Skip to content
FortaRisks
Back to blogThreat Intelligence

Record Patch Tuesday: 570 flaws, 3 zero-days, and 3 days to patch

July 28, 2026 · 4 min read

On July 14, Microsoft shipped the largest Patch Tuesday in its history: roughly 570 vulnerabilities fixed (622 CVEs counting every entry in the Security Update Guide, excluding Edge's Chromium flaws), around sixty of them rated Critical, and three zero-days. Microsoft attributes part of the surge to an internal AI-assisted vulnerability discovery system. In other words: this volume is probably the new normal, not an outlier.

But the number a risk owner should focus on is not 570. It is 3: the number of days CISA gave US federal agencies to remediate one of the actively exploited flaws. When the regulator of the best-resourced country on earth decides the acceptable window is measured in days, a monthly patch cycle has a design problem.

The two flaws already being exploited

Two zero-days were under active exploitation before the patches even shipped.

  • CVE-2026-56155, Active Directory Federation Services. An elevation of privilege that hands a local attacker administrative control of the AD FS server. It was discovered by Microsoft's own incident response team, meaning it was found in the field, during breach investigations. A compromised AD FS can forge tokens and impersonate any user across every federated service. It is a master key to your identity layer.
  • CVE-2026-56164, SharePoint Server. A missing-authentication flaw, exploitable remotely with no authentication and no user interaction. It was used in a chain with two other flaws (spoofing, then remote code execution) to steal IIS machine keys and establish persistence. On July 15, Microsoft confirmed exploitation of a fourth SharePoint flaw (CVE-2026-58644, rated 9.8).

The IIS machine key detail deserves a pause: when an attacker steals cryptographic secrets, applying the patch does not evict them. The keys have to be rotated too. A program that measures "patch applied" without measuring "secrets rotated" can believe itself protected while remaining compromised.

The biggest lesson: severity is not priority

Here is the most instructive fact of the month. The actively exploited SharePoint flaw, unauthenticated, over the network, was published by Microsoft with a CVSS score of 5.3, "Moderate." Tenable, for its part, scores it 9.8. A patching policy along the lines of "Criticals within 15 days, the rest next cycle" would have pushed the most dangerous bug of the month to the back of the queue.

The reliable signal was elsewhere: CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, with a remediation deadline of July 17. Three days, against the usual two to three weeks.

The governance rule that follows is simple: prioritize on evidence of exploitation (the KEV catalog, threat intelligence, EPSS scores), not on the severity score alone. We have documented this shift before: between the disclosure of a critical flaw and its mass exploitation, you now have hours, not weeks.

What your program should take from this

  • Build an emergency lane measured in days. Your standard SLA can stay monthly. But you need an express lane for actively exploited flaws, with a 72-hour target and a decision path that does not run through the monthly change board.
  • Treat identity infrastructure as a tier-zero asset. AD FS, domain controllers, SSO providers: a compromise there propagates everywhere else. That asset class deserves the shortest SLA and, after patching, a rotation of keys and certificates.
  • Think in chains, not in isolated CVEs. The SharePoint attack combined a 6.5 flaw, an 8.8 flaw and a privilege escalation. Counting individually patched CVEs hides chain risk; the meaningful remediation unit is the exposed product.
  • Measure the exposure window, not the patch rate. The metric that matters to a board is not "98% of patches applied," it is "how many days were we exposed on actively exploited flaws." The first flatters; the second governs.
  • Take offline what does not need to be exposed. On-premises SharePoint and AD FS, reachable from the internet, were the targets. Every legacy service facing the internet is a risk decision to revisit, not a fact of life.

The board question

If 570 flaws a month becomes the norm, the board question is no longer "did we patch everything," which has lost its meaning, but: "on the flaws with proven exploitation, what was our exposure window last month, and who owns reducing it." It is a simple metric, comparable quarter over quarter, and it summarizes the maturity of the whole program.

Where FortaRisks comes in

The FortaRisks Threat Intelligence module crosses your assets with real-world exploitation, the KEV catalog, EPSS and intelligence feeds, so your patch queue reflects actual risk rather than raw CVSS. And to place your overall exposure in minutes, our free cyber risk score gives you a quantified starting point you can bring to an executive committee.

See your real risk in a 30-minute demo.

A member of our team walks you through FortaRisks on threats relevant to your sector. No chatbot.