

The July 2026 release affects a broad range of Microsoft products including Windows 10 and 11 (multiple versions), Windows Server 2016 through 2025, Microsoft Office (M365, LTSC 2021/2024, mobile), SharePoint Server (2016, 2019, Subscription Edition), Exchange Server (2016, 2019, Subscription Edition), SQL Server (2019, 2022), Hyper-V, Remote Desktop Services, Microsoft Defender, and over 150 additional components.
Microsoft's July 2026 Patch Tuesday is the largest in the company's history, addressing 569 CVEs, surpassing the previous record of 198 set in June 2026. The release includes 56 Critical-rated vulnerabilities, 510 Important, and 3 Moderate. Three zero-day vulnerabilities are included: two were actively exploited in the wild prior to patch availability and one was publicly disclosed. Elevation of Privilege vulnerabilities represent the largest category at 43.8%, followed by Remote Code Execution at 25.1%. Separately, CISA issued an urgent advisory regarding active exploitation of three SharePoint Server vulnerabilities, urging organisations to harden deployments and apply patches immediately.
Patches released 14 July 2026. CVE-2026-45659 (SharePoint deserialization RCE, CVSS 8.8) added to CISA KEV on 1 July 2026 and actively exploited. CVE-2026-56164 (SharePoint missing authentication) added to CISA KEV on 14 July 2026 and actively exploited. CVE-2026-32201 (SharePoint authentication bypass, CVSS 6.5) added to CISA KEV on 14 April 2026 and actively exploited. Two additional zero-days in this Patch Tuesday were exploited before patch availability; one was publicly disclosed without confirmed exploitation.
Windows systems across all supported versions represent the broadest surface for Elevation of Privilege and RCE. SharePoint Server on-premises deployments (2016, 2019, Subscription Edition) are actively targeted; Microsoft 365 SharePoint Online is not affected. Office applications across desktop and mobile represent an additional high-priority RCE surface. Exchange Server deployments are exposed to a spoofing vulnerability. Any organisation with unpatched on-premises SharePoint should treat this as an active incident risk given confirmed in-the-wild exploitation.
The three actively exploited SharePoint vulnerabilities represent the most immediate operational risk. CVE-2026-45659 allows an authenticated attacker with Site Member permissions to achieve remote code execution on SharePoint Server through deserialization of untrusted data. Post-exploitation activity observed by Microsoft includes deployment of Warlock ransomware, Velociraptor tooling, Cloudflare tunnelling, and use of a vulnerable driver (NSecKrnL.sys) to tamper with endpoint security controls. A concurrent attacker in the same victim environment used DLL side-loading and custom backdoors with lateral movement into a second organisation, demonstrating the risk of delayed remediation on actively exploited systems.
The 56 Critical-rated CVEs across Windows, Office, SharePoint, SQL Server, Exchange, and Hyper-V represent further RCE and privilege escalation risk across the full Microsoft estate. Hyper-V Elevation of Privilege vulnerabilities (CVE-2026-50680, CVE-2026-54127) are of particular concern in virtualised and cloud-hosted environments.
Risk is rated High for large and medium government and business entities, and Medium for small entities and home users. The record scale of this Patch Tuesday, 569 CVEs in a single release, combined with three zero-days and confirmed active SharePoint exploitation, makes this the highest-priority Microsoft patch cycle in recent history. Organisations with on-premises SharePoint Server must treat this as an emergency response rather than routine patching.
Apply all July 2026 Patch Tuesday updates immediately. Prioritise SharePoint Server, Windows, and Office given active exploitation and Critical severity ratings. For SharePoint specifically: verify AMSI integration is enabled for each web application in Full Mode for Request Body Scan Mode; monitor for AMSI detections including Exploit:Script/SuspSignoutReqBody.A and Exploit:Script/ToolPaneAuthBypass.A; and hunt for the MDAV detection Backdoor:MSIL/LeakFang.A!dha indicating post-exploitation activity involving IIS-protected secrets.
Before rotating IIS machine keys, hunt for and remediate any machine-key harvesters that could allow the keys to be stolen again. Avoid exposing SharePoint Server directly to the internet; if required, place it behind a Layer 7 reverse proxy with authentication and request inspection. Block external access to SharePoint Central Administration and restrict farm and database communications to required systems only.
Deploy host-based intrusion detection and prevention solutions across SharePoint Server infrastructure. Establish tailored logging to detect exploitation including anomalous SharePoint worker-process activity, webshells, and machine-key access. Monitor for suspicious process execution, unexpected outbound connections, and new account creation on SharePoint hosts. Conduct user training on social engineering including phishing. If SharePoint compromise is suspected, isolate affected systems immediately, preserve logs, and initiate incident response. Engage a managed detection and response provider if in-house SOC capacity is insufficient to respond to the volume of this Patch Tuesday.
Microsoft Security Response Center - July 2026 Release Notes: msrc.microsoft.com/update-guide/releaseNote/2026-Jul. CISA Alert - CISA Urges SharePoint Hardening After New Exploitations (14 July 2026). Tenable Blog - Microsoft July 2026 Patch Tuesday Addresses 569 CVEs. BleepingComputer - Microsoft July 2026 Patch Tuesday Fixes Massive 570 Flaws, 3 Zero-Days.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




