Microsoft’s July 2026 Patch Tuesday shipped fixes for 622 vulnerabilities, the largest release in the program’s history, and three of those flaws were already being used against real networks before a patch existed. If your business treats patch management as something that happens whenever someone gets around to it, this is the month that gap gets expensive. The fix isn’t new software. It’s a patch management routine that tests and installs critical fixes within days, not months.
- Microsoft’s July 14 update addressed 622 CVEs, including 62 rated Critical, according to The Hacker News and SecurityWeek.
- Three vulnerabilities were exploited or publicly disclosed before the patch shipped: an Active Directory Federation Services flaw (CVE-2026-56155), a SharePoint Server flaw (CVE-2026-56164), and a BitLocker security feature bypass (CVE-2026-50661).
- CISA added the AD FS flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies until July 28, 2026 to patch it, about two weeks after disclosure.
- The BitLocker bypass needs physical access to a device, which matters most for laptops that leave the building, not just desktops sitting in a locked office.
- A managed patch cadence, not a bigger firewall, is what actually closes the window attackers are counting on.
What actually shipped on July 14?
Microsoft’s July release covered Windows, Office, Azure, and Exchange Online, and the sheer volume stood out even to people who track this every month. The Hacker News reported that this was the biggest single Patch Tuesday since the program started, with 62 of the fixes rated Critical severity. Most months bring a handful of urgent items buried in a long list of routine fixes. This month buried three flaws that mattered a lot, and all three had a head start on the businesses that hadn’t patched yet.
Which flaws were already being exploited?
The AD FS vulnerability, CVE-2026-56155, comes from overly permissive access controls on a component called the Distributed Key Manager container. An attacker who already has a foothold on an AD FS server can use it to mint identities that every connected application already trusts, which is a serious problem for any business relying on federated logins. CISA confirmed active exploitation and set a short remediation clock once it landed on the Known Exploited Vulnerabilities catalog.
The SharePoint flaw, CVE-2026-56164, is a privilege escalation issue reachable over the network without authentication, meaning an attacker doesn’t need stolen credentials to try it. The BitLocker flaw, CVE-2026-50661, is a security feature bypass that was publicly disclosed ahead of the fix, and it requires someone to have the device in hand, which is exactly the scenario a lost or stolen laptop creates.
Why does a Windows update matter to a business in Naples or Fort Myers?
Most small businesses down here don’t run AD FS or a public SharePoint farm, and that’s fine. The pattern is the point, not the specific product. Every month brings a mix of routine fixes and a small number that attackers are already using, and the businesses that get hurt are the ones that can’t tell the difference or don’t have a process to act on it quickly. We wrote about a related version of this problem in our look at Microsoft 365 security gaps, where the risk wasn’t a missing patch but a default setting nobody had reviewed. Both problems come from the same root cause: nobody owns the job of checking.
If your business runs on a mix of employee-owned laptops, an aging desktop in the back office, and whatever Windows update happened to install itself last time someone rebooted, you don’t actually know your exposure. That’s the gap a managed patch process is built to close, and it’s one of the core things a managed IT provider should be doing for you already, not something you find out is missing after an incident.
What should you actually do this week?
Start by finding out which of your machines are still missing the July updates. If you have a managed IT provider, ask them directly whether every device, including remote and part-time staff laptops, is confirmed patched, not just scheduled. If you don’t, check Windows Update history on your business laptops now, particularly any that travel, since the BitLocker issue only matters once a device is out of your hands. Confirm encryption is actually turned on for those traveling laptops too. A bypass doesn’t help an attacker if there’s nothing worth bypassing.
None of this requires new hardware or a bigger budget. It requires someone checking, on a schedule, and following through when a fix needs to go out fast instead of waiting for the next quiet weekend.
Frequently asked questions
What did Microsoft actually patch in July 2026?
On July 14, 2026, Microsoft released fixes for 622 vulnerabilities, its largest single Patch Tuesday release on record, including 62 rated Critical.
Which vulnerabilities were already being used against real networks?
Three flaws were exploited or publicly known before a fix existed: an Active Directory Federation Services flaw (CVE-2026-56155), a SharePoint Server flaw (CVE-2026-56164), and a BitLocker security feature bypass (CVE-2026-50661).
Why does a BitLocker bypass matter for a small office?
It requires physical access to the device, which is a real risk for laptops that travel for site visits, storm evacuations, or after-hours work, not just desktops locked in a server closet.
How fast should a small business patch a flaw like this?
CISA gave federal agencies about two weeks to patch the AD FS flaw once it hit the Known Exploited Vulnerabilities catalog. A business patching on an ad hoc schedule usually takes far longer, and that gap is exactly what attackers count on.
If you’re not sure whether every device on your network is actually patched against this month’s flaws, we’ll check for free. Request a 15-minute patch and security review and we’ll tell you plainly what’s exposed and what it takes to fix it. SWFIT will handle it.