Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
Reported exploitedActive DirectorySharePoint ServerOur summary
Microsoft has issued a record number of security patches—622 total—during its July 2026 Patch Tuesday update cycle. Among these, two critical zero-day vulnerabilities were confirmed to be exploited in the wild. These include CVE-2026-56155 affecting Active Directory Federation Services and CVE-2026-56164 impacting SharePoint Server, both enabling privilege escalation attacks. Other notable issues addressed involve Windows VMSwitch, Remote Desktop Protocol, and Exchange Server. This extensive patch release highlights the growing pace of vulnerability discovery, driven in part by AI tools like Microsoft's MDASH.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.