What happened

Microsoft's July 2026 Patch Tuesday was the largest on record: 570 vulnerabilities fixed across Windows, Office, SharePoint Server, Remote Desktop Services and more — including three publicly disclosed zero-days. It followed a June update that itself addressed 206 issues.

Within days, attackers were chaining three SharePoint vulnerabilities for unauthenticated remote code execution, prompting CISA to add them to its Known Exploited Vulnerabilities catalogue the same day patches shipped. The gap between 'patch available' and 'actively exploited' has effectively closed.

Why it matters to your business

Volume like this overwhelms manual patching. When an operating system ships 570 fixes in a month, 'we update when we remember' is no longer a strategy — it's an exposure. And exploitation now begins within days of disclosure, not months.

The uncomfortable detail for SMEs: many critical fixes don't apply automatically. SharePoint servers, network appliances and line-of-business machines need deliberate, tested patch deployment — exactly the unglamorous work that determines whether an attack succeeds.

What you should do

Automate OS and application patching across every device — with reporting so you can prove it's happening.

Prioritise exploited vulnerabilities. CISA's KEV catalogue is the de facto emergency list.

Don't forget non-Microsoft software. Browsers, PDF readers and line-of-business apps are patched on their own cycles.

Hand it to someone accountable. Patch management is built into our Backup & Device Management bundle and above — devices get patched, verified and reported on monthly.

Source: DCD July 2026 Cybersecurity Digest