July Patch Tuesday: A Record 570 Fixes. Due to advances in AI SMBs and their MSPs Need To Patch Faster and Patch Smarter.
- 6 days ago
- 5 min read
Updated: 3 days ago

Microsoft’s July Patch Tuesday is the largest release on record: 570 vulnerabilities, including 59 rated Critical. Two of the three zero-days fixed this month were already being exploited in attacks.
We are not suggesting you to try to patch 570 things on every system before lunch but we think businesses and their MSPs need to recognise the world is changing. The job is to identify which of those fixes affect the organisation, which systems are exposed, and which issues attackers can already exploit. Then act at the speed the risk requires.
A note on the number: 570 is the count for vulnerabilities Microsoft released on 14 July. Some wider reporting gives a 622-CVE total by using the Microsoft Security Update Guide’s broader scope. The important point is unchanged: this is a record-sized release, and raw volume makes prioritisation essential.
Issues that move to the front of the queue
The first priority is not necessarily the vulnerability with the highest CVSS score. It is the one where exposure and attacker activity meet.
Priority | Issue | Why it matters | What to do now |
Urgent | CVE-2026-56164 — Microsoft SharePoint Server elevation of privilege | Microsoft reports active exploitation. An unauthenticated attacker can elevate privileges over the network. This affects self-hosted SharePoint Server, not SharePoint Online. | Establish whether any vulnerable on-premise SharePoint exists, is it exposed to the internet? If so patch it immediately, enable AMSI and set Request Body Scan to Full, also review logs and recent permission changes. |
High | CVE-2026-56155 — Active Directory Federation Services (AD FS) elevation of privilege | Microsoft reports active exploitation. It requires a local foothold, but AD FS is identity infrastructure: administrator access there can turn a limited compromise into a much larger one. | Patch AD FS immediately, restrict local access, investigate unexpected administrator activity and unusual token issuance. |
High | CVE-2026-56190 — Remote Desktop Protocol remote code execution | CVSS 9.8. It is exploitable when Network Level Authentication (NLA) is disabled. Publicly exposed RDP makes an already serious issue more attractive. | Always remove RDP from the internet, enforce NLA and patch affected systems. |
High | CVE-2026-50522 — SharePoint Server remote code execution | CVSS 9.8. It requires site-owner access, but it sits in the same product family as an actively exploited unauthenticated privilege flaw. | Patch self-hosted SharePoint urgently and review who has site-owner privileges. |
High | CVE-2026-57092 — Windows VMSwitch elevation of privilege | CVSS 9.9. A compromised virtual machine may be able to reach the Hyper-V host. | Prioritise Hyper-V hosts, particularly where several workloads share a host. |
There is a practical lesson here for smaller organisations: a score is useful, but it is not a patching plan. The actively exploited SharePoint issue has a lower score than several other items in the release. It still belongs first because attackers are already using it.
Why the numbers are rising — and why the exploit window matters
Microsoft has said that AI is changing the scale and speed of vulnerability discovery. That is generally good news, defects can be found and fixed before criminals exploit them.
More effective AI-assisted discovery means more valid findings arriving in a shorter period.
The dark side of AI also means that, once a patch is released, defenders are not the only people who can rapidly analyse what changed. Threat actors are able to use AI to sift advisories, identify likely affected products, compare patched code and adapt scanning or exploit attempts more quickly.
AI is not magic, and it does not turn every vulnerability into a working attack. But it reduces the time, specialist effort and cost needed to do repetitive work at scale. The result is a shorter interval between fix available and unpatched systems becoming interesting targets.
For SMBs, that means the relevant measure is no longer only “did we patch this month?” It is “how long did the systems that matter most remain exposed after a fix became available?” Weeks may be acceptable for a low-risk internal application. They are a poor fit for a confirmed exploited weakness in an internet-facing server or identity system.
What SMBs and MSPs should check this week
Start with an inventory rather than a CVE spreadsheet.
Confirm whether you run the affected products. Ask specifically about self-hosted SharePoint Server, AD FS, Hyper-V hosts and systems with RDP enabled. Do not assume that a cloud migration means no legacy server remains.
Find what is internet-facing. A VPN, remote-access gateway, RDP service or web server deserves faster scrutiny because it is reachable by attackers before they have an account in your environment.
Patch the exploited vulnerabilities first. If SharePoint Server or AD FS is present, treat the task as urgent and include a short post-patch check for signs of prior compromise.
Apply configuration protections as well as patches. For RDP, NLA and removing public exposure are immediate risk reducers; a patch alone is not the whole answer.
Check identity and recovery. Use MFA, separate administrator accounts, keep privileged access tightly controlled, and test that backups can be restored. These controls limit the impact if an initial foothold is gained.
Record exceptions with an owner and date. If a patch needs a maintenance window, document the compensating control, the person responsible and the committed completion date. “We will get to it” is not a control.
The MSP angle: turn a giant release into a managed workflow
For an MSP, a record Patch Tuesday is not just a technical workload, it is a coordination problem across many customers, technology stacks and change windows.
The most useful response is a repeatable, evidence-led workflow:
Use RMM, asset-management and vulnerability data to identify customers with self-hosted SharePoint, AD FS, Hyper-V and RDP exposure.
Triage by active exploitation, internet exposure and business consequence, rather than applying the same urgency to every critical CVE.
Contact affected customers in plain language: what is installed, why it matters, the action needed, the timing and any service impact.
Apply emergency mitigations where a patch cannot safely be installed immediately, then track the permanent fix to closure.
Run a post-remediation check. For actively exploited flaws, “patch deployed” should not be the final status; review relevant logs and configuration changes for evidence of earlier access.
Keep an auditable record of detection, notification, approval, patch outcome and exceptions. It makes the process safer and gives the customer confidence that the risk was actively managed.
This is also where 24 x 7 critical-vulnerability alerting has value. A credible, actively exploited vulnerability affecting an exposed customer system should reach the MSP and the customer contact promptly — not wait for the next business day or a monthly report.
A record release is a signal, not a reason to panic
July’s volume is a useful warning about the direction of travel. Vulnerability discovery is accelerating, and the time attackers need to turn public information into action is shrinking.
For SMBs, the answer is not an impossible ask to patch everything immediately. It is a mature priority process: know what you run, reduce unnecessary exposure, put exploited and internet-facing issues first, and ensure your MSP can act when a routine patch becomes an urgent security event.
The organisations best placed for the AI-enabled pace of vulnerability discovery will be those with a clear owner, an accurate inventory and a patching process measured in hours or days for the risks that genuinely cannot wait.



Comments