Microsoft’s July update just broke its own record, again. Last month it was roughly 200 fixes. This month it’s 622, or 570 depending on which count you trust, plus another 427 in the Chromium engine that powers Edge. Two of those bugs were already being exploited before the patches landed. If your team is still working through June’s backlog, July just buried you deeper, and that’s the actual story here: patch volume is now outpacing the operational capacity of the teams responsible for applying it. That’s a real cybersecurity resourcing problem, not a headline number.
Meanwhile, SonicWall customers running Secure Mobile Access 1000 series appliances got a different kind of bad news this week: two zero-days, already exploited in the wild, serious enough that SonicWall is telling some customers to re-image hardware and reset every credential and TOTP token on the box. Different vendor, same lesson. Attackers don’t wait for your patch calendar, and lately your patch calendar can’t keep up with them anyway.
570 Became 622. Your Triage Window Didn’t Grow.
Microsoft says the jump in vulnerability counts is partly the result of AI-assisted vulnerability discovery, both by its own researchers and by external hunters submitting reports. That’s not spin. Automated fuzzing and LLM-assisted code review genuinely surface bugs that used to sit undiscovered for years. The problem is that discovery scaled a lot faster than remediation capacity did.
Microsoft’s July release covers 622 of its own CVEs, more than triple June’s previous high of around 200, with 57 to 62 rated critical depending on which vendor scorecard you read.
Fifty-plus critical flaws in a single Patch Tuesday used to be an outlier event that got its own incident bridge call. Now it’s just Tuesday. When “record-breaking” becomes monthly, the record stops meaning anything to the people who have to triage it, and that’s exactly the environment where a genuinely urgent bug slips into the “we’ll get to it next sprint” pile.
Two vulnerabilities in this batch don’t have that luxury. One in Active Directory and one in SharePoint Server were already being exploited before Microsoft shipped fixes, meaning organizations running either were exposed with no patch available for some window of time. A third bug, in BitLocker, was publicly disclosed ahead of the fix, which is its own kind of gift to attackers watching for disclosure timing.
While You Were Counting CVEs, SonicWall Customers Were Getting Re-Imaged
The SonicWall incident is worth sitting with because the remediation guidance is unusually blunt. This isn’t “apply the patch and move on.” SonicWall is telling affected organizations that if indicators of compromise are present, the right response is to re-image physical appliances or redeploy virtual ones from scratch, then rotate every user and administrator password and reset TOTP tokens.
That’s not a patch instruction. That’s an assumption of compromise. When a vendor tells you to nuke the box and start over rather than trust a patched instance, it’s because the two zero-days, CVE-2026-15409 and CVE-2026-15410, gave attackers enough access that partial remediation isn’t credible. Edge appliances like SMA gateways sit exactly where an intruder wants to land: authenticated, trusted, and facing the internet.
The pattern across both stories is the same. Microsoft’s flood of patches is a capacity problem. SonicWall’s zero-days are a trust problem. Put them together and you get the actual state of enterprise defense in 2026: more things need fixing than any team can fix on schedule, and the handful that matter most are the ones actively being used against you right now, not the ones sitting at the top of a CVSS-sorted spreadsheet.

What Actually Reduces the Damage This Month
You are not going to triage 622 CVEs by severity score alone this week, and you shouldn’t try. Exploitation status beats CVSS score every time. Here’s where to spend the next few days:
- Patch the Active Directory and SharePoint Server zero-days first, full stop. They’re already being used against real targets, not theoretical ones.
- If you run SonicWall SMA 1000 series appliances, check for the published indicators of compromise before you assume patching alone fixes it. If IOCs are present, follow the re-image and full credential reset guidance, including TOTP tokens.
- Push the BitLocker fix on any device where disk encryption is your last line of defense against physical theft, since the flaw was public before the patch shipped.
- Update your incident response runbook to assume “patch available” and “risk resolved” are not the same thing. Some of these bugs need forensic review, not just a reboot.
- Treat internet-facing remote access appliances, VPN concentrators, SMA gateways, firewalls, as your highest-priority hardening targets regardless of vendor. They’re the front door, and attackers know it.
Longer term, this month is a decent argument for revisiting how your organization prioritizes patching at all. A pure CVSS-driven queue breaks down when the queue is 622 items long. Threat detection tied to known exploitation, not just severity, is what should be moving items to the front of the line. That means subscribing to exploited-in-the-wild feeds, not just vendor severity ratings, and building alerting around indicators of compromise for the specific products you run, not generic signatures.
Defense in depth matters more this month than usual, precisely because you cannot patch everything on day one. A firewall rule that limits exposure on a vulnerable service, brute-force lockout policies on remote access portals, and network segmentation that contains a compromised appliance all buy you the days you need to actually get through the patch queue. None of that replaces patching. It just keeps one unpatched box from becoming the whole network’s problem while you work through the other 621.
Sources
- Microsoft Patches a Record 570 Security Flaws
- Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
- Microsoft Patch Tuesday July 2026 – The AI Apocalypse is Here
- SonicWall SMA appliances targeted in zero-day attacks
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
