Microsoft’s July 2026 Patch Tuesday addressed 570 vulnerabilities, including three zero-day vulnerabilities and 59 critical vulnerabilities, increasing pressure on organisations to assess and remediate risk quickly.
Two of the three zero-day vulnerabilities have been exploited in the wild, including privilege escalation flaws affecting Active Directory Federation Services and Microsoft SharePoint Server. The third zero-day is a publicly disclosed BitLocker security feature bypass.
With Microsoft releasing increasingly large security updates, organisations need a risk-based approach to remediation that considers severity, confirmed exploitation, internet exposure, asset criticality and potential impact of compromise.