🔐 CYBERDEFENSIVE PATCH ADVISORY — MICROSOFT JULY 2026

Issued: 15 July 2026 · Severity: 🔴 CRITICAL — PATCH IMMEDIATELY Distribution: All managed clients · Prepared by: CyberDefensive Pty Ltd Reference: CADV-2026-07-MS-PT

570

Security Vulnerabilities

3

Zero-Days Patched

59

Critical Fixes

48

Remote Code Executions

Executive Summary

Microsoft's July 2026 Patch Tuesday dropped Tuesday 14 July, and it's the biggest patch release in Microsoft's history570 security vulnerabilities fixed in a single go. For comparison, the monthly average this year sat around 100–150. They've rolled out a new AI-powered vulnerability scanning system (internally called MDASH), and it's flushing out bugs at a rate we've never seen before — which is good news (proactive) but also means your patch cycle just got compressed.

Three zero-days were patched:

CISA has added the two exploited zero-days to the Known Exploited Vulnerabilities (KEV) Catalog, which means federal patch deadlines are already in force — and any serious business should treat those deadlines as their own.

570

CVEs Fixed

Record-breaking — largest patch release in Microsoft's history

3

Zero-Days

Patched in this release

2

Actively Exploited

Added to CISA KEV Catalog

~125

Previous Monthly Avg

100–150 CVEs per month this year

🎯 The 3 Zero-Days (Patch First)

🔴 CVE-2026-56155 — Active Directory Federation Services (AD FS)

  • Type: Elevation of Privilege
  • Status: ⚠️ ACTIVELY EXPLOITED IN THE WILD
  • Discovered by: Microsoft's own DART team during live attack investigation
  • Impact: Authorised attacker gains administrator privileges on the AD FS server — basically a master key to your federated identity
  • Who is affected: Any organisation running AD FS on-premises (it's the identity gateway for Office 365, Azure federated apps, SAML SSO)
  • Action: Patch today. If you can't patch within 24 hours, review AD FS admin access logs for anomalous activity since at least late June 2026 [BleepingComputer].

🔴 CVE-2026-56164 — Microsoft SharePoint Server (On-Premises)

  • Type: Elevation of Privilege (missing authentication)
  • Status: ⚠️ ACTIVELY EXPLOITED IN THE WILD
  • Credited to: Mandiant (Jayson Frost), Google Cloud FLARE OTF (Genwei Jiang), and an anonymous reporter
  • Impact: Unauthenticated attacker gains elevated privileges over the network — no credentials required
  • Who is affected: Any business running SharePoint Server on-premises (note: SharePoint Online in Microsoft 365 is NOT affected)

Action:

  1. If you can patch now → just patch.
  1. If you need a 48–72 hour buffer → enable SharePoint Antimalware Scan Interface (AMSI) in "Full" Request Body Scan mode [Microsoft via BleepingComputer]
  1. Review IIS worker process logs for unusual POST requests [Tenable, CrowdStrike].

🟠 CVE-2026-50661 — Windows BitLocker

  • Type: Security Feature Bypass
  • Status: 📢 Publicly disclosed, exploitation considered "less likely" but still pre-patched disclosure is bad news
  • Impact: Attacker with physical access to a powered-on device bypasses BitLocker Device Encryption and reads encrypted data
  • Who is affected: Any Windows 10/11 device with BitLocker enabled — i.e., everyone running corporate laptops and travel devices
  • Action: Patch this week. Particularly important if staff travel with company laptops (and in Sydney, between airport, taxi, and client sites, that's basically all of them) [BleepingComputer].

💀 Critical RCEs Worth Calling Out

Beyond the zero-days, 59 of the 570 fixes are rated "Critical" by Microsoft — and 48 of those are Remote Code Execution (RCE). Here are the CVEs you most want to know about, grouped by product:

Microsoft SharePoint Server (On-Premises) — CVSS 9.8 ⚠️

Same vector as recent "ToolShell"-style attacks — these ones weren't named that, but they share the family [CrowdStrike].

Windows DHCP Server — Critical RCEs ⚠️

Five critical DHCP RCEs landed in this release:

CVE-2026-50518

CVE-2026-50370

CVE-2026-54128

CVE-2026-48564

CVE-2026-56159

A rogue or compromised DHCP server on your network can hand out malicious options to clients — any environment with DHCP-relay, multiple subnets, or guest wifi should patch [CrowdStrike].

Microsoft Dynamics NAV / 365 Business Central (On-Prem)

  • CVE-2026-55944 — Critical RCE, no authentication required, no user interaction [CrowdStrike]

Other Critical RCE Products Patched This Cycle

According to BleepingComputer and Tenable, Microsoft also addressed critical RCEs in:

  • Microsoft Office (Word, Excel, PowerPoint — 9 criticals reported)
  • Windows Media Foundation (5 criticals)
  • Microsoft 365 Copilot
  • Azure OpenAI Service
  • Exchange Server (on-prem)
  • Azure Synapse
  • Hyper-V
  • Minecraft Bedrock Server (yes really — game servers in scope too!)

🛠️ Recommended Actions & Timeline

🧭 Detection & Hunting Guidance

While patches roll out, please ensure your SIEM/SOC is hunting for:

AD FS suspicious activity

Look for unusual token-issuance patterns, new federation trust configurations, anomalous admin role activations [Microsoft MSRC].

SharePoint exploitation

Monitor IIS worker process logs for unusual POST body shapes, AMSI hits in SharePoint Windows Event logs, new IIS modules being loaded.

BitLocker bypass

Less urgent on the hunting front, but worth flagging any endpoint showing tamper events.

📈 Bigger Picture — Why This Is The "New Normal"

This isn't a one-time spike — June 2026 was 198 CVEs, July is 570+. Microsoft's new AI-backed vulnerability scanner (MDASH) is already producing results, and security researchers expect the trend to hold or increase through the rest of 2026.

What this means for your patch policy:

The traditional "review Patch Tuesday on Wednesday, deploy by Friday" cadence is no longer fast enough for actively-exploited zero-days.

A 48-hour SLA for zero-days and 7-day SLA for Critical RCE is now baseline best practice.

Make sure your patch reporting dashboard is showing clients the same picture we're seeing — patch hygiene is becoming a measurable business risk.


📚 References

All CVE details in this advisory have been cross-verified against the following primary sources:


🤝We Are On It

For our managed clients: our team has already initiated the rollout process across all monitored environments. You'll receive a per-environment patch status report within the next 48 hours. If you've not yet opted into our automated patch orchestration for Microsoft products, give us a shout — given this cycle, it's worth the conversation.

Contact: [Your patch management team / service desk / Research@Cyberdefensive.com.au]


This advisory is intended for the recipient organisation's IT and security teams. Distribution outside your organisation requires written permission from CyberDefensive Pty Ltd. CVE details confirmed against Microsoft Security Response Center primary sources as of 15 July 2026.