Microsoft's Record July 2026 Patch Tuesday: What to Patch First
Microsoft's July 2026 Patch Tuesday fixes a record 570 vulnerabilities, including two actively exploited zero-days in AD FS and SharePoint Server. Here's what Griffin IT Group recommends patching first — and why the BitLocker bypass matters for laptops in the field.

Microsoft's July 2026 Patch Tuesday is the largest security update the company has ever shipped in a single release: 570 vulnerabilities fixed, including two zero-days already being exploited in the wild and a third publicly disclosed flaw affecting BitLocker. If your organization runs on-premises Active Directory Federation Services or SharePoint Server, this is not a patch cycle to push to next month's maintenance window.
Here's what's actually in this release, why it's bigger than usual, and what we're telling our own managed clients to prioritize this week.
The headline numbers
Of the 570 flaws Microsoft addressed on July 14, 59 are rated Critical — 48 of those are remote code execution bugs, the kind that let an attacker run arbitrary code without any user interaction. Broken down by category, this month's release included:
- 254 Elevation of Privilege vulnerabilities
- 145 Remote Code Execution vulnerabilities
- 102 Information Disclosure vulnerabilities
- 35 Denial of Service vulnerabilities
- 17 Security Feature Bypass vulnerabilities
- 16 Spoofing vulnerabilities
For context, that's on top of a separate 468 Chromium-based flaws Google patched in Microsoft Edge this month, and doesn't include earlier fixes to Microsoft 365 Copilot, Exchange Online, and Entra Provisioning Service released outside the normal Patch Tuesday cadence. Taken together, July has been an unusually heavy month for Microsoft's security team — and, by extension, for whoever owns patch management at your organization.
Two zero-days already under active attack
Three zero-day vulnerabilities were disclosed alongside this month's fixes. Two are already being exploited; the third was publicly disclosed before a patch existed, though no exploitation has been reported yet.
CVE-2026-56155 — Active Directory Federation Services elevation of privilege
This is the one we'd patch first. A gap in how AD FS scopes access control lets an attacker who already has some level of authenticated access escalate straight to administrator. Microsoft credits its own Detection and Response Team with finding the flaw — typically a sign it surfaced during investigation of a real intrusion, not a routine security audit. If your organization uses AD FS for single sign-on with clients, vendors, or a hybrid identity setup, treat this as a same-week priority. Microsoft hasn't published exploitation details, which usually means the attack technique is still being actively used and they'd rather not hand out a blueprint.
CVE-2026-56164 — SharePoint Server elevation of privilege
This one is arguably worse on paper: a missing authentication check in on-premises SharePoint Server lets a remote, unauthenticated attacker gain elevated privileges over the network — no valid credentials required at all. It was reported by multiple independent researchers (including Mandiant Incident Response and Google Cloud's FLARE team), which tends to happen when a flaw is being actively probed across many organizations at once. If you can't get the patch deployed same-day, Microsoft's documented interim mitigation is to enable the Antimalware Scan Interface (AMSI) on the SharePoint server and set Request Body Scan mode to Full. That buys you time — it isn't a substitute for the actual update.
A publicly disclosed BitLocker bypass
CVE-2026-50661 is different in character from the other two: it requires physical access to the device, so it isn't something that can be exploited remotely over the internet. An attacker with a stolen or unattended laptop could bypass BitLocker Device Encryption and read the contents of the drive directly. That lowers the urgency for desktop workstations sitting in a locked office, but raises it meaningfully for any laptop that leaves the building — field technicians, sales staff, executives travelling for client meetings. This flaw was publicly disclosed rather than found in active attacks, so there's a window to patch before it's weaponized at scale.
Why Patch Tuesdays keep getting bigger
Microsoft flagged last week that it expects the volume of security updates to keep climbing, and named the reason: an AI-assisted vulnerability discovery system now scanning the Windows codebase for flaws before attackers find them. That's a genuinely good development for security over the long run, but it means the operational burden of patch management — testing, deploying, verifying — is going to keep growing too. "We'll get to it next cycle" is a riskier bet with every release.
Other July updates worth knowing about
Alongside the security fixes, Windows 11 (versions 26H1, 25H2, and 24H2) picked up a new recovery feature that lets users roll back to a recent automatic restore point more easily, and versions 25H2/24H2 got a quieter, easier-to-ignore Widgets experience. Windows 10 also received its KB5099539 extended security update for organizations still working through their migration off the platform. None of these are security-critical on their own, but they're worth knowing about before your helpdesk starts fielding "what changed?" tickets.
What we recommend
- Patch AD FS and SharePoint Server this week — both are confirmed under active attack, not theoretical risk.
- If SharePoint patching has to wait even a few days, enable AMSI with Request Body Scan set to Full as an interim control, not a long-term fix.
- Prioritize the BitLocker update on every device that leaves your premises, starting with field and sales laptops.
- Confirm your patch management platform is reporting verified compliance on these three CVEs specifically — "deployment initiated" and "confirmed installed" are not the same status, and the gap between them is where breaches happen.
Griffin IT Group clients on our managed patching program are already being rolled forward on this cycle, with AD FS and SharePoint prioritized ahead of the standard schedule. If you're not sure where your organization stands against July's Patch Tuesday, reach out — we're happy to run a quick compliance check and tell you exactly where the gaps are.