Microsoft’s July 2026 Patch Tuesday Fixes Two Actively-Exploited Zero-Days
Microsoft’s July 2026 Patch Tuesday release addressed roughly 570 vulnerabilities across its product line — a sharp jump from June’s count — including two flaws that were already being actively exploited before the patch shipped, according to CrowdStrike’s analysis.
The two zero-days
The two actively-exploited vulnerabilities are CVE-2026-56164, affecting SharePoint Server, and CVE-2026-56155, affecting Active Directory Federation Services (AD FS). Both are the kind of enterprise-infrastructure flaws that, left unpatched, can give an attacker a foothold deep inside an organization’s identity and document-management systems — which is exactly why they were reportedly already being used in the wild.
Scale of this month’s release
The overall vulnerability count this month is described as roughly triple June’s total and nearly five times May’s, though counts like this can swing significantly month to month depending on what’s been queued up for disclosure.
Why it matters
For IT teams, the two actively-exploited CVEs are the ones to prioritize immediately, not the aggregate count. For everyday Windows users, Patch Tuesday updates typically install automatically, but it’s still worth confirming Windows Update has actually applied this month’s release rather than assuming it happened silently.
Source: CrowdStrike Patch Tuesday Analysis.


