Bg Shape
Image

Microsoft's Record Patch Tuesday, a Live Windows Zero-Day, and a CISA Warning

Robert Kehoe
Chief Technology Officer
Published:
July 20, 2026

Three significant developments landed this week. Each one warrants immediate attention. Together, they represent an unusually dense threat window for security leaders.

Microsoft Shatters Its Own Patch Record

Microsoft released 570 patches in this month's Patch Tuesday, more than doubling the previous record of 207 set just last month. The scale is notable and is widely attributed to AI-assisted vulnerability discovery, accelerating both the identification and remediation of flaws across the Microsoft estate.

Volume alone is not the concern. Two specific vulnerabilities within this release are already being actively exploited in the wild: one in Active Directory and one in SharePoint on-premises. If either technology is present in your environment, these patches are not discretionary. Exploitation of Active Directory vulnerabilities in particular creates direct lateral movement risk across your entire estate. Patch these immediately and treat any delay as an accepted, documented risk.

A Live, Unpatched Windows Zero-Day

A security researcher has published a working proof-of-concept exploit targeting a core Windows user service. Every version of Microsoft Windows is affected. The partial mitigation is that an attacker requires an existing authenticated session to execute the exploit, meaning it is not remotely triggerable without prior access. That is a meaningful constraint, but not a reason for complacency.

Microsoft has not yet released a patch. An out-of-band release is anticipated given the severity. In the interim, lock down exposed remote access points, deploy EDR detections against the published proof-of-concept, and ensure your team is positioned to apply the patch immediately upon release. Treat this as a live, unresolved exposure.

Russian State Actors Are Targeting Routers

CISA, the FBI, the NSA, and a number of international partners issued a joint advisory this week confirming that Russian state-sponsored actors are actively hijacking routers globally. The targeting spans communication, energy, government, and healthcare sectors, and is not limited to the United States. European organisations are explicitly included in the advisory scope.

The attack surface is edge networking infrastructure: routers and other internet-facing devices running outdated firmware or with remote management interfaces exposed to the internet. For CISOs, the immediate actions are clear. Audit firmware on all edge devices, disable unused remote management interfaces, remove internet-facing access to network management where it is not operationally required, and rotate credentials on all internet-facing network gear.

The Week in Summary

This is not a typical patch cycle. A record-breaking vulnerability release, an unpatched zero-day affecting every Windows version, and a state-actor advisory targeting critical infrastructure represent a convergence of pressure that demands prioritised response. Security teams should be operating at heightened tempo this week.

Read Our Latest Blogs

Blog Image
JFrog Confirmed AI Attack, Minnesota Water Attack & Coca-Cola Refuse to Pay

JFrog patches the zero-day used in the Hugging Face breach, Coca-Cola's Fairlife hit by Anubis ransomware, and a coordinated attack knocks out Minnesota water systems.

Blog Image
Ghost Executive: The Fast-Growing Fraud Impersonating Your Leadership

A Ghost Executive attack is a form of business email compromise (BEC) in which a fraudster impersonates a senior figure to authorise a fraudulent payment or reroute a legitimate one. Read more at Smarttech247

Blog Image
Autonomous AI Attacks, Ransomware Disruption, and a Critical WordPress Threat

Explore this week's Risk Radar covering autonomous AI cyberattacks, the Anubis ransomware attack, and a critical WordPress vulnerability, with key guidance for CISOs.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Microsoft's Record Patch Tuesday, a Live Windows Zero-Day, and a CISA Warning

Risk Radar
Vulnerabilities and Exposure
Threat Actors and Campaigns
Robert Kehoe
Chief Technology Officer
July 17, 2026

Three significant developments landed this week. Each one warrants immediate attention. Together, they represent an unusually dense threat window for security leaders.

Microsoft Shatters Its Own Patch Record

Microsoft released 570 patches in this month's Patch Tuesday, more than doubling the previous record of 207 set just last month. The scale is notable and is widely attributed to AI-assisted vulnerability discovery, accelerating both the identification and remediation of flaws across the Microsoft estate.

Volume alone is not the concern. Two specific vulnerabilities within this release are already being actively exploited in the wild: one in Active Directory and one in SharePoint on-premises. If either technology is present in your environment, these patches are not discretionary. Exploitation of Active Directory vulnerabilities in particular creates direct lateral movement risk across your entire estate. Patch these immediately and treat any delay as an accepted, documented risk.

A Live, Unpatched Windows Zero-Day

A security researcher has published a working proof-of-concept exploit targeting a core Windows user service. Every version of Microsoft Windows is affected. The partial mitigation is that an attacker requires an existing authenticated session to execute the exploit, meaning it is not remotely triggerable without prior access. That is a meaningful constraint, but not a reason for complacency.

Microsoft has not yet released a patch. An out-of-band release is anticipated given the severity. In the interim, lock down exposed remote access points, deploy EDR detections against the published proof-of-concept, and ensure your team is positioned to apply the patch immediately upon release. Treat this as a live, unresolved exposure.

Russian State Actors Are Targeting Routers

CISA, the FBI, the NSA, and a number of international partners issued a joint advisory this week confirming that Russian state-sponsored actors are actively hijacking routers globally. The targeting spans communication, energy, government, and healthcare sectors, and is not limited to the United States. European organisations are explicitly included in the advisory scope.

The attack surface is edge networking infrastructure: routers and other internet-facing devices running outdated firmware or with remote management interfaces exposed to the internet. For CISOs, the immediate actions are clear. Audit firmware on all edge devices, disable unused remote management interfaces, remove internet-facing access to network management where it is not operationally required, and rotate credentials on all internet-facing network gear.

The Week in Summary

This is not a typical patch cycle. A record-breaking vulnerability release, an unpatched zero-day affecting every Windows version, and a state-actor advisory targeting critical infrastructure represent a convergence of pressure that demands prioritised response. Security teams should be operating at heightened tempo this week.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365