve has gone vertical, but the exploitation curve has not yet followed,” with only 85 (0.24%) landing in the CISA Known Exploited Vulnerabilities catalog. In other words, enterprises must accept that they are drowning in potential problems and start anchoring their priorities in what attackers are actually using.
AI-Accelerated Discovery and an Industry-Wide Patch Wave
This Patch Tuesday is not an isolated Microsoft event; it is part of a broader industry wave driven in part by AI‑accelerated vulnerability discovery. A Microsoft executive recently warned customers to expect a “higher volume of security updates included in each security release” as AI tools find more bugs, and the company’s own MDASH system identified 16 vulnerabilities in a previous Patch Tuesday. On top of the 622 Microsoft CVEs, there are 428 Chromium vulnerabilities affecting Edge that sit outside the main count. At the same time, other major vendors are shipping their own sizable security updates. Mozilla has released fixes for two critical Firefox vulnerabilities—CVE-2026-15718 and CVE-2026-15719—in version 152.0.6 after warning that exploit code is already public, even though no attacks have been seen yet. Google patched 15 Chrome flaws, including two critical use‑after‑free bugs in Ozone, while Adobe shipped updates for 88 vulnerabilities across ColdFusion, Commerce, Experience Manager, and Illustrator, including a path traversal bug in ColdFusion (CVE-2026-48318, CVSS 9.9) that can lead to arbitrary code execution. Broadcom also fixed a critical authentication bypass in VMware Avi Load Balancer (CVE-2026-47865, CVSS 9.8).

A New Playbook for Enterprise Patch Management
For enterprise defenders, the message is clear: patching the way you did even a year ago is no longer enough. The flood of patches is gutting severity‑based triage, and exploitability ratings designed around human analysis are struggling to keep pace with AI‑driven exploitation, as recent red‑team work showed by producing proof‑of‑concept exploits for vulnerabilities previously labeled “Exploitation Less Likely” or “Exploitation Unlikely.” Practical patch management now starts with a different calculus: sort by what is being exploited, not by CVSS score; patch faster than you used to; and do not wait for a formal KEV listing before treating an exploited bug as urgent. That means prioritizing the Microsoft zero‑days in SharePoint and ADFS, rolling out Firefox 152.0.6 and the latest Chrome builds, applying ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22, and deploying VMware Avi Load Balancer fixes as soon as possible. Although none of the Firefox, Chrome, Adobe, or VMware vulnerabilities are marked as actively exploited yet, organizations should install the latest updates, because attackers routinely weaponize these flaws in real‑world campaigns. The conclusion is uncomfortable but unavoidable: Patch Tuesday is now a race, and enterprises that do not re‑engineer their patch processes for speed and exploit‑driven prioritization will be the ones left exposed.






