MilikMilik

Microsoft’s Record Patch Tuesday Is a Wake-Up Call, Not a One-Off

Microsoft’s Record Patch Tuesday Is a Wake-Up Call, Not a One-Off
Interest|High-Quality Software

622 Microsoft Security Patches: What This Record Release Really Means

Microsoft’s latest Patch Tuesday is a record-breaking security update that delivers 622 distinct CVE vulnerability fixes across Windows, Office, SharePoint, and identity services, including two zero-day exploits already under active attack, and it forces defenders to rethink how they prioritize Windows updates when traditional severity scores no longer reflect real-world risk.

This is not a noisy but routine Patch Tuesday; it is a turning point. Microsoft shipped 622 CVEs in a single release, more than tripling June’s record of roughly 200 and making it the largest update in the program’s history. The July release alone is bigger than the three previous months combined. Windows accounts for 416 of the 622 fixes, while Office receives patches covering 164 issues. This flood is where Microsoft security patches are headed, not an exception. As AI-driven tooling finds more bugs faster, the company has already warned customers to expect “a higher volume of security updates included in each security release”. If you are still sorting patches by CVSS score and waiting for quiet months, this update is proof that era is over.

Microsoft’s Record Patch Tuesday Is a Wake-Up Call, Not a One-Off

Two Quiet-Sounding Zero-Days You Cannot Ignore

Buried inside the 622 CVEs are the only items that should matter to you today: the live zero-day exploits. Two of the fixes close holes that attackers are already exploiting, and both sit in the infrastructure that decides who is trusted inside your environment. CVE-2026-56164 is an elevation-of-privilege flaw in on-premises SharePoint Server that lets an unauthenticated attacker escalate privileges over the network with no credentials or user interaction required. CVE-2026-56155 is an Active Directory Federation Services elevation-of-privilege bug that an already-authenticated attacker can use locally.

These are not flashy remote code execution headlines, and that is exactly why many teams might underestimate them. Both are privilege bugs in identity and collaboration infrastructure: the company document store and the box that signs its logins. Microsoft even rates the SharePoint bug fairly low on severity, a reminder that severity labels are the wrong lens this month. The two exploited zero-days carry mid-tier scores of 5.3 and 7.8, which means “critical” no longer sorts anything when more than 600 CVEs drop in a day. If you run self-hosted SharePoint or AD FS, these are the Microsoft security patches that must jump to the front of your queue.

The risk is sharper for legacy SharePoint. If you run self-hosted SharePoint, this is the one to grab first, and there is a second clock on it: the same day the patch arrived, SharePoint Server 2016 and 2019 reached end of extended support, and there is no paid extended security updates program to fall back on. This is not the CVE you leave until next quarter.

Kerberos RC4 Hardening: The Change That Breaks Before It Protects

Beyond headline zero-day exploits, one change in this Patch Tuesday can hurt you in a different way: it breaks things first. Microsoft has finished its multi-year Kerberos RC4 hardening in this release. The July rollout removes the RC4DefaultDisablementPhase rollback switch, the escape hatch admins have leaned on since Microsoft began the crackdown in January. After this, RC4 works only for accounts explicitly configured to allow it.

If any service account in your environment still requests RC4 Kerberos tickets, it can fail authentication the moment the update lands. That is why this change demands careful Windows update prioritization and testing. The order matters: audit first using the RC4 audit events Microsoft added in January, then rotate the passwords on flagged service accounts so Windows generates AES keys for them, then patch. Rotation only fixes accounts that are missing AES keys; anything pinned to RC4 by configuration, or any legacy client that only speaks RC4, needs its own remediation before the update. This RC4 cleanup will not get you breached by itself, but it will page you at 2 a.m. if you skip the audit phase.

How to Prioritize This Patch Tuesday: Stop Worshipping CVSS

With 622 CVE vulnerability fixes on the table, “patch everything now” is not useful guidance. You have to triage, but the old method—sorting by CVSS score and calling it a day—is broken. This month’s two exploited bugs make the point: neither is a headline 9.8, both are mid-tier privilege flaws, and both are already in use. In parallel, a third zero-day, CVE-2026-50661, is publicly disclosed but not under attack; it is another BitLocker bypass that needs physical access to the device, so it does not jump the queue.

For defenders, the calculus has shifted. Sort by what is being exploited, not by CVSS score, and patch faster than you used to. That means: first, apply the SharePoint and AD FS zero-day fixes wherever those products are present, regardless of their official severity labels. If you run self-hosted SharePoint, also enable AMSI in Full Mode on the server, which Microsoft notes can blunt attacks on CVE-2026-56164. Next, prioritize identity, remote code execution, and token-signing infrastructure updates, then move on to the long tail of Windows and Office fixes. Do not wait for an appearance on any exploited-vulnerability catalog—Microsoft’s own ratings already mark both key CVEs as exploited.

The New Normal: AI-Driven Volume and Defender Overload

This record Patch Tuesday is not an isolated spike; it is a preview of life in an AI-accelerated vulnerability world. Microsoft has warned that customers should expect a higher volume of security updates as its internal multi-model agentic scanning tools find more issues, contributing to months where hundreds of Microsoft security patches land at once. To cope, the company’s Security Update Guide no longer lists every individual CVE, instead switching to summary tables grouped by product family and a Notable CVEs section. Individual advisories still exist, but defenders must assemble the full picture themselves.

The volume is also undermining traditional signaling. When two actively exploited zero-day exploits are labeled with mid-tier scores, and when researchers can build proof-of-concept exploits for vulnerabilities rated “Exploitation Less Likely” or “Exploitation Unlikely”, severity-based triage loses meaning. The only sustainable response is disciplined Windows update prioritization centered on exploit status, identity infrastructure, and configuration-breaking changes like the Kerberos RC4 cutoff. This month, the message is blunt: treat the 622 CVEs as a wall of noise, pull out the handful that can hurt you today or break you tonight, and patch them first. Everything else can wait a short while; live zero-days cannot.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!