Jul 15 · Industry News

The Month AI Broke Patch Tuesday

Microsoft’s July Patch Tuesday set an all-time record at about 569 CVEs — and Microsoft credits AI-assisted vulnerability discovery for the surge, making it a new normal. Two zero-days were exploited before a fix shipped, and CISA added four KEV entries (including a CVSS-10 SonicWall SSRF) due July 17. When the vendor’s own AI surfaces hundreds of flaws a month, patch-by-count is arithmetically dead.

★ Top Read

Microsoft’s July Patch Tuesday set an all-time record — Microsoft’s own catalog lists about 569 CVEs (some trade outlets counted higher), the largest monthly release the company has ever issued — and Microsoft has tied the rising volume to AI-assisted vulnerability discovery across its codebase, making this a new normal rather than a spike. Three zero-days were disclosed; two were already exploited before a fix shipped: CVE-2026-56155 (Active Directory Federation Services elevation of privilege) and CVE-2026-56164 (SharePoint Server). Both, plus two actively exploited SonicWall SMA1000 flaws — including CVE-2026-15409, a CVSS 10.0 pre-auth SSRF — landed in CISA’s KEV catalog on July 14 with a federal remediation deadline of July 17.

The takeaway for CISOs and boards: when the vendor’s own AI is surfacing hundreds of flaws a month, “patch everything” is arithmetically dead. You triage against the handful CISA confirms under active exploitation and against real telemetry of what’s internet-reachable in your environment. This is exposure-as-a-visibility-question, not a spreadsheet.

Sources: Tenable · BleepingComputer · CISA

Vulnerabilities & Exposure

Microsoft ships a record ~569 CVEs with two actively exploited zero-days. The July batch is the largest ever. Two of three zero-days were exploited pre-patch — CVE-2026-56155 (AD FS elevation of privilege) and CVE-2026-56164 (SharePoint Server) — while a third (a BitLocker security-feature bypass) was disclosed but not observed exploited. Microsoft attributes the rising volume to AI-assisted vulnerability discovery.

CISA adds four KEV entries on July 14 — two Microsoft zero-days plus two SonicWall SMA1000 flaws — federal due July 17. The SonicWall entries are CVE-2026-15409 (a CVSS 10.0 pre-auth SSRF) and CVE-2026-15410 (code injection); SonicWall confirmed both are being actively exploited as zero-days and urges customers to patch or discontinue the appliance by July 17.

SAP’s July Patch Day headlines a critical NetWeaver memory-corruption flaw (CVE-2026-44747, CVSS 9.9). SAP released 16 new security notes, led by an authenticated memory-corruption bug in NetWeaver Application Server ABAP spanning legacy through current kernels, plus critical HTTP request-smuggling (Approuter) and insecure-sample-credentials (Commerce Cloud) fixes. No confirmed in-the-wild exploitation as of disclosure.

So what: The exposure story isn’t a bug, it’s the volume — and now the volume itself is AI-generated. Prioritize the four CISA confirmed under active exploitation ahead of the ~569-item pile, and treat the July 17 KEV clock as the operative deadline.

AI Impact on Security

AI-assisted vulnerability discovery is now visibly inflating patch volume. Microsoft’s record month is tied to AI-driven discovery across its codebase — meaning defenders face AI-accelerated flaw disclosure on the vendor side while attackers use AI to compress time-to-exploit. That two-sided squeeze is exactly what makes patch-by-count untenable and exploitation-signal triage mandatory.

GhostApproval remains the live agent-observability thread. Wiz’s disclosure that several AI coding assistants can conceal an agent’s real action from the approval prompt (via symlink-following) still stands as the cleanest agentic-oversight proof point: a human-in-the-loop is only a control if you can independently verify what the agent actually did.

So what: The volume story and the agent-oversight thread share one spine — AI changes both the volume and the verifiability of risk, and visibility is the answer to both.

Regulatory & Policy

Treasury/OFAC sanctions a ransomware-enabling VPN provider (1VPNS) and a cryptor seller. OFAC designated First VPN Service and its administrator, plus a seller of “cryptors” used to disguise ransomware from security tools. OFAC says 1VPNS advertised no-logs, no-cooperation hosting on criminal forums since 2014; the action continues pressure on the ransomware supply chain rather than just the operators.

Nigeria advances mandatory cyberattack-disclosure rules. Nigeria moved to require organizations to disclose cyberattacks, joining the global shift toward mandated breach transparency. Thresholds and timelines are still emerging; treat specifics as provisional until the final rule text is published.

So what: The policy signals rhyme with the tech story — regulators are compressing disclosure timelines and remediation clocks while squeezing the ransomware economy, all pushing toward exploitation-driven prioritization.

Sources & further reading (8)

← All Industry News