
Issued: 15 July 2026 · Severity: 🔴 CRITICAL — PATCH IMMEDIATELY Distribution: All managed clients · Prepared by: CyberDefensive Pty Ltd Reference: CADV-2026-07-MS-PT
Microsoft's July 2026 Patch Tuesday dropped Tuesday 14 July, and it's the biggest patch release in Microsoft's history — 570 security vulnerabilities fixed in a single go. For comparison, the monthly average this year sat around 100–150. They've rolled out a new AI-powered vulnerability scanning system (internally called MDASH), and it's flushing out bugs at a rate we've never seen before — which is good news (proactive) but also means your patch cycle just got compressed.
Three zero-days were patched:
CISA has added the two exploited zero-days to the Known Exploited Vulnerabilities (KEV) Catalog, which means federal patch deadlines are already in force — and any serious business should treat those deadlines as their own.
Record-breaking — largest patch release in Microsoft's history
Patched in this release
Added to CISA KEV Catalog
100–150 CVEs per month this year
Action:
Beyond the zero-days, 59 of the 570 fixes are rated "Critical" by Microsoft — and 48 of those are Remote Code Execution (RCE). Here are the CVEs you most want to know about, grouped by product:
Same vector as recent "ToolShell"-style attacks — these ones weren't named that, but they share the family [CrowdStrike].
Five critical DHCP RCEs landed in this release:
A rogue or compromised DHCP server on your network can hand out malicious options to clients — any environment with DHCP-relay, multiple subnets, or guest wifi should patch [CrowdStrike].
According to BleepingComputer and Tenable, Microsoft also addressed critical RCEs in:
While patches roll out, please ensure your SIEM/SOC is hunting for:
Look for unusual token-issuance patterns, new federation trust configurations, anomalous admin role activations [Microsoft MSRC].
Monitor IIS worker process logs for unusual POST body shapes, AMSI hits in SharePoint Windows Event logs, new IIS modules being loaded.
Less urgent on the hunting front, but worth flagging any endpoint showing tamper events.
This isn't a one-time spike — June 2026 was 198 CVEs, July is 570+. Microsoft's new AI-backed vulnerability scanner (MDASH) is already producing results, and security researchers expect the trend to hold or increase through the rest of 2026.
What this means for your patch policy:
The traditional "review Patch Tuesday on Wednesday, deploy by Friday" cadence is no longer fast enough for actively-exploited zero-days.
A 48-hour SLA for zero-days and 7-day SLA for Critical RCE is now baseline best practice.
Make sure your patch reporting dashboard is showing clients the same picture we're seeing — patch hygiene is becoming a measurable business risk.
All CVE details in this advisory have been cross-verified against the following primary sources:
For our managed clients: our team has already initiated the rollout process across all monitored environments. You'll receive a per-environment patch status report within the next 48 hours. If you've not yet opted into our automated patch orchestration for Microsoft products, give us a shout — given this cycle, it's worth the conversation.
Contact: [Your patch management team / service desk / Research@Cyberdefensive.com.au]
This advisory is intended for the recipient organisation's IT and security teams. Distribution outside your organisation requires written permission from CyberDefensive Pty Ltd. CVE details confirmed against Microsoft Security Response Center primary sources as of 15 July 2026.
🔐 CYBERDEFENSIVE PATCH ADVISORY — MICROSOFT JULY 2026