PatchTriageWhat to patch first
Patch Intelligence Brief

Microsoft Patch Tuesday — July 2026

Microsoft shipped 653 fixes this month, 75 of them rated Critical. A further 762 entries in the same document are third-party CVEs Microsoft republishes or Edge/Chromium updates, carrying 39 Critical — counted separately here, because that total tracks Microsoft's role as a CNA rather than the size of Patch Tuesday. 4 are already under active attack and should be patched today; 1 publicly disclosed zero-day should be closed this week. Everything else fits the normal monthly cycle.

Compiled 2026-07-26 23:40 UTC Basis MSRC 2026-Jul · CISA KEV MSRC document revision 831, last revised 2026-07-25 00:29 UTC (first released 2026-07-14 07:00 UTC) Corroboration krebsonsecurity.com · thezdi.com · isc.sans.edu · bleepingcomputer.com · HCL BigFix
653
Microsoft-authored CVEs
75
rated Critical (Microsoft)
762
third-party / Chromium
39
rated Critical (everything else)
4
actively exploited
1
disclosed zero-day

As of 2026-07-26 23:40 UTC, this cycle’s MSRC document lists 1,415 CVEs — 653 Microsoft-authored, plus 464 Edge/Chromium and 298 Linux/other entries that are republished third-party fixes patching through their own vendors. That figure is a reading at a timestamp, not a fixed total for the month: Microsoft revises this document in place, and it is currently at revision 831 (last revised 2026-07-25 00:29 UTC). The two Critical lines above are kept separate for the same reason — the third-party total moves with Microsoft’s CNA scope, not with the size of Patch Tuesday.

Patch today

Confirmed in CISA KEV and flagged as exploited by Microsoft. Treat as active incidents, not routine patching.

CVE-2026-50522 Exploited CVSS 9.8 Microsoft SharePoint Remote Code Execution

in CISA KEV (added 2026-07-22); network / no-auth / no-interaction; MSRC: exploitation more likely; ⬆ HCL: flagged dangerous. Owner routes to the SharePoint owners team.

Owner: SharePoint owners
CVE-2026-58644 Exploited CVSS 9.8 Microsoft SharePoint Remote Code Execution

in CISA KEV (added 2026-07-16); MSRC Exploited; network / no-auth / no-interaction. Owner routes to the SharePoint owners team.

Owner: SharePoint owners
CVE-2026-56155 Exploited CVSS 7.8 Active Directory Federation Services Elevation of Privilege

in CISA KEV (added 2026-07-14); MSRC Exploited. Owner routes to the Identity / AD team.

Owner: Identity / AD
CVE-2026-56164 Exploited CVSS 5.3 Microsoft SharePoint Server Elevation of Privilege

in CISA KEV (added 2026-07-14); MSRC Exploited; network / no-auth / no-interaction; ⬆ HCL: flagged dangerous. Owner routes to the SharePoint owners team.

Owner: SharePoint owners

Close this week

Publicly disclosed but not yet observed in the wild — a zero-day on a countdown. Schedule ahead of the normal cycle.

CVE-2026-50661 Zero-day CVSS 6.1 Windows BitLocker Security Feature Bypass

publicly disclosed (zero-day); ⬆ HCL: flagged dangerous. Owner routes to the Endpoints / Windows client team.

Owner: Endpoints / Windows client

Who owns what

This month's priority items grouped by the team that patches them.

Other / general Windows61
57106 · 57100 · 54120 · 56165 · 55010 · 38968 · +55
Office / productivity16
8926 · 55045 · 50314 · 50467 · 55018 · 55022 · +10
Cloud / M365 apps15
56163 · 62825 · 58630 · 45499 · 50517 · 55944 · +9
Network / infra servers8
58275 · 50518 · 56159 · 56188 · 54999 · 48564 · +2
SharePoint owners4
50522 · 58644 · 56164 · 55040
Identity / AD3
56155 · 54121 · 49164
Endpoints / Windows client3
50661 · 54982 · 54995
Exchange / mail3
56191 · 55008 · 54998
Virtualization / Hyper-V3
57092 · 50680 · 54127
Database / SQL2
54117 · 54118
Remote access / RDP1
50474

Priority ranking

Ordered by a composite priority that weights active exploitation and disclosure above raw CVSS. Showing the sharp end; the full ranked set of 1,415 CVEs is in the index.

CVEStatusCVSSImpactOwner
CVE-2026-50522Exploited9.8Remote Code ExecutionSharePoint owners
CVE-2026-58644Exploited9.8Remote Code ExecutionSharePoint owners
CVE-2026-56155Exploited7.8Elevation of PrivilegeIdentity / AD
CVE-2026-56164Exploited5.3Elevation of PrivilegeSharePoint owners
CVE-2026-50661Zero-day6.1Security Feature BypassEndpoints / Windows client
CVE-2026-56163Critical10.0Elevation of PrivilegeCloud / M365 apps
CVE-2026-56191Critical10.0TamperingExchange / mail
CVE-2026-57106Critical10.0Elevation of PrivilegeOther / general Windows
CVE-2026-62825Critical10.0Elevation of PrivilegeCloud / M365 apps
CVE-2026-58630Critical10.0Elevation of PrivilegeCloud / M365 apps
CVE-2026-58275Critical10.0Elevation of PrivilegeNetwork / infra servers
CVE-2026-45499Critical9.9Elevation of PrivilegeCloud / M365 apps
CVE-2026-57100Critical9.9Elevation of PrivilegeOther / general Windows
CVE-2026-54120Critical9.9Remote Code ExecutionOther / general Windows
CVE-2026-57092Critical9.9Elevation of PrivilegeVirtualization / Hyper-V

Plus further Critical-severity items this cycle — browse and filter them all in the index.

Browse the full index of all 1,415 vulnerabilities →

Deep dives

The items on the sharp end, with attack profile and cross-source context.

Microsoft SharePoint Remote Code Execution

Severity
Critical · CVSS 9.8 · Remote Code Execution
Profile
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Why now
in CISA KEV (added 2026-07-22); network / no-auth / no-interaction; MSRC: exploitation more likely; ⬆ HCL: flagged dangerous

↑ Corroborated — HCL BigFix field analysts independently flagged this item in their published briefing.

Microsoft SharePoint Remote Code Execution

Severity
Critical · CVSS 9.8 · Remote Code Execution
Profile
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Why now
in CISA KEV (added 2026-07-16); MSRC Exploited; network / no-auth / no-interaction

↑ Corroborated — HCL BigFix field analysts independently flagged this item in their published briefing.

Active Directory Federation Services Elevation of Privilege

Severity
Important · CVSS 7.8 · Elevation of Privilege
Profile
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Why now
in CISA KEV (added 2026-07-14); MSRC Exploited

↑ Corroborated — HCL BigFix field analysts independently flagged this item in their published briefing.

Microsoft SharePoint Server Elevation of Privilege

Severity
Moderate · CVSS 5.3 · Elevation of Privilege
Profile
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:O/RC:C
Why now
in CISA KEV (added 2026-07-14); MSRC Exploited; network / no-auth / no-interaction; ⬆ HCL: flagged dangerous

↑ Corroborated — HCL BigFix field analysts independently flagged this item in their published briefing.

Windows BitLocker Security Feature Bypass

Severity
Important · CVSS 6.1 · Security Feature Bypass
Profile
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
Why now
publicly disclosed (zero-day); ⬆ HCL: flagged dangerous

↑ Corroborated — Automox independently flagged this item in their published briefing.

Sources & method

Authoritative counts and exploitation flags come from Microsoft's MSRC Security Update Guide and CISA's Known Exploited Vulnerabilities catalog. Independent reporting and analyst commentary corroborate and add context but do not set priority.

Ranking is a composite score that weights active exploitation and public disclosure above raw CVSS, adjusted for network-reachable / no-authentication attack profiles and field-analyst judgment — which is why a low-CVSS vulnerability under active attack can outrank an unexploited 9.8.

  • BackboneMicrosoft MSRC (2026-Jul) · CISA KEV catalog
  • Reportingkrebsonsecurity.com · thezdi.com · isc.sans.edu · bleepingcomputer.com
  • AnalystHCL BigFix field analysts · Automox