Microsoft’s July 2026 Patch Tuesday broke every record the company has ever set: 570 security vulnerabilities patched in a single release, including three zero-days already being exploited by attackers in the wild.
For context: July 2025 had 137 patches. June 2026 had 200. This month had 570.
That 316% year-over-year increase is not because Windows became dramatically less secure. It is because Microsoft deployed AI to find the bugs before attackers could.
What Changed
The company has been expanding its MDASH system — the Multi-Model Agentic Scanning Harness that we covered back in May when it found 16 vulnerabilities autonomously. By July, MDASH runs in production across the full Windows codebase, hunting for exploitable flaws around the clock.
The result is a surge in discovered-and-patched vulnerabilities. Microsoft warned in advance that update volumes would increase as the AI system identifies more issues. What they did not telegraph was the scale: 570 patches in a single Patch Tuesday is staggering by any historical measure.
The breakdown: 254 elevation-of-privilege vulnerabilities, 145 remote code execution flaws, 102 information disclosure issues, 35 denial-of-service bugs, 17 security feature bypass vulnerabilities, and 16 spoofing flaws. Of the 570 total, 59 are rated Critical.
The Three Zero-Days That Matter Now
Three vulnerabilities stand out because attackers were actively exploiting them before Microsoft could patch:
CVE-2026-56155 — An elevation-of-privilege flaw in Active Directory Federation Services caused by insufficient access-control granularity. Any organization running ADFS on-premises needs to treat this as urgent.
CVE-2026-56164 — A Microsoft SharePoint Server flaw where missing authentication for a critical function allows an unauthorized network attacker to escalate privileges. SharePoint is in production at hundreds of thousands of organizations worldwide.
CVE-2026-50661 — A BitLocker Security Feature Bypass that allows an attacker with physical device access to read encrypted data. Relevant for any organization with mobile workers or unattended devices.
These are not theoretical risks. All three were being actively exploited before the patch shipped. The window between disclosure and exploitation is effectively zero.
What This Means for Business Leaders
Most organizations treat Patch Tuesday as a routine IT maintenance task. After this release, that framing needs to change.
The patching burden is permanently higher. Microsoft has updated its guidance to deploy quality updates within three days, not the 30-day window most enterprise IT teams use. If AI is consistently finding 400 to 500 vulnerabilities per month, that pace is not going to slow. It is likely to accelerate as the AI systems improve.
Attackers have AI too. The reason Microsoft is racing to find these flaws is that threat actors are deploying similar systems to discover and exploit them. The gap between “vulnerability exists” and “vulnerability is actively exploited” is shrinking. Three of this month’s 570 patches were already too late — attackers found and weaponized them before the fix arrived.
AI-found vulnerabilities run deeper. When a human researcher finds a bug through manual code review, the finding is typically narrow. MDASH and similar systems scan entire codebases systematically and surface the kind of subtle, long-standing flaws that manual review misses. The critical remote code execution vulnerabilities found in May had existed in Windows for years.
The New Security Baseline
Here is what this signals for any organization running Microsoft infrastructure.
The historical assumption — patch quarterly, test, deploy, move on — is no longer adequate. The old model assumed a relatively stable flow of patches from human security researchers. That assumption does not hold anymore.
Microsoft is not unique. Every major software vendor is deploying or will deploy AI to find vulnerabilities in their own codebase. This is broadly positive — catching flaws before attackers is better than after — but it means enterprise IT teams need to adapt both their patching cadence and their risk models.
The same AI capabilities that help businesses automate workflows are being applied to infrastructure security at scale. That is an argument for building AI literacy inside your team rather than treating AI as a black box managed entirely by vendors.
What to Do This Week
-
Prioritize the three zero-days: CVE-2026-56155, CVE-2026-56164, and CVE-2026-50661. These should be on production systems within 24 hours if they have not been patched already.
-
Review your patching cadence. A 30-day cycle made sense when patches numbered in the dozens. A 570-patch release requires a different posture.
-
Audit which systems are running ADFS and SharePoint Server on-premises. These are the highest-risk targets in this release.
-
Set expectations internally. Monthly patch volumes will remain elevated — this is the new operational reality, not an anomaly.
The AI finding 570 vulnerabilities before attackers did is genuinely good news. The question is whether your organization moves fast enough to benefit from that head start.
Enterprise DNA helps businesses build AI-literate teams and deploy AI strategies that work in practice, not just in demos. Talk to us about getting your team ready.
Source
Bleeping Computer
Free Resource
Going deeper with Claude?
Get the free 32-page implementation guide for ANZ teams.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the Guide