Jul 17 · Industry News

622 Patches, Five That Matter: Why Volume Is the Wrong Scoreboard

Microsoft’s July Patch Tuesday broke a record at 622 CVEs — and proved patch volume is the wrong scoreboard. The only fixes that matter this week are the exploited SharePoint and AD FS zero-days on CISA’s KEV, with a third SharePoint RCE added July 16. When the list triples, you triage by what’s actually being exploited.

★ Top Read

Microsoft’s July 2026 Patch Tuesday (July 14) was the largest in company history — 622 CVEs, more than triple June’s prior record of about 200 — and it landed with actively exploited zero-days in exactly the infrastructure attackers want: on-prem SharePoint (CVE-2026-56164, network privilege escalation) and Active Directory Federation Services (CVE-2026-56155, local privilege escalation), both confirmed exploited and added to CISA’s KEV on July 14. Two days later, CISA’s July 16 KEV batch added a third SharePoint flaw — CVE-2026-58644, a critical CVSS 9.8 deserialization RCE — confirming the SharePoint exploitation cluster is still widening, not closing. Federal civilian agencies were put on an accelerated, three-day remediation clock for the SharePoint bug, with the earliest deadline landing right around today.

A 622-CVE month is the clearest proof yet that raw patch volume is the wrong scoreboard. You cannot remediate 622 things at once, and you don’t need to — the exploited set is a handful, it’s published in KEV, and it concentrates on identity (AD FS) and collaboration (SharePoint) systems that sit at the center of enterprise trust. The teams that win this month are the ones that can answer, from telemetry rather than a spreadsheet, “which of these exploited CVEs is actually reachable and unpatched in my estate right now?” — and route their scarce patch windows there first. Volume is noise; exploitation plus exposure is signal.

Sources: The Hacker News · SecurityWeek · Dark Reading · CISA

Vulnerabilities & Exposure

CISA adds a third exploited SharePoint zero-day (CVE-2026-58644, CVSS 9.8 deserialization RCE) to KEV. On July 16, CISA confirmed active exploitation of a critical deserialization-of-untrusted-data flaw in on-prem SharePoint Server (2016, 2019, Subscription Edition) that can yield remote code execution. It sits on top of the two SharePoint and AD FS zero-days (CVE-2026-56164, CVE-2026-56155) confirmed exploited on the July 14 Patch Tuesday, making SharePoint the standout exploitation cluster of the cycle — chained for unauthenticated network access, IIS machine-key theft, and persistence. (CISA KEV; The Hacker News; SecurityWeek)

So what: The exploited set this cycle is small and legible even inside a record 622-CVE month. Route patch windows by KEV plus reachability, not by the size of the backlog.

Microsoft’s record 622-CVE Patch Tuesday makes triage the only strategy. The largest-ever release (622 CVEs, about 57 critical) carried three zero-days: the two exploited elevation-of-privilege flaws above, plus CVE-2026-50661, an unexploited BitLocker protection-mechanism bypass that requires physical access. The volume itself is the story — more than triple the prior monthly record — and it makes exploitation-driven prioritization (KEV first) the only workable path. (SecurityWeek; The Hacker News; Dark Reading)

Two critical Fortinet FortiSandbox command-injection flaws added to KEV under active attack. Also on July 16, CISA added CVE-2026-25089 and CVE-2026-39808 (OS command injection, CVSS 9.1 each) to KEV after confirmed exploitation; CVE-2026-25089 abuses the “start VNC” feature via shell metacharacters in JSON HTTP payloads. Fortinet fixed these in FortiSandbox 4.4.9 and 5.0.6, and the federal patch deadline was set for July 19. (BleepingComputer; The Hacker News; Infosecurity Magazine)

Cyberattacks & Breaches

Coca-Cola discloses ransomware at fairlife; U.S. dairy production halted. In an SEC 8-K, Coca-Cola said its fairlife subsidiary found unauthorized third-party access to systems “including its production-related systems” in a ransomware event, forcing a temporary suspension of U.S. production; Canadian production is unaffected, and the company says product quality and safety were not impacted. No ransomware group has been named, and Coca-Cola has not confirmed data theft or extortion. The notable angle is blast radius: an IT and ransomware incident that stopped a physical production line for a roughly $4B brand. (Coca-Cola SEC 8-K; BleepingComputer; TechCrunch; The Register)

So what: The lesson here is operational, not privacy: when ransomware reaches production systems, “the data is safe” is cold comfort if the line is down. Watch for IT/OT-convergence framing.

AI Impact on Security

Prompt injection hardens into a containment problem for agentic AI. Fresh 2026 analysis reinforces that prompt injection remains OWASP’s number-one LLM risk and, as agents gain tools like email and database access, a landed injection lets an attacker act through the system rather than just produce a bad answer. The working posture in 2026 is containment — assume some injections succeed, and ensure a successful one can’t do much. Unit 42 documented real in-the-wild indirect injection earlier this year, moving this from theory to observed. (Help Net Security; Unit 42)

So what: This cycle’s vuln story (patch by exploitation) and the agent thread (contain the injection you can’t prevent) share one spine — defend by seeing and constraining what actually happens, not by trusting a count or a prompt.

Sources & further reading (14)

← All Industry News