Back to news

Microsoft Issues Record 622-Flaw Patch Tuesday With Two Active Zero-Days

Microsoft's July 2026 Patch Tuesday is the largest in company history, closing more than 600 vulnerabilities including two flaws already being exploited in the wild.

Microsoft Issues Record 622-Flaw Patch Tuesday With Two Active Zero-Days

What happened

Microsoft released its most expansive security update in company history this month, addressing between 570 and 622 vulnerabilities across Windows and related software products — figures that vary slightly by counting methodology but dwarf the previous record set just last month. That prior release was itself considered extraordinary at roughly 200 CVEs. Two of the newly patched flaws are confirmed zero-days: active exploits were already underway before the fixes shipped, and both were identified with the help of incident response teams. Microsoft has attributed the rapid escalation in discovered vulnerabilities partly to artificial intelligence-assisted security research accelerating the identification of previously unknown flaws.

Why it matters for your business

The sheer volume of patches creates a triage burden that most IT and security teams are not staffed to handle quickly — and attackers know it. The two actively exploited zero-days should be treated as emergency patches and deployed before the broader rollout is complete. Organizations running unpatched Windows environments, particularly those with internet-facing services or remote workforces, face the greatest immediate risk. The practical takeaway is straightforward: prioritize the zero-days now, establish a phased rollout plan for the remaining fixes within your standard patch cycle, and verify that automated update mechanisms are functioning correctly across all endpoints.

What to watch next

The involvement of AI in surfacing this volume of vulnerabilities suggests patch volumes of this magnitude may become routine rather than exceptional, forcing security teams to rethink how they assess and deploy updates at scale. Details on the technical nature and full exploit chains of the two zero-days are expected to emerge from the incident response community in the coming days, which could clarify whether broader campaigns are underway. Organizations should also monitor vendor advisories for any downstream products built on affected Windows components.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp