Last week, Microsoft confirmed what enterprise security teams had been bracing for since spring. Its new multi-model agentic security scanning harness, internally referred to as MDASH, is now hunting vulnerabilities across the Windows codebase faster than any human research team could match. Microsoft has been explicit that “customers will see a higher volume of security updates included in each security release.”
This July 2026 Patch Tuesday is the first release to make that warning tangible, and enterprise patch teams should expect this elevated cadence to be the new normal rather than a one-month anomaly.
This month's Patch Tuesday shattered the record set just one cycle ago. Microsoft addressed 569 CVEs (industry trackers report figures ranging from 569 to 622 depending on methodology and disclosure timing), easily surpassing June's previous all-time high of 204. As in prior months, this count excludes the separate Chromium/Edge flaws patched by Google, with 468 such issues fixed this cycle and left out of today's core roundup. 56 vulnerabilities are tagged “Critical,” 510 are “Important,” and three are “Moderate.”
July 2026 Patch Tuesday at a Glance
|
Category |
Detail |
|
Total CVEs |
569 |
|
Critical |
56 |
|
Important |
510 |
|
Zero-Days (Exploited in the Wild) |
2 |
|
Zero-Days (Publicly Disclosed) |
1 |
|
Top Affected Products |
Active Directory Federation Services, Microsoft SharePoint Server, Windows BitLocker, Windows Kernel |
|
Immediate Priority |
Active Directory Federation Services, SharePoint Server (on-premises), BitLocker |
Zero-Day Vulnerabilities in the July 2026 Patch Tuesday Release
This month's Patch Tuesday fixes three zero-day vulnerabilities. Unlike June, where all three disclosed zero-days were publicly leaked but not yet weaponized, two of this month's three flaws were already being actively exploited in the wild before a fix was available. Microsoft credits its own Detection and Response Team (DART), along with external researchers at Mandiant and Google Cloud's FLARE OTF, with uncovering the in-the-wild activity — a strong signal that both flaws were first identified during live incident response rather than through routine research.
The third zero-day, a BitLocker bypass, was publicly disclosed rather than exploited, and appears to be connected to last month's saga: the researcher known as “Chaotic Eclipse” (or “Nightmare Eclipse”), who published the day after June's Patch Tuesday a related proof-of-concept called GreatXML on GitHub that is yet another Security Feature Bypass on Windows BitLocker. This month's fix is widely believed to close that gap.
Active Directory Federation Services – Elevation of Privilege
CVE-2026-56155 is an Elevation of Privilege (EoP) vulnerability affecting Active Directory Federation Services (AD FS), the identity federation role many enterprises rely on for SSO and hybrid Azure AD authentication. It was assigned a CVSSv3 score of 7.8 and rated “Important.” Microsoft describes the root cause as insufficient granularity of access control in AD FS, which allows an already-authorized attacker to elevate privileges locally to administrator level. Microsoft confirmed active exploitation and credited the discovery to its own Detection and Response Team (DART), indicating the flaw was likely uncovered while investigating live attacks rather than through pre-release research.
BigFix remediates this vulnerability through the standard cumulative security update fixlets for the affected Windows Server versions running the AD FS role.
Microsoft SharePoint Server – Elevation of Privilege
CVE-2026-56164 is an Elevation of Privilege vulnerability in on-premises Microsoft SharePoint Server, assigned a CVSSv3 score of 5.3 and rated “Moderate” by Microsoft's own scoring, though its active-exploitation status makes it an operational priority regardless of the CVSS band. Microsoft describes the flaw as missing authentication for a critical function, which allows an unauthorized attacker to elevate privileges over the network with no credentials required. It affects SharePoint Server 2019, SharePoint Server Subscription Edition, SharePoint Server 2016, and SharePoint Enterprise Server 2016. Microsoft confirmed in-the-wild exploitation and credited researchers from Mandiant Incident Response and Google Cloud's FLARE OTF team, alongside an anonymous reporter. As an interim mitigation ahead of patching, Microsoft recommends enabling Antimalware Scan Interface (AMSI) integration with the Request Body Scan mode set to Full, which can detect and block malicious POST requests targeting this flaw.
BigFix delivers the SharePoint Server security updates through the dedicated Microsoft Office/SharePoint patch content published alongside the core Windows fixlets this cycle. Three different fixlets are available to fix the vulnerability on SharePoint Server 2016, 2019, and the Subscription Edition.
Windows BitLocker – Security Feature Bypass
CVE-2026-50661 is a Security Feature Bypass vulnerability affecting Windows BitLocker, Microsoft's full-disk encryption feature. It was assigned a CVSSv3 score of 6.1 and rated “Important.” Microsoft states that a successful attacker could bypass BitLocker Device Encryption on the system storage device, gaining access to encrypted data, but only with physical access to the target machine. The flaw was publicly disclosed before a patch was available, though Microsoft assessed it as “Exploitation Less Likely” given the physical-access requirement, and attributed the disclosure to the same researcher behind June's bypass, known as 'Chaotic Eclipse'. This is the second consecutive month BigFix customers have had to remediate a publicly disclosed BitLocker bypass, following CVE-2026-50507 in June; both trace back to the same researcher's disclosure campaign.
As with June's BitLocker fix, remediation for this vulnerability is included in the Cumulative Update fixlets BigFix publishes for each actively supported Windows Client and Server version.
| Vulnerability type | Count | What it means |
|---|---|---|
| Remote Code Execution | 145 | Attackers execute code remotely; highest priority class |
| Elevation of Privilege | 254 | Moves the attacker from limited access to the SYSTEM level |
| Information Disclosure | 102 | Exposes sensitive data; audit and compliance exposure |
| Denial of Service | 35 | Disrupts services; assess business impact per environment |
| Security Feature Bypass | 17 | Disables controls compliance frameworks require to be active |
| Spoofing | 16 | Identity and authentication risk |
During the July 2026 Patch Tuesday cycle, the BigFix Patch team published 296 fixlets covering the Windows, .NET, SQL Server, and SharePoint updates released by Microsoft this month.
Additional remediation content for Windows Applications is available through the BigFix “Updates for Windows Application Extended” External Site. The full list of fixlets for this month's security updates is available in the BigFix Forum
Compliance Risks from July 2026 Patch Tuesday Vulnerabilities
This month's release carries heavier compliance weight than most, because two of the three zero-days — CVE-2026-56155 (AD FS Elevation of Privilege) and CVE-2026-56164 (SharePoint Server Elevation of Privilege) — were confirmed as actively exploited before patches were released. Organizations that fail to remediate actively exploited flaws within required timelines face materially higher audit and regulatory exposure than with publicly disclosed but unexploited issues, since exploitation removes any argument that the risk was theoretical.
AD FS compromise is particularly consequential for identity governance controls under frameworks such as NIST 800-53, SOC 2, and ISO 27001, since AD FS often underpins SSO trust boundaries between on-premises identity and cloud services. Similarly, the SharePoint Server flaw affects a system that frequently stores regulated content (PII, financial records, healthcare data), so an unauthenticated privilege-escalation path directly threatens data-handling controls under HIPAA, PCI DSS, and similar regimes. The BitLocker bypass, CVE-2026-50661, again undermines full-disk encryption as a compensating control for lost or stolen devices — the same concern raised by June's BitLocker zero-day, now recurring for a second straight month.
Conclusion
July 2026 Patch Tuesday is not a routine monthly release. It is the largest security update Microsoft has ever shipped, and it arrives with Microsoft's own confirmation that AI-assisted vulnerability discovery will keep pushing future releases toward this scale. More urgently, two of this month's three zero-days were caught only after attackers were already exploiting them, a sharper threat profile than June's entirely pre-exploitation disclosures. Organizations relying on manual or fragmented patching processes will find it increasingly difficult to triage a release of this size within a defensible remediation window. The organizations best positioned to manage this reality are those with automated, policy-driven patching infrastructure that can absorb record-breaking release cycles without placing undue burden on their security and IT operations teams. HCL BigFix is built for exactly this environment.
See how HCL BigFix can automate remediation across your entire environment without the operational overhead. Book a demo and speak with an HCL BigFix specialist today.
Start a Conversation with Us
We’re here to help you find the right solutions and support you in achieving your business goals.



