Security1 publisher2 min readPublished
Microsoft rates its only two exploited July bugs important and moderate
Microsoft's July update fixes 622 vulnerabilities, 62 of them rated critical. The two it says attackers are already using, in AD FS and SharePoint Server, sit below that line, so exploited status has to order the work.
The Watch · Security desk

What happened
- Johannes Ullrich's SANS Internet Storm Center diary counted 622 vulnerabilities in Microsoft's July 2026 update, with a further 427 Chromium vulnerabilities reaching Microsoft Edge.
- One of the 622 was public before release day and two were already being exploited when the patches shipped, according to the diary.
- The pre-disclosed item is CVE-2026-50661, a BitLocker security feature bypass credited to "Anonymous", which the diary lists as not yet exploited.
- Two critical Reliable Multicast Transport Driver bugs, CVE-2026-54982 and CVE-2026-54995, typically need a network-adjacent attacker, and Ullrich has not seen exploits for the similar bugs in past updates.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint A queue built on Microsoft's severity column spends its first pass on 62 items with no reported attacks against them, and reaches the two that attackers are using afterwards.
- cost The 622 figure does not multiply the labour for a team that deploys by product, so a volume argument for extra patching budget this month has little behind it.
- exposure Laptops that join untrusted wireless carry the reachable surface for the DHCP client RCE until the July update lands; the DHCP server bugs land on a separate, server-side owner.
- decision With no published account of how the AD FS and SharePoint bugs were used, the ordering decision falls to asset exposure: who fronts AD FS to the internet and who still runs SharePoint on premises.
CVE-2026-56155, the Active Directory Federation Services elevation of privilege, and CVE-2026-56164, the SharePoint Server elevation of privilege, are the two Microsoft says have already been exploited [4][5][3]. Two out of 622 is 0.32 percent of the release [3]. The critical set is about ten percent of it, 62 items [2], and neither exploited bug is in that set [4]. Patch critical-first and both arrive late.
Johannes Ullrich, who wrote the SANS Internet Storm Center diary on July 14, said the volume itself defeats the usual triage read: with the count that high, he wrote, it is hard to single out which issues are the noteworthy ones [6][15]. His counsel on the flood was about inventory. "You still own the same number of Microsoft products," he wrote [12]. Many products, Office among them, take a large number of CVEs in one update, and patching the product does not take much longer because the patch covers more bugs [13].
CVE-2026-54128, the Windows DHCP client remote code execution, is rated critical, and it needs the target to connect to a network with a malicious DHCP server. Ullrich flagged it for public wifi attacks [9]. The same release also fixes several critical DHCP server RCEs [10].
One vulnerability was public before release day. Ullrich wrote that it is not clear whether CVE-2026-50661, the BitLocker security feature bypass, is one of the Nightmare Eclipse vulnerabilities [8]. Counting Microsoft's own 622 and the 427 Chromium fixes that reach Edge, the month's total is 1,049 [1].
What to watch
- A KEV listing with a remediation due date for CVE-2026-56155 or CVE-2026-56164 would set a hard clock on both.