Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources VULNERABILITIES & THREATS APPLICATION SECURITY THREAT INTELLIGENCE NEWS Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes Three of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities. Jai Vijayan,Contributing Writer July 14, 2026 5 Min Read SOURCE: MAFPHOTOART8 VIA SHUTTERSTOCK When Microsoft vice president of engineering Tom Gallagher warned in May that the company's monthly patch releases could soon grow larger because of AI-driven vulnerability discovery, few likely expected the numbers would surpass 600 just two months later. But with fixes for 622 unique CVEs, Microsoft’s July 2026 Patch Tuesday update is the largest by far in the program's history and offers a preview of the growing prioritization challenges organizations face as AI dramatically increases the volume of flaws requiring attention. LOADING... Buried Under the Deluge — 3 Zero-Days July's update contains fixes for three zero-day vulnerabilities, two of which attackers are already exploiting and one that's publicly known but remains unexploited. The patch update also includes fixes for more than five dozen critical vulnerabilities, many of which Microsoft identified as flaws that attackers are more likely to exploit. The total includes 416 vulnerabilities in Windows, 82 each in Office and Office 2016, 46 in Edge, 27 in Microsoft Developer Tools, and 17 in SharePoint Server. Related:Fresh ATM Crypto Software Bugs: Jackpot or Bust? "If people want a severity hook, July has 26 vulnerabilities with a CVSS base score above 9.0, and 13 of those sit at 9.8," said Josh Taylor, lead cybersecurity analyst at Fortra, in an emailed comment. "That matters, but CVSS is still only one part of the risk story. The real triage problem this month is the mix of exploited issues, a publicly disclosed BitLocker flaw, and a massive concentration of vulnerabilities in Windows and Office," he said. And rather than focusing on volume, patching teams need to prioritize the exploited vulnerabilities and their exposed infrastructure first, Taylor added. "Today, July 14, 2026, marks a pivotal moment in our industry," researchers from Nightwing said in a statement. "We are officially moving past the traditional 'Patch Tuesday' approach and entering an era of continuous, high-volume security updates" and continuous patching. LOADING... High-Priority Vulnerabilities The immediate threats in this month's release are CVE-2026-56155 (CVSS: 7.2), an elevation of privilege (EoP) vulnerability in Microsoft Active Directory Federation Services that attackers can exploit to gain system level privileges; and CVE-2026-56164 (CVSS: 5.3), another EoP flaw, this time tied to missing authentication in a critical function in SharePoint Server. The US Cybersecurity and Infrastructure Security Agency (CISA) has already included both bugs in its catalog of known exploited vulnerabilities and given federal agencies until July 17 to address the SharePoint Server issue and July 28 to mitigate the flaw in Active Directory. Related:Microsoft Reins in RoguePlanet Zero-Day Threat The third-zero day vulnerability — publicly known, but as yet unexploited — is a security feature bypass vulnerability in Windows BitLocker, tracked as CVE-2026-50661 (CVSS: 6.1). The vulnerability allows an attacker with physical access to an affected system to bypass BitLocker's Device Encryption feature and gain access to encrypted data. Security experts highlighted several other vulnerabilities in Microsoft's July update — all of them with a CVSS score of 9.0 and higher — as bugs that merit immediate attention. These include: CVE-2026-57092 (CVSS 9.9), a near maximum severity vulnerability in Windows VMSwitch that an attacker could exploit to escape a VM boundary and compromise the host system CVE-2026-48561 (CVSS 9.6), a Microsoft Copilot remote code execution (RCE) vulnerability that an unauthorized attacker can leverage to execute arbitrary code on affected systems CVE-2026-55008 (CVSS 9.6), a spoofing vulnerability in Microsoft Exchange Server that enables an unauthorized attacker to perform spoofing over a network (Microsoft identified this vulnerability as one attackers are more likely to exploit.) CVE-2026-58644 (CVSS: 9.8), an RCE in SharePoint Server Related:CitrixBleed-ing Again? NetScaler Vulnerability Under Attack CVE-2026-55012 (CVSS 7.8) and CVE-2026-55011 (CVSS 7.8), two RCEs in Microsoft Defender Growing Volume a Prioritization Challenge In comments to Dark Reading, Jack Bicer, director of vulnerability research at Action1, says the growing volume of vulnerabilities is not really the biggest challenge. Rather, it's the ability to triage, prioritize, and deploy patches quickly. To keep pace with the accelerating volume of vulnerability disclosures, organizations should implement a comprehensive asset management program; phishing-resistant multifactor authentication; and a centralized patch management system. He recommends organizations also test, deploy, and verify critical and zero-day patches within hours, and high-severity vulnerabilities within days. "Track patch deployment times as a key performance indicator (KPI) and regularly report the results." Satnam Narang, senior staff research engineer at Tenable, says in comments to Dark Reading that building context around vulnerabilities and prioritizing remediation based on those that pose the biggest threats is an organization's best strategy for quickly and demonstrably reducing risk. When considering the exploitability of a vulnerability, organizations need to consider the fact that current exploitability indexes don't account for the speed of AI-developed exploits. For example, Claude's Mythos Preview was able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that Microsoft rated as “Exploitation Less Likely” or “Exploitation Unlikely," he pointed out. "CVSS is a good foundation, but it's just a number. Not every CVSS 9.8 is urgent, and not every CVSS <8.0 should be ignored. Context matters. This is one of the core principles of proactive exposure management." Mayuresh Dani, security research manager, at Qualys Threat Research Unit, says the days of CVSS-only prioritization are over and organizations should consider resources like the Exploit Prediction Scoring System (EPSS), CISA KEV, and the Likely Exploited Vulnerabilities model when prioritizing flaws. "Graduate to a tiered patching SLA mechanism. For example, a KEV-listed CVE or EPSS >0.5 should be patched within 24 to 36 hours. Your next tier is the Internet-facing high-privilege infrastructure such as VPN gateways and remote admin console," he recommends. Dani encourages attack surface reduction and mitigation mechanisms, as well as avoiding exposing services like Active Directory FS to the Internet. Organizations also shouldn't enable SharePoint on premises with public access, or allow remote management tools to be reachable from anywhere. About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program More Webinars You May Also Like VULNERABILITIES & THREATS Exchange Flaw Lets Attackers Spoof Any Email Address by Alexander Culafi JUN 09, 2026 VULNERABILITIES & THREATS Cheap Hardware Module Bypasses AMD, Intel Memory Encryption by Rob Wright NOV 25, 2025 VULNERABILITIES & THREATS Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs by Jai Vijayan NOV 11, 2025 VULNERABILITIES & THREATS Microsoft Issues Emergency Patch for Critical Windows Server Bug by Rob Wright OCT 24, 2025 Editor's Choice CYBERSECURITY OPERATIONS 'Yellow Teams' Are Defining the Future of AI Security byNate Nelson JUL 13, 2026 6 MIN READ CYBERSECURITY O