Bg Shape
Image

Microsoft's Record Patch Tuesday, a Live Windows Zero-Day, and a CISA Warning

Robert Kehoe
Chief Technology Officer
Published:
July 20, 2026

Three significant developments landed this week. Each one warrants immediate attention. Together, they represent an unusually dense threat window for security leaders.

Microsoft Shatters Its Own Patch Record

Microsoft released 570 patches in this month's Patch Tuesday, more than doubling the previous record of 207 set just last month. The scale is notable and is widely attributed to AI-assisted vulnerability discovery, accelerating both the identification and remediation of flaws across the Microsoft estate.

Volume alone is not the concern. Two specific vulnerabilities within this release are already being actively exploited in the wild: one in Active Directory and one in SharePoint on-premises. If either technology is present in your environment, these patches are not discretionary. Exploitation of Active Directory vulnerabilities in particular creates direct lateral movement risk across your entire estate. Patch these immediately and treat any delay as an accepted, documented risk.

A Live, Unpatched Windows Zero-Day

A security researcher has published a working proof-of-concept exploit targeting a core Windows user service. Every version of Microsoft Windows is affected. The partial mitigation is that an attacker requires an existing authenticated session to execute the exploit, meaning it is not remotely triggerable without prior access. That is a meaningful constraint, but not a reason for complacency.

Microsoft has not yet released a patch. An out-of-band release is anticipated given the severity. In the interim, lock down exposed remote access points, deploy EDR detections against the published proof-of-concept, and ensure your team is positioned to apply the patch immediately upon release. Treat this as a live, unresolved exposure.

Russian State Actors Are Targeting Routers

CISA, the FBI, the NSA, and a number of international partners issued a joint advisory this week confirming that Russian state-sponsored actors are actively hijacking routers globally. The targeting spans communication, energy, government, and healthcare sectors, and is not limited to the United States. European organisations are explicitly included in the advisory scope.

The attack surface is edge networking infrastructure: routers and other internet-facing devices running outdated firmware or with remote management interfaces exposed to the internet. For CISOs, the immediate actions are clear. Audit firmware on all edge devices, disable unused remote management interfaces, remove internet-facing access to network management where it is not operationally required, and rotate credentials on all internet-facing network gear.

The Week in Summary

This is not a typical patch cycle. A record-breaking vulnerability release, an unpatched zero-day affecting every Windows version, and a state-actor advisory targeting critical infrastructure represent a convergence of pressure that demands prioritised response. Security teams should be operating at heightened tempo this week.

Read Our Latest Blogs

Blog Image
Three Things Security Leaders Must Know About NIS 2

Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.

Blog Image
Miasma Worm, Microsoft Mega Patch Tuesday & Defender Bypass

This week's Risk Radar covers the Miasma supply chain worm hitting 73 Microsoft GitHub repositories, the largest Patch Tuesday in Microsoft's history including a critical Secure Boot deadline, and a confirmed Microsoft Defender bypass that lets attackers elevate to SYSTEM privileges.

Blog Image
Why your NIS2 Gap Might Sit Outside IT

Discover why NIS2 readiness needs to move beyond policy documents and into operational response planning across IT, OT, and supplier ecosystems.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Microsoft's Record Patch Tuesday, a Live Windows Zero-Day, and a CISA Warning

Risk Radar
Vulnerabilities and Exposure
Threat Actors and Campaigns
Robert Kehoe
Chief Technology Officer
July 17, 2026

Three significant developments landed this week. Each one warrants immediate attention. Together, they represent an unusually dense threat window for security leaders.

Microsoft Shatters Its Own Patch Record

Microsoft released 570 patches in this month's Patch Tuesday, more than doubling the previous record of 207 set just last month. The scale is notable and is widely attributed to AI-assisted vulnerability discovery, accelerating both the identification and remediation of flaws across the Microsoft estate.

Volume alone is not the concern. Two specific vulnerabilities within this release are already being actively exploited in the wild: one in Active Directory and one in SharePoint on-premises. If either technology is present in your environment, these patches are not discretionary. Exploitation of Active Directory vulnerabilities in particular creates direct lateral movement risk across your entire estate. Patch these immediately and treat any delay as an accepted, documented risk.

A Live, Unpatched Windows Zero-Day

A security researcher has published a working proof-of-concept exploit targeting a core Windows user service. Every version of Microsoft Windows is affected. The partial mitigation is that an attacker requires an existing authenticated session to execute the exploit, meaning it is not remotely triggerable without prior access. That is a meaningful constraint, but not a reason for complacency.

Microsoft has not yet released a patch. An out-of-band release is anticipated given the severity. In the interim, lock down exposed remote access points, deploy EDR detections against the published proof-of-concept, and ensure your team is positioned to apply the patch immediately upon release. Treat this as a live, unresolved exposure.

Russian State Actors Are Targeting Routers

CISA, the FBI, the NSA, and a number of international partners issued a joint advisory this week confirming that Russian state-sponsored actors are actively hijacking routers globally. The targeting spans communication, energy, government, and healthcare sectors, and is not limited to the United States. European organisations are explicitly included in the advisory scope.

The attack surface is edge networking infrastructure: routers and other internet-facing devices running outdated firmware or with remote management interfaces exposed to the internet. For CISOs, the immediate actions are clear. Audit firmware on all edge devices, disable unused remote management interfaces, remove internet-facing access to network management where it is not operationally required, and rotate credentials on all internet-facing network gear.

The Week in Summary

This is not a typical patch cycle. A record-breaking vulnerability release, an unpatched zero-day affecting every Windows version, and a state-actor advisory targeting critical infrastructure represent a convergence of pressure that demands prioritised response. Security teams should be operating at heightened tempo this week.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365