By NHI Mgmt Group Editorial TeamDomain: Breaches & IncidentsSource: SenservaPublished July 14, 2026

TL;DR: Microsoft’s July 2026 Patch Tuesday includes 622 CVEs, 56 Critical issues, and three zero-days, with two already exploited in the wild, while Microsoft says AI-assisted vulnerability discovery helped drive the surge. The message for practitioners is clear: exploitability, exposure, and business-critical identity surfaces matter more than raw patch volume.


At a glance

What this is: Microsoft’s July 2026 Patch Tuesday is the largest on record, with 622 CVEs, 56 Critical issues, and two zero-days already being exploited in the wild.

Why it matters: It matters because identity and collaboration surfaces are in the highest-risk set, so IAM and security teams need risk-based prioritisation rather than volume-based patching.

By the numbers:

  • Microsoft’s July 2026 release note lists 622 Microsoft CVEs, including 56 rated Critical and three zero-day vulnerabilities.
  • Microsoft’s July 2026 release note lists 622 Microsoft CVEs, including 56 rated Critical and three zero-day vulnerabilities.
  • Microsoft’s July 2026 release note lists 622 Microsoft CVEs, including 56 rated Critical and three zero-day vulnerabilities.

👉 Read Senserva's analysis of July 2026 Patch Tuesday prioritisation


Context

Microsoft’s July 2026 Patch Tuesday is a patch governance problem as much as a vulnerability event. When a single release contains hundreds of fixes, teams cannot treat every item as equal, especially when the most urgent items sit on identity and collaboration surfaces that can materially change access paths across the estate.

For IAM and PAM teams, this is also an access-control event. Active Directory Federation Services and SharePoint Server sit close to authentication, federation, and collaboration workflows, so exploitation in those layers can quickly become an identity breach problem, not just a patching problem.


Key questions

Q: What breaks when identity platforms stay unpatched after disclosure?

A: What breaks is the assumption that identity control planes remain trustworthy until the next maintenance window. If an identity provider, vault, or directory service stays exposed after disclosure, attackers may use it to harvest credentials or pivot across environments. At that point, patching delay has become a governance failure, not a technical inconvenience.

Q: Why should patch teams treat AD FS and SharePoint as high-priority systems?

A: AD FS and SharePoint sit close to authentication and collaboration workflows, so compromise can affect how users and services are trusted across the environment. That makes them more than ordinary application servers. If they are exploited, the blast radius can include identity trust, access continuity, and downstream service dependencies.

Q: How can security teams tell whether a patch programme is actually working?

A: A patch programme is working when installation success is confirmed across the full estate, exploited vulnerabilities are cleared first, and exceptions are measured rather than hidden. Strong programmes report by deployment state, not ticket completion, and they can explain which high-risk services remain exposed after each cycle.

Q: Which frameworks help teams govern large patch cycles more effectively?

A: NIST Cybersecurity Framework 2.0 helps teams organise govern, identify, protect, detect, respond, and recover activities, while NIST SP 800-53 Rev 5 supports control mapping for access control, authentication, and monitoring. For patch triage, the useful question is whether exploitation evidence is being translated into governance decisions fast enough.


Technical breakdown

Why exploited zero-days outrank high-volume patch lists

A patch release becomes operationally meaningful when exploitability is known. A zero-day already being used in the wild carries a different risk profile from a large set of unexploited CVEs because the attacker has removed the uncertainty that normally buys defenders time. In practice, release-note volume is a poor proxy for exposure. Teams need to separate confirmed exploitation, public disclosure, and theoretical severity. That distinction is especially important when internet-facing systems or identity services are involved, because compromise there can unlock lateral movement quickly.

Practical implication: patch known-exploited vulnerabilities first, starting with the systems that sit on authentication, federation, and collaboration paths.

Kerberos RC4 change and the problem of hidden legacy dependency

Kerberos RC4 breaking changes expose a common identity infrastructure weakness: many environments still carry protocol dependencies that no one wants to find during a broad rollout. RC4 support often persists because it is buried in legacy integrations, service dependencies, or older directory configurations. Once a vendor removes a safety valve, the hidden dependency becomes an outage risk as well as a security issue. This is a classic lifecycle problem in IAM programmes: the control looks stable until a protocol change reveals how much technical debt has been allowed to accumulate.

Practical implication: inventory Kerberos dependencies before rollout, and test the change in rings where legacy authentication paths can fail safely.

Why patch ranking should start with KEV, then EPSS, then exposure

Risk-based triage works because it combines three different signals. CISA KEV shows confirmed exploitation. EPSS estimates the likelihood that a vulnerability will be used next. Exposure and severity tell you where a successful exploit would matter most. None of these signals alone is enough, but together they produce a much better queue than CVSS scoring alone. That matters during large release cycles, because the administrative burden of hundreds of CVEs can otherwise overwhelm patch teams and delay action on the few items that actually change attacker options.

Practical implication: build patch queues around exploit evidence, probability, and exposure rather than reading fixes in numerical order.


Threat narrative

Attacker objective: The attacker’s objective is to turn a patchable edge vulnerability into durable access across trusted enterprise identity and collaboration workflows.

  1. Entry begins with exploitation of internet-facing identity and collaboration surfaces such as Active Directory Federation Services and SharePoint Server.
  2. Escalation follows when those surfaces are used to gain control over authentication or trusted access paths, widening the attacker’s reach beyond the initial foothold.
  3. Impact is achieved through privileged access expansion, service disruption, or downstream movement into systems that rely on the compromised identity layer.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Risk-based patch triage has become an identity governance issue, not just a vulnerability-management task. When the most urgent fixes sit on AD FS and SharePoint, the patch queue directly affects trust in authentication and collaboration pathways. IAM teams cannot stay at the access-policy layer while platform teams make emergency decisions about identity infrastructure. The governance question is whether the organisation can still prioritise by exploitation, exposure, and business impact. Practitioners should treat patch ordering as part of identity risk management.

Legacy protocol dependency debt: is the hidden failure mode this release exposes. Kerberos RC4 shows how old authentication choices continue to shape today’s operational risk. A breaking change with no rollback means the environment has been carrying an undocumented dependency that now has to be surfaced and retired. This is not just a protocol story; it is a lifecycle control failure where deprecation planning lagged behind actual use. Practitioners should map legacy authentication paths before they become incident drivers.

Identity surfaces are where patch urgency becomes attacker leverage. AD FS, SharePoint, and Kerberos are not generic endpoints. They mediate trust, token issuance, and access continuity, which means a successful exploit can move faster and farther than a typical host compromise. That is why identity security teams need to sit inside patch prioritisation decisions, not receive the output after the queue is built. Practitioners should elevate identity-adjacent systems into the first tier of remediation.

Volume is now a poor security signal when AI-assisted discovery accelerates disclosure. If vulnerability discovery is being accelerated by automation, teams will see larger monthly release sets without a corresponding increase in human review capacity. That shifts the discipline from enumeration to selection. Security leaders should expect more release noise, fewer easy triage assumptions, and a greater premium on operational ranking models that are tied to real exploitation signals.

Patch governance must now distinguish between business-critical exposure and compliance-driven completeness. Completing every patch is not the same as reducing risk in time. In large release cycles, the first objective is to remove the attacker’s most viable paths, then work through the rest by exposure and dependency. Practitioners should build governance that measures time-to-remediate for exploitable identity surfaces, not only percentage patched.

From our research:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • From our research: 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • For related analysis: The 52 NHI breaches Report shows how identity and credential failures become real incidents, which is the right next read once patch triage is under control.

What this signals

Legacy identity systems will keep surfacing as patch bottlenecks until organisations treat dependency mapping as part of security operations. The immediate lesson from a release like this is that patching is no longer just a maintenance function. It is a control plane for trust, and the teams that own identity, infrastructure, and vulnerability management need a shared view of which services cannot tolerate delay. The NHI and IAM angle is especially clear where federation and directory services are exposed to the internet.

Patch governance is shifting toward exposure-led queues, not calendar-led cycles. That means practitioners should expect more pressure to justify why some fixes are deferred while others are accelerated, especially when identity surfaces are involved. The practical response is to build queues around exploit evidence, business criticality, and dependency depth, then keep that ranking visible to operational owners.

Legacy authentication debt is a measurable risk factor, not an abstract architecture issue. The more an organisation depends on older protocol behaviour, the more a vendor change can become a service disruption or an access event. Teams should document those dependencies now, because the next breaking update may not include a rollback path and the risk will land in production first.


For practitioners

  • Prioritise exploited zero-days first Patch CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server before working through the rest of the release, because both are already being exploited in the wild and sit on identity-adjacent surfaces.
  • Test Kerberos RC4 changes in controlled rings Validate CVE-2026-20833 in a staged environment that mirrors legacy authentication dependencies, then map any application or directory path that still relies on RC4 before broad rollout.
  • Rank the backlog by exploit evidence and exposure Use CISA KEV first, then EPSS, then severity and internet-facing exposure to build the remediation queue instead of working down a list of hundreds of CVEs in release order.
  • Review identity-adjacent internet-facing systems Treat federation, collaboration, and directory-connected services as top-tier patch targets because compromise there can translate into token abuse, access expansion, or delegated trust abuse.

Key takeaways

  • The July 2026 Patch Tuesday shows that raw CVE counts are no longer a useful ordering signal when active exploitation is already underway.
  • Identity-adjacent services such as AD FS and SharePoint turn patch urgency into access-risk management because compromise there can affect trust, not just endpoints.
  • Teams that rank by exploitation evidence, exposure, and legacy dependency are more likely to reduce attacker advantage before a large release becomes an operational backlog.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral MovementThe article centres on exploited identity and collaboration surfaces that can enable credential access and movement.
NIST CSF 2.0PR.IP-12Patch management and vulnerability remediation are central to the article’s triage guidance.
NIST SP 800-53 Rev 5SI-2Security flaw remediation directly fits the article’s patch-first guidance.
CIS Controls v8CIS-7 , Continuous Vulnerability ManagementThe article is fundamentally about ranking and remediating vulnerabilities at scale.
NIST AI RMFMANAGEThe article references AI-assisted vulnerability discovery and the governance response to faster discovery cycles.

Map the exploited Microsoft surfaces to credential-access and lateral-movement tactics when building remediation priority.


Key terms

  • Known Exploited Vulnerability: A Known Exploited Vulnerability is a flaw that has confirmed active exploitation in the wild and is tracked for urgent remediation. In governance terms, KEV status turns patching from a general hygiene task into a time-bound operational obligation.
  • Identity-adjacent system: A system that directly supports authentication, federation, authorisation, or collaboration workflows. These systems are especially sensitive because compromise can affect trust relationships, token handling, and access continuity across multiple services, not only the host on which the flaw appears.
  • Patch triage: The process of deciding which vulnerabilities to fix first, based on exploitation evidence, exposure, criticality, and operational dependency. Good triage does not try to treat every issue as equal; it aims to remove the attacker’s most realistic options with the least delay.
  • Legacy authentication: Older login or protocol methods that remain in place for compatibility even after stronger controls exist. They often preserve weaker trust assumptions, which makes them attractive to attackers and difficult to defend if they are not tightly scoped and eventually retired.

What's in the full analysis

Senserva's full analysis covers the operational detail this post intentionally leaves for the source:

  • Per-CVE breakdown of the July 2026 Microsoft release, including the identity and collaboration fixes most likely to drive urgent remediation.
  • Tracker methodology for ranking Microsoft patches by KEV, EPSS, severity, and exposure instead of release order.
  • Updated handling notes for the Kerberos RC4 change and the emergency RoguePlanet fix.
  • Live patch triage views that help teams separate exploited items from lower-priority backlog entries.

👉 Senserva's full post covers the exploited zero-days, Kerberos RC4 change, and risk-ranking logic in more detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It gives practitioners a practical way to connect access control, lifecycle management, and risk decisions across identity programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org