security
Patch Tuesday Fatigue: What Microsoft's Record 2026 Vulnerability Wave Means for Your Business
Microsoft's July 2026 Patch Tuesday, released July 14, was one of the largest on record — Krebs on Security counted 570 fixed flaws, while other trackers put the figure as high as 621 depending on what's included in the count. For IT teams outside the security function, the exact number matters less than what's actually being exploited in the wild right now.
Two of the three zero-days in that release were already under active attack when patches shipped: CVE-2026-56155, an elevation-of-privilege flaw in Active Directory Federation Services, and CVE-2026-56164, an elevation-of-privilege flaw in SharePoint that CISA added to its Known Exploited Vulnerabilities list on July 1 — meaning it was being used against real targets before most organizations had even applied the patch.
SharePoint had a second, separate problem the same month: CVE-2026-50522, a critical deserialization flaw rated 9.8 out of 10, was confirmed under active exploitation against on-premises SharePoint servers in the weeks after disclosure. Researchers described its impact as comparable to the 2025 "ToolShell" campaign that compromised hundreds of SharePoint customers, including multiple federal agencies — a reminder that on-prem SharePoint deployments are a recurring, high-value target, not a one-off.
August's Patch Tuesday lands August 12, and early guidance already points to another 200-300-plus fixes, including a flagged SharePoint RCE chain and a Windows kernel privilege-escalation issue. If your team is still treating each release as a monthly fire drill instead of a standing process — asset inventory, exploitability triage, and a rollout plan that doesn't wait for a breach to move fast — that gap is exactly what turns a routine CVE into an incident. Apeniq works with lean IT teams to build that process once instead of relearning it every release; get in touch if last month's patch cycle felt more reactive than you'd like.