Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack 36%

By Swati Khandelwal11%

7/14/2026, 1:29:25 PM

BS Summary: This article contains 29 faulty reasoning types, including Appeal to Authority, Availability Heuristic, and Negativity Bias, with Biased Writer Voice as the most egregious example at 26% saturation with 330 hits. Analysis detected 2,847 faulty-reasoning hits from 1,267 analyzed words, generating a BS Score of 43% and a BS Rank of 36% (14,099 of 21,887 articles). This article is better (less manipulative) than 64.40% of the article peer group.

Microsoft shipped its largest <strong>Patch Tuesday</strong> on record today, and two of the fixes close holes that attackers are already exploiting. 
The release covers 622 of Microsoft's own CVEs by its <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul" target="_blank">Security Update Guide</a> count, more than triple <a href="https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html" target="_blank">June's previous high of around 200</a>. 
Those two live bugs are the ones to grab first. 
Microsoft credits incident responders for both. 
Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. 
Neither is one of the splashy remote code execution criticals. 
They are privilege bugs in two systems that matter more than their scores suggest: the company document store, and the box that signs its logins. 
<h2>The two zero-days to patch first</h2> 
<p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164" target="_blank">CVE-2026-56164</a>, a SharePoint Server flaw Microsoft says is being exploited in attacks, lets an unauthenticated attacker escalate privileges over the network. 
No credentials, no user interaction, remote. 
Microsoft credited it to Mandiant's incident responders and Google's FLARE team, which points to discovery inside active attacks, though Microsoft has not said how it was exploited or by whom.</p> 
<p>If you run self-hosted SharePoint, this is the one to grab first, and there is a second clock on it: today is also the day SharePoint Server 2016 and 2019 reach the end of extended support. 
Unlike Windows Server or SQL Server, neither has a paid ESU program to fall back on.</p> 
<div class='dog_two clear'><div class='cf'><a href='https://thehackernews.uk/ai-vuln-protection-d' rel='nofollow noopener sponsored' target='_blank'><img class='lazyload' alt="Cybersecurity" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=" data-src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1/s728-e100/zz-d.jpg" width="729" height="91"/></a></div></div> 
<p>Beyond patching, Microsoft's advisory notes that enabling AMSI in Full Mode on the server blunts the attack. 
SharePoint has been an attacker magnet since the <a href="https://thehackernews.com/2025/07/critical-microsoft-sharepoint-flaw.html" target="_blank">ToolShell chain</a> tore through unpatched servers in 2025, and it has not stopped being one.</p> 
<a name="more"></a> 
<p><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155" target="_blank">CVE-2026-56155</a>, an Active Directory Federation Services flaw Microsoft also flags as exploited, lets an already-authenticated attacker elevate privileges locally through weak access controls. 
Microsoft's own DART incident-response unit gets the credit.</p> 
<p>AD FS is the box that signs the tokens for the rest of the estate trusts, which is why a flaw labeled "local" on that host is worth more attention than the label suggests. 
Microsoft has not said what privileges it grants, or how attackers used it.</p> 
<p>Worth knowing for anyone tracking remediation deadlines: neither CVE is on <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank">CISA's Known Exploited Vulnerabilities catalog</a> as of this writing. 
Microsoft's own exploitability rating already marks both as exploited. 
Do not wait for a KEV listing to make it official.</p> 
<p>Microsoft also rates the SharePoint bug fairly low on severity, which is a good reminder that the severity label is not the thing to sort by this month.</p> 
<h2>A third bug, and a SharePoint chain landing in August</h2> 
<p>The third zero-day was publicly disclosed but is not under attack: CVE-2026-50661, another <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661" target="_blank">BitLocker bypass</a>. 
It needs physical access to the device, so it is not a remote emergency. 
Patch it, but it does not jump the queue. 
It continues a run of BitLocker bypasses stretching back through bitskrieg and <a href="https://thehackernews.com/2026/05/microsoft-releases-mitigation-for.html" target="_blank">YellowKey</a> earlier this year.</p> 
<p>SharePoint drew a second notable fix. 
Rapid7 Labs disclosed <a href="https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed/" target="_blank">CVE-2026-55040</a>, a JWT authentication bypass they built for their Pwn2Own Berlin entry. 
The score depends on who you ask: Rapid7 puts it at 5.3 and says Microsoft assigned it medium severity, while ZDI <a href="https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review" target="_blank">reads</a> the release as Critical at 9.1.</p> 
<p>What it does is not in dispute. 
Rapid7 chained it to a separate remote code execution bug to reach unauthenticated RCE against a vulnerable server, and the RCE half is not patched yet; Microsoft is slated to fix it in August.</p> 
<p>That makes July bypass the fix that breaks the chain. 
A four-point spread on one bug also tells you what a severity number is worth this month.</p> 
<h2>The RC4 cleanup that can break logins</h2> 
<p>This update also finishes Microsoft's multi-year Kerberos RC4 hardening. 
The July rollout removes the RC4DefaultDisablementPhase rollback switch, the escape hatch admins have leaned on since Microsoft began the crackdown in January.</p> 
<p>After this, RC4 works only for accounts explicitly configured to allow it. 
If any service account in your environment still requests RC4 Kerberos tickets, it can fail authentication the moment the update lands.</p> 
<p>The order matters: audit first, using the RC4 audit events Microsoft added in January, then rotate the passwords on flagged service accounts, so Windows generates AES keys for them, then patch. 
Rotation only fixes accounts missing AES keys.</p> 
<p>Anything pinned to RC4 by configuration, or a legacy client that speaks nothing else, needs its own fix before the update lands. 
This one does not get you breached; it breaks things, but it will page you at 2am if you skip the audit.</p> 
<h2>Why a quiet month set a record</h2> 
<p>July is historically one of the lightest months on Microsoft's calendar, which makes a release this size stand out. 
Windows alone accounts for 416 of the 622, and ZDI counts 95 remote code execution bugs across the release.</p> 
<p>Here is where the rest sits, and what is worth pulling out of each pile:</p> 
<table> 
<tbody> 
<tr><th>Product family</th><th>CVEs</th><th>Worth pulling out</th></tr> 
<tr><td>Windows</td><td>416</td><td>Both the AD FS zero-day (<code>CVE-2026-56155</code>) and the disclosed BitLocker bypass (<code>CVE-2026-50661</code>) live here. 
Top score of the release is a VMSwitch RCE, <code>CVE-2026-57092</code> at 9.9. 
Also five DHCP RCEs, and 21 NTFS and ReFS driver bugs that ZDI reads as one shared root cause.</td></tr> 
<tr><td>Office</td><td>82</td><td>Counted once. 
Microsoft lists the same 82 again under a separate Office 2016 track, which is why some outlets report 164.</td></tr> 
<tr><td>Microsoft Edge</td><td>46</td><td>ZDI counts 21 as Microsoft's own rather than Chromium re-listings.</td></tr> 
<tr><td>Developer Tools</td><td>27</td><td>Security feature bypasses across Visual Studio, VS Code, and GitHub Copilot, mostly injection and path traversal.</td></tr> 
<tr><td>SharePoint Server</td><td>17</td><td>The exploited zero-day (<code>CVE-2026-56164</code>) and Rapid7's chain bypass (<code>CVE-2026-55040</code>), plus a Critical RCE pair including <code>CVE-2026-50522</code> at 9.8.</td></tr> 
<tr><td>Azure</td><td>11</td><td>Nothing flagged as urgent.</td></tr> 
<tr><td>SQL Server</td><td>8</td><td>An RCE pair, <code>CVE-2026-54117</code> and <code>CVE-2026-54118</code>, both 8.8.</td></tr> 
<tr><td>Defender</td><td>5</td><td>Two Critical RCEs.</td></tr> 
<tr><td>Exchange Server</td><td>5</td><td>A stored XSS in Outlook Web Access, <code>CVE-2026-55008</code>, at 9.6. 
Microsoft files it under spoofing, which undersells it.</td></tr> 
<tr><td>Other</td><td>5</td><td>Nothing flagged as urgent.</td></tr> 
</tbody> 
</table> 
<p>Counts are from Microsoft's Security Update Guide, which totals 622 unique CVEs this month. 
ZDI, counting independently, landed on 621, and its July review is the source for the per-family callouts.</p> 
<div class='dog_two clear'><div class='cf'><a href='https://thehackernews.uk/sygnia-cyber-response-d-2' rel='nofollow noopener sponsored' target='_blank'><img class='lazyload' alt="Cybersecurity" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHcvlLVmAqlffm6kG54_0cGVf8WfcgzqT9B0fBSizSSeIjh8tBepXnrf6BMqKiG344WgqNejcRtEFKT1PmOzQNQBhdmu2iz9Po10z0SSDlFuZ37iip2uYibJDoxTEkbUI7Bx8NJM2Io_z_nl5p4YA-ZhqFLfi0GW1axyu-lQx-iytCn9RGSJ2iqCwdyv8m/s1600/sy-d-2.jpg" width="729" height="91"/></a></div></div> 
<p>Microsoft called this one five days early. 
In a <a href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/" target="_blank">July 9 post</a>, it told customers to expect a "higher volume of security updates included in each security release" as AI helps it uncover more issues. 
That work includes <a href="https://thehackernews.com/2026/05/microsofts-mdash-ai-system-finds-16.html" target="_blank">MDASH</a>, its multi-model agentic scanning system, which found 16 of the bugs in May's Patch Tuesday by itself. 
Microsoft has not said how many of July's 622 came out of that pipeline.</p> 
<p>The same automation cuts both ways. 
Once a patch ships, attackers can diff it against the last build, find the bug it closes, and build a working exploit before most shops have finished testing. 
That eats the old "wait a week" cushion and shrinks the gap to Exploit Wednesday.</p> 
<p>It also guts CVSS-based triage. 
When a release carries 600-plus CVEs and a large share are rated High or Critical, "critical" stops sorting anything. 
This month's two exploited bugs make the point: neither is a headline 9.8, both are mid-tier privilege flaws, and both are already in use.</p> 
<p>Sort by what is being exploited, using KEV, EPSS, and Microsoft's exploited flag, not by score, and patch faster than you used to. 
The number on the box is only going up.</p> 
Article reasoning-pattern comparisonThis article: 5.8%Swati Khandelwal: 2.4%The Hacker News: 1.9%Confirmation Bias5.8%This article: 11.4%Swati Khandelwal: 1.5%The Hacker News: 1.2%Anchoring Bias11.4%This article: 15.9%Swati Khandelwal: 3.5%The Hacker News: 3.3%Availability Heuristic15.9%This article: 9.8%Swati Khandelwal: 1.4%The Hacker News: 1.5%Representativeness Heuristic9.8%This article: 2.8%Swati Khandelwal: 0.7%The Hacker News: 0.6%Hindsight Bias2.8%This article: 0.6%Swati Khandelwal: 2.4%The Hacker News: 2.5%Overconfidence Bias0.6%This article: 11.4%Swati Khandelwal: 2.8%The Hacker News: 2.7%Framing Effect11.4%This article: 7.1%Swati Khandelwal: 0.9%The Hacker News: 1.0%Loss Aversion7.1%This article: 2.0%Swati Khandelwal: 0.7%The Hacker News: 0.6%Status Quo Bias2.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 6.1%Swati Khandelwal: 1.2%The Hacker News: 1.3%Optimism Bias6.1%This article: 5.2%Swati Khandelwal: 1.9%The Hacker News: 1.6%Pessimism Bias5.2%This article: 13.8%Swati Khandelwal: 6.3%The Hacker News: 6.7%Negativity Bias13.8%This article: 0.6%Swati Khandelwal: 0.4%The Hacker News: 0.8%Self-Serving Bias0.6%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 5.8%Swati Khandelwal: 0.4%The Hacker News: 0.6%Halo Effect5.8%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 10.5%Swati Khandelwal: 1.5%The Hacker News: 1.5%Recency Bias10.5%This article: 3.2%Swati Khandelwal: 0.2%The Hacker News: 0.3%Primacy Effect3.2%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 21.0%Swati Khandelwal: 3.9%The Hacker News: 4.0%Appeal to Authority21.0%This article: 7.7%Swati Khandelwal: 1.3%The Hacker News: 1.6%False Dilemma7.7%This article: 2.8%Swati Khandelwal: 0.7%The Hacker News: 0.5%Slippery Slope2.8%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 8.3%Swati Khandelwal: 3.8%The Hacker News: 4.3%Hasty Generalization8.3%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Bandwagon0.0%This article: 5.3%Swati Khandelwal: 0.8%The Hacker News: 1.1%Appeal to Emotion5.3%This article: 0.6%Swati Khandelwal: 0.3%The Hacker News: 0.5%Begging the Question0.6%This article: 9.1%Swati Khandelwal: 2.0%The Hacker News: 1.9%Post Hoc (False Cause)9.1%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 5.5%Swati Khandelwal: 0.7%The Hacker News: 0.6%Burden of Proof5.5%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 11.8%Swati Khandelwal: 2.5%The Hacker News: 2.3%Ambiguity (Equivocation)11.8%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.5%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.5%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 0.0%Swati Khandelwal: 1.0%The Hacker News: 1.4%Unattributed Quote0.0%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 26.0%Swati Khandelwal: 2.7%The Hacker News: 2.3%Biased Writer Voice26.0%This article: 12.2%Swati Khandelwal: 5.0%The Hacker News: 4.4%Indoctrination12.2%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 2.3%Swati Khandelwal: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…2.3%

1267 words analyzed.

Speakers

3speakers25%attributed speech947writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 11 words • 100.0% coverageWriter's voice • 21 words • 100.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 10 words • 100.0% coverageMicrosoft • 6 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 10 words • 100.0% coverageWriter's voice • 25 words • 100.0% coverageWriter's voice • 6 words • 100.0% coverageMicrosoft • 23 words • 0.0% coverageWriter's voice • 6 words • 100.0% coverageMicrosoft • 30 words • 0.0% coverageWriter's voice • 36 words • 100.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 15 words • 100.0% coverageMicrosoft • 17 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 2 words • 0.0% coverageMicrosoft • 25 words • 0.0% coverageMicrosoft • 8 words • 0.0% coverageWriter's voice • 34 words • 100.0% coverageMicrosoft • 13 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageMicrosoft • 9 words • 0.0% coverageWriter's voice • 11 words • 100.0% coverageMicrosoft • 28 words • 100.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 9 words • 100.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageRapid7 Labs • 17 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 7 words • 100.0% coverageRapid7 Labs • 34 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 17 words • 100.0% coverageWriter's voice • 7 words • 100.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 22 words • 100.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 31 words • 100.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 22 words • 100.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageZDI • 19 words • 0.0% coverageWriter's voice • 2 words • 0.0% coverageMicrosoft • 19 words • 0.0% coverageZDI • 11 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 8 words • 100.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageZDI • 17 words • 0.0% coverageWriter's voice • 14 words • 100.0% coverageWriter's voice • 7 words • 0.0% coverageMicrosoft • 30 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageMicrosoft • 14 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 5 words • 100.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 23 words • 100.0% coverageWriter's voice • 9 words • 100.0% coverage
Selected voice

Microsoft

88%flagged-word coverage
222 attributed words69% of attributed speech92% writer coverage
0%17.5%35.0%Biased Writer Voice-34.8 ptsWriter: 34.8%Microsoft: 0.0%0.0%Indoctrination-0.7 ptsWriter: 13.3%Microsoft: 12.6%12.6%Attempt to Sell a Product -3.1 ptsWriter: 3.1%Microsoft: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.