Cyber - 6 min read - 19 July 2026

Microsoft's biggest Patch Tuesday on record includes a flaw already being used against your SSO

570 fixes landed on 14 July, more than any single Patch Tuesday in Microsoft's history. One of the three zero-days in that batch sits in Active Directory Federation Services, the system a large share of enterprise single sign-on quietly depends on.

Microsoft's July 2026 update Tuesday, released on 14 July, patched 570 vulnerabilities, 59 of them rated Critical, making it the largest single Patch Tuesday Microsoft has shipped, according to Bleeping Computer. Counting fixes for third-party components bundled into Windows, The Hacker News puts the total closer to 622. Three of the flaws were zero-days: two already being exploited in the wild, one publicly disclosed before a patch existed. For any organisation still running a monthly or even fortnightly patch cycle, the volume alone is a scheduling problem. The zero-days are the reason it can't wait for the next cycle.

The one that should move to the top of the list

CVE-2026-56155 affects Active Directory Federation Services, the component that underpins federated single sign-on for a large proportion of enterprises running hybrid identity between on-premises AD and cloud services. Microsoft's own advisory describes it plainly: insufficient granularity of access control in AD FS allows an authorised attacker to elevate privileges locally. In practice, that means an attacker who has already obtained low-privilege access to a federation server, through phishing, a stolen credential, or a foothold elsewhere on the network, can escalate to administrative control of the system that issues SSO tokens for everything behind it. Per Tenable's analysis, the flaw was identified by Microsoft's own Detection and Response Team, which typically means it surfaced during a real incident investigation rather than a routine audit. Microsoft has not published exploitation details, but a vulnerability found by an incident response team, in a system that mints authentication tokens, is not one to file under "patch when convenient."

The same release includes CVE-2026-56164, a separate elevation-of-privilege flaw in SharePoint Server that is also being actively exploited, a reminder that SharePoint's run of exploited flaws this year, including the unrelated CVE-2026-45659 we covered last week, isn't a one-off. CVE-2026-50661, a BitLocker bypass that can expose data on encrypted drives, and a cluster of critical remote code execution issues in Windows Media Foundation and DirectX Graphics Kernel round out the highest-priority items in a batch large enough that most vulnerability management teams will need to triage hard rather than patch everything on day one.

Why the count itself is worth paying attention to

A jump to 570 fixes in a single month, against a rolling average that has typically sat well below that, is not simply Microsoft finding more time to look for bugs. Coverage of the release notes that Microsoft has been expanding AI-assisted vulnerability discovery across the Windows codebase, which is finding a genuinely larger backlog of latent flaws than manual review historically surfaced. That's a good outcome for security in the medium term. In the short term, it means the volume of critical patches enterprises are asked to absorb in any given month is likely to keep growing faster than most patch management processes were designed around, and prioritisation discipline matters more than it did when a typical Patch Tuesday ran to a few dozen items.

What this means for identity and patch governance

AD FS sits in the same category of infrastructure as the domain controllers and privileged access systems we've written about here: unglamorous, rarely front of mind, and catastrophic to lose control of. An attacker with administrative access to a federation server can forge tokens that let them impersonate any user to any service trusting that federation, which is a materially worse outcome than compromising a single application. Enterprises that federate identity with partners, a pattern we discuss separately, should treat this patch as urgent regardless of where AD FS sits in their normal change calendar.

The broader lesson is that patch prioritisation now has to run on more than CVSS score. A vulnerability found during an incident response engagement, in a system that issues authentication tokens, deserves emergency-change treatment even when it's one line in a list of 570.

  • Patch CVE-2026-56155 on every AD FS server this week, treating it as an emergency change rather than waiting for the next scheduled maintenance window.
  • Check whether any of your SSO or federation servers show signs of anomalous local privilege escalation in the weeks before the patch, not just after.
  • Prioritise this month's other actively exploited flaw, the SharePoint elevation-of-privilege issue CVE-2026-56164, alongside AD FS rather than treating SharePoint patching as already handled by last week's fix.
  • Review whether your patch management tooling can distinguish "exploited in the wild" and "found via incident response" from routine Critical-rated CVEs, since both are stronger signals than severity score alone.
  • Revisit your patch SLA assumptions given the trend toward larger monthly patch volumes; a process built around 30-40 fixes a month will not scale cleanly to 500-plus.

A record patch count is a headline. A privilege-escalation flaw in your federation layer, found during someone else's incident response, is the part that belongs on this week's change board. If you'd like help reviewing how your identity infrastructure and patch governance would hold up under this kind of month, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources