Microsoft’s 14 July release fixed 570 flaws by BleepingComputer’s count, excluding 468 Edge and Chromium flaws, 59 of them Critical (Tenable counts 569). The two exploited zero-days were CVE-2026-56155, an elevation of privilege in Active Directory Federation Services, and CVE-2026-56164, an elevation of privilege in SharePoint Server. A BitLocker security feature bypass, CVE-2026-50661, was publicly disclosed.

Critical fixes also covered Microsoft Defender (CVE-2026-55011 and CVE-2026-55012), Copilot (CVE-2026-48561), Office (CVE-2026-55129) and the Windows DHCP client (CVE-2026-54128) — a reminder that security and AI tools are software too, and get patched like everything else.

Both zero-days hit on-premises servers that many small businesses have already retired, and the ones that haven’t are often the least-watched machines in the building. If you still run AD FS or SharePoint Server on site, patch first, then ask why: Entra ID and SharePoint Online remove whole categories of this work.

What it means for your businessIf AD FS or on-premises SharePoint is still in your environment, July’s patches were urgent. Longer term, moving those workloads to Entra ID and SharePoint Online takes them off your patch list.
Source & referenceBleepingComputer — July 2026 Patch Tuesday fixes 570 flaws ↑Tenable — July 2026 Patch Tuesday addresses 569 CVEs ↑