569 CVEs in a single month is a record, and the number is almost useless on its own. Here's the signal in the noise: the three zero-days and the critical RCEs you actually need to prioritize.
Microsoft's July 2026 Patch Tuesday is the largest in its history: 569 CVEs fixed in a single month, including 56 critical vulnerabilities and three actively-exploited zero-days. That number is genuinely overwhelming — and on its own, useless. No one patches 569 things by severity number in order. The job is prioritization, so here's the signal buried in the noise: the handful of fixes that actually demand immediate action, and why.
Why the headline number is a trap
A record 569-CVE month generates alarming headlines, but treating the number as the story leads teams astray. The reality is that the vast majority of any Patch Tuesday is routine — important to apply on your normal cadence, but not on-fire. What changes risk today is a small subset: vulnerabilities that are already being exploited, and unauthenticated remote code execution flaws reachable from the internet. A 9.8 RCE on an internet-facing server matters enormously; a high-scored local flaw that needs an authenticated foothold in obscure software can wait for your normal window. So the correct response to '569 CVEs' isn't panic — it's triage. Sort by exploited-in-the-wild first, unauthenticated internet-facing RCE second, everything else on cadence, and the impossible-looking list becomes a short priority queue.
July 2026 Patch Tuesday — what to prioritize
1 — Now
Priority
The 3 exploited zero-days
What
Attackers using them today
2 — This week
Priority
Unauth internet-facing RCEs
What
Mass-exploitable if exposed
3 — Cadence
Priority
Remaining 56 critical
What
Serious but not on-fire
4 — Cadence
Priority
The rest of the 569
What
Routine monthly hygiene
Priority
What
Why
1 — Now
The 3 exploited zero-days
Attackers using them today
2 — This week
Unauth internet-facing RCEs
Mass-exploitable if exposed
3 — Cadence
Remaining 56 critical
Serious but not on-fire
4 — Cadence
The rest of the 569
Routine monthly hygiene
569 CVEs is not 569 emergencies — triage by exploitation and exposure, and the list shrinks fast. · Unsplash
The ones to act on first
Two exploited zero-days lead the queue. [CVE-2026-56155](/windows-adfs-cve-2026-56155-zero-day-exploited-patch-now) is an AD FS elevation-of-privilege flaw — prioritize it because it sits on your identity layer, where a compromise has the widest blast radius. [CVE-2026-56164](/sharepoint-cve-2026-56164-microsoft-moderate-nvd-critical) is a SharePoint elevation-of-privilege zero-day. And while it was patched in this same release, [CVE-2026-50522](/sharepoint-cve-2026-50522-critical-rce-exploited-patch-now) — a 9.8 unauthenticated SharePoint RCE — came under active exploitation shortly after a public PoC, making SharePoint a two-front problem this month. Beyond the zero-days, scan the 56 critical CVEs for unauthenticated, internet-reachable RCEs and patch those next. Everything else is your normal monthly hygiene. If you run Windows Server or SharePoint, this month is a real one — but it's manageable if you triage instead of drowning in the count.
Quick answers
How many CVEs did Microsoft fix in July 2026?
Microsoft's July 2026 Patch Tuesday fixed a record 569 CVEs — the largest single monthly release in its history — including 56 critical-severity vulnerabilities and three actively-exploited zero-days. However, the raw number is not a measure of urgency: most of any Patch Tuesday is routine and can be applied on a normal cadence. The priority items are the exploited zero-days and unauthenticated, internet-facing remote code execution flaws, which are a small subset of the total.
Which July 2026 patches should I prioritize?
Prioritize the three actively-exploited zero-days first, everywhere they apply — notably CVE-2026-56155 (AD FS elevation of privilege, an identity-layer flaw) and CVE-2026-56164 (SharePoint elevation of privilege). Also urgently patch CVE-2026-50522, a critical (9.8) unauthenticated SharePoint RCE that came under active exploitation after a public PoC. After the zero-days, address any unauthenticated, internet-reachable RCEs among the 56 critical CVEs. The remaining fixes can follow your normal monthly patching cadence.
Is a record Patch Tuesday something to worry about?
Not in the way the headline number suggests. A record 569-CVE month sounds alarming, but volume isn't the same as risk — the vast majority are routine fixes for your normal cadence. What actually raises risk today is the small subset that's being exploited in the wild or is an unauthenticated internet-facing RCE. The right response is triage, not panic: patch exploited zero-days now, internet-facing critical RCEs next, and the rest on schedule. A big number becomes a short, manageable priority list.