[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcqBRNpU_qVAvxXkrq_Y6F96gASYF8tCHlMQB388yEpc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"6dd87e51-afad-4f54-bb93-d755196dd974","record-622-vulnerabilities-patched-in-single-patch-tuesday-including-two-active-zero-days","9d0bb94e-194d-43af-9b37-cdf6b18af41d","Record 622 Vulnerabilities Patched in Single Patch Tuesday, Including Two Active Zero-Days","Microsoft's July 2025 Patch Tuesday disclosed a staggering 622 vulnerabilities — triple the previous monthly record — driven in part by AI-powered scanning tools accelerating defect discovery at unprecedented scale. Two of these vulnerabilities were actively exploited zero-days targeting Active Directory Federation Services and Microsoft SharePoint Server, meaning attackers were already in the wild leveraging them before patches were available. This surge highlights the growing gap between the rate at which vulnerabilities are discovered and the rate at which organizations can realistically test and deploy patches. The situation matters because organizations relying on traditional monthly patching cycles are increasingly exposed, especially when critical identity and collaboration infrastructure like AD FS and SharePoint are in scope. Without a risk-tiered patching strategy, security teams will be overwhelmed and the most dangerous flaws may not receive timely remediation.","**Immediate actions:**\n- Prioritize and emergency-patch the two actively exploited zero-days in Active Directory Federation Services and Microsoft SharePoint Server before addressing lower-severity CVEs.\n- Run an authenticated vulnerability scan across your environment immediately to identify all unpatched Microsoft assets exposed by this Patch Tuesday release.\n- Apply mitigations or workarounds published by Microsoft for critical vulnerabilities where full patching cannot be completed within 24–48 hours.\n\n**Long-term improvements:**\n- Implement a risk-tiered patching policy that separates zero-days and critical CVEs (CVSS 9.0+) from routine patches with dedicated SLAs of 24–72 hours.\n- Maintain a continuously updated asset inventory so that every Microsoft product in your environment is automatically mapped to newly disclosed CVEs.\n- Evaluate automated patch deployment tooling (e.g., WSUS, SCCM, Intune, or third-party solutions) to reduce manual patching bottlenecks as CVE volumes continue to grow.\n\n**Detection & monitoring measures:**\n- Deploy threat detection rules specific to exploitation indicators for AD FS and SharePoint vulnerabilities, including anomalous authentication events and unusual file access patterns.\n- Subscribe to Microsoft Security Response Center (MSRC) alerts and threat intelligence feeds to receive real-time notification of actively exploited vulnerabilities.\n- Conduct weekly vulnerability trend reviews to ensure patch SLA compliance is tracked and reported to leadership as a key security metric.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","CIS Control 12: Network Infrastructure Management","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST CSF ID.RA-1: Asset vulnerabilities are identified and documented","NIST CSF RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks","ISO\u002FIEC 27001:2022 Annex A 8.8: Management of Technical Vulnerabilities","ITIL 4: Change Enablement and Vulnerability Management Practices","published","2026-07-14T22:21:31.237706+00:00","2026-07-14T22:21:31.038+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fcyberscoop.com\u002Fmicrosoft-patch-tuesday-july-2026\u002F","microsoft-discloses-the-mother-of-all-vulnerability-loads-tripling-june-s-previo-b591db","Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]