Microsoft Patch Tuesday - July 2026
Release Date: July 14, 2026
Patch Summary
- Total Patches: 1,150
- Critical: 66
- Important: 594
- Moderate: 55
- Low: 435
Zero-Day Vulnerabilities
| CVE | Title | CVSS | Severity | Exploited | Disclosed |
|---|---|---|---|---|---|
| CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege | 7.8 | Important | Yes | No |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege | 5.3 | Moderate | Yes | No |
| CVE-2026-50661 | Windows BitLocker Security Feature Bypass | 6.1 | Important | No | Yes |
Notable Fixes
- Active Directory Federation Services (ADFS): Critical elevation of privilege vulnerability under active exploitation
- SharePoint Server: Moderate-severity privilege escalation affecting on-premises deployments
- Windows BitLocker: Security feature bypass with public disclosure
Priority Guidance for MSPs
- Immediate (24-48 hours): Deploy patches for CVE-2026-56155 (ADFS) and CVE-2026-56164 (SharePoint) due to active exploitation
- High Priority (Week 1): Address all 66 Critical patches and BitLocker bypass (CVE-2026-50661)
- Standard Cycle: Schedule Important and Moderate patches within standard maintenance windows
- Monitor: Track exploit activity for remaining Critical vulnerabilities given the 3% zero-day rate