Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

622 CVEs and three zero-days: what should patch teams prioritise?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12324
Topic starter  

TL;DR: Microsoft’s July 2026 Patch Tuesday includes 622 CVEs, 56 Critical issues, and three zero-days, with two already exploited in the wild, while Microsoft says AI-assisted vulnerability discovery helped drive the surge. The message for practitioners is clear: exploitability, exposure, and business-critical identity surfaces matter more than raw patch volume.

NHIMG editorial — based on content published by Senserva: Microsoft’s July 2026 Patch Tuesday and how to prioritise it

By the numbers:

  • Microsoft’s July 2026 release note lists 622 Microsoft CVEs, including 56 rated Critical and three zero-day vulnerabilities.
  • Microsoft’s July 2026 release note lists 622 Microsoft CVEs, including 56 rated Critical and three zero-day vulnerabilities.
  • Microsoft’s July 2026 release note lists 622 Microsoft CVEs, including 56 rated Critical and three zero-day vulnerabilities.

Questions worth separating out

Q: What breaks when identity platforms stay unpatched after disclosure?

A: What breaks is the assumption that identity control planes remain trustworthy until the next maintenance window.

Q: Why should patch teams treat AD FS and SharePoint as high-priority systems?

A: AD FS and SharePoint sit close to authentication and collaboration workflows, so compromise can affect how users and services are trusted across the environment.

Q: How can security teams tell whether a patch programme is actually working?

A: A patch programme is working when installation success is confirmed across the full estate, exploited vulnerabilities are cleared first, and exceptions are measured rather than hidden.

Practitioner guidance

  • Prioritise exploited zero-days first Patch CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server before working through the rest of the release, because both are already being exploited in the wild and sit on identity-adjacent surfaces.
  • Test Kerberos RC4 changes in controlled rings Validate CVE-2026-20833 in a staged environment that mirrors legacy authentication dependencies, then map any application or directory path that still relies on RC4 before broad rollout.
  • Rank the backlog by exploit evidence and exposure Use CISA KEV first, then EPSS, then severity and internet-facing exposure to build the remediation queue instead of working down a list of hundreds of CVEs in release order.

What's in the full analysis

Senserva's full analysis covers the operational detail this post intentionally leaves for the source:

  • Per-CVE breakdown of the July 2026 Microsoft release, including the identity and collaboration fixes most likely to drive urgent remediation.
  • Tracker methodology for ranking Microsoft patches by KEV, EPSS, severity, and exposure instead of release order.
  • Updated handling notes for the Kerberos RC4 change and the emergency RoguePlanet fix.
  • Live patch triage views that help teams separate exploited items from lower-priority backlog entries.

👉 Read Senserva's analysis of July 2026 Patch Tuesday prioritisation →

622 CVEs and three zero-days: what should patch teams prioritise?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 11878
 

Risk-based patch triage has become an identity governance issue, not just a vulnerability-management task. When the most urgent fixes sit on AD FS and SharePoint, the patch queue directly affects trust in authentication and collaboration pathways. IAM teams cannot stay at the access-policy layer while platform teams make emergency decisions about identity infrastructure. The governance question is whether the organisation can still prioritise by exploitation, exposure, and business impact. Practitioners should treat patch ordering as part of identity risk management.

A few things that frame the scale:

A question worth separating out:

Q: Which frameworks help teams govern large patch cycles more effectively?

A: NIST Cybersecurity Framework 2.0 helps teams organise govern, identify, protect, detect, respond, and recover activities, while NIST SP 800-53 Rev 5 supports control mapping for access control, authentication, and monitoring. For patch triage, the useful question is whether exploitation evidence is being translated into governance decisions fast enough.

👉 Read our full editorial: July 2026 Patch Tuesday shows why risk-based triage beats CVE counts



   
ReplyQuote
Share: