Microsoft’s July 2026 Patch Tuesday Fixes a Record 570 Vulnerabilities — Here’s What Toronto Businesses Need to Know

August 11, 2026by MSPH Admin0

Microsoft’s July 2026 Patch Tuesday is the largest security release in the program’s history — 570 vulnerabilities fixed, including three zero-days, two of which were already being exploited by attackers before a fix existed. If your business runs Windows, Microsoft 365, or SharePoint, this is a month to prioritize updates.

The numbers at a glance:

  • 570 total vulnerabilities patched
  • 59 rated Critical
  • 3 zero-day vulnerabilities, 2 actively exploited in the wild

Microsoft has pointed to a new AI-powered vulnerability scanning system as a driver of this month’s unusually high count — a trend that may continue in future releases.

The three zero-days you should know about:

  • AD FS Elevation of Privilege (CVE-2026-56155) — Actively exploited. Lets an attacker escalate to administrator-level access through Active Directory Federation Services, which many businesses use for single sign-on.
  • SharePoint Server Elevation of Privilege (CVE-2026-56164) — Actively exploited. Allows an unauthenticated attacker to escalate privileges on SharePoint Server, potentially exposing sensitive business documents.
  • Windows BitLocker Bypass (CVE-2026-50661) — Publicly disclosed. An attacker with physical access to a device could bypass BitLocker encryption and read the drive’s contents — a real risk for lost or stolen laptops.

Both actively exploited flaws have been added to CISA’s Known Exploited Vulnerabilities catalog, underscoring how seriously they’re being treated.

What this means for your business:

If you run AD FS or SharePoint Server, these updates should be a priority this week, not something deferred to a routine maintenance window. If your team uses laptops that leave the office, this is also a good moment to confirm BitLocker is enabled and enforced across your devices.

How MSP Helpers can help

We track every Patch Tuesday release and manage deployment for our clients so nothing falls through the cracks. If you’re not sure whether your business is fully patched, contact us for a free IT assessment — we’ll review your environment and flag anything that needs immediate attention.

MSP Helpers provides managed IT and cybersecurity services for small and mid-sized businesses across Toronto and the GTA.

Leave a Reply

Your email address will not be published. Required fields are marked *