CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

July 14, 2026

Microsoft shipped its largest Patch Tuesday on record, addressing 622 CVEs, more than triple the previous high. Two zero-days are under active attack: CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services (AD FS). Both are elevation-of-privilege flaws. Microsoft credits Mandiant and Google’s FLARE team for the SharePoint bug, and its own DART unit for the AD FS flaw. A third zero-day, CVE-2026-50661, a BitLocker bypass requiring physical access, was disclosed but not exploited. Rapid7 Labs disclosed CVE-2026-55040, a JWT authentication bypass in SharePoint chained to an unpatched RCE (slated for August). The update also finalizes Kerberos RC4 hardening, removing the rollback switch. Windows accounts for 416 CVEs, including a VMSwitch RCE (CVE-2026-57092, 9.9), five DHCP RCEs, and 21 NTFS/ReFS driver bugs. Office has 82 CVEs, Edge 46, Developer Tools 27, SharePoint 17, Azure 11, SQL Server 8, Defender 5, Exchange Server 5 (including a stored XSS in OWA, CVE-2026-55008, 9.6), and Other 5. Microsoft’s MDASH AI scanning system contributed to discovery. The volume of patches and active exploits underscores the need to prioritize by exploitation status (KEV, EPSS, Microsoft’s flag) rather than CVSS score.

CVEs: CVE-2026-56164, CVE-2026-56155, CVE-2026-50661, CVE-2026-55040, CVE-2026-57092, CVE-2026-50522, CVE-2026-54117, CVE-2026-54118, CVE-2026-55008

Companies: Microsoft, Mandiant, Google, Rapid7, ZDI

Products: SharePoint Server, Active Directory Federation Services, BitLocker, Windows Server, SQL Server, Exchange Server, Microsoft Edge, Visual Studio, VS Code, GitHub Copilot, Azure, Microsoft Defender

Events: Pwn2Own Berlin