Microsoft’s July 2026 Patch Tuesday (July 14) was the largest in company history — 622 CVEs, more than triple June’s prior record of about 200 — and it landed with actively exploited zero-days in exactly the infrastructure attackers want: on-prem SharePoint (CVE-2026-56164, network privilege escalation) and Active Directory Federation Services (CVE-2026-56155, local privilege escalation), both confirmed exploited and added to CISA’s KEV on July 14. Two days later, CISA’s July 16 KEV batch added a third SharePoint flaw — CVE-2026-58644, a critical CVSS 9.8 deserialization RCE — confirming the SharePoint exploitation cluster is still widening, not closing. Federal civilian agencies were put on an accelerated, three-day remediation clock for the SharePoint bug, with the earliest deadline landing right around today.
A 622-CVE month is the clearest proof yet that raw patch volume is the wrong scoreboard. You cannot remediate 622 things at once, and you don’t need to — the exploited set is a handful, it’s published in KEV, and it concentrates on identity (AD FS) and collaboration (SharePoint) systems that sit at the center of enterprise trust. The teams that win this month are the ones that can answer, from telemetry rather than a spreadsheet, “which of these exploited CVEs is actually reachable and unpatched in my estate right now?” — and route their scarce patch windows there first. Volume is noise; exploitation plus exposure is signal.
Sources: The Hacker News · SecurityWeek · Dark Reading · CISA
Vulnerabilities & Exposure
CISA adds a third exploited SharePoint zero-day (CVE-2026-58644, CVSS 9.8 deserialization RCE) to KEV. On July 16, CISA confirmed active exploitation of a critical deserialization-of-untrusted-data flaw in on-prem SharePoint Server (2016, 2019, Subscription Edition) that can yield remote code execution. It sits on top of the two SharePoint and AD FS zero-days (CVE-2026-56164, CVE-2026-56155) confirmed exploited on the July 14 Patch Tuesday, making SharePoint the standout exploitation cluster of the cycle — chained for unauthenticated network access, IIS machine-key theft, and persistence. (CISA KEV; The Hacker News; SecurityWeek)
So what: The exploited set this cycle is small and legible even inside a record 622-CVE month. Route patch windows by KEV plus reachability, not by the size of the backlog.
Microsoft’s record 622-CVE Patch Tuesday makes triage the only strategy. The largest-ever release (622 CVEs, about 57 critical) carried three zero-days: the two exploited elevation-of-privilege flaws above, plus CVE-2026-50661, an unexploited BitLocker protection-mechanism bypass that requires physical access. The volume itself is the story — more than triple the prior monthly record — and it makes exploitation-driven prioritization (KEV first) the only workable path. (SecurityWeek; The Hacker News; Dark Reading)
Two critical Fortinet FortiSandbox command-injection flaws added to KEV under active attack. Also on July 16, CISA added CVE-2026-25089 and CVE-2026-39808 (OS command injection, CVSS 9.1 each) to KEV after confirmed exploitation; CVE-2026-25089 abuses the “start VNC” feature via shell metacharacters in JSON HTTP payloads. Fortinet fixed these in FortiSandbox 4.4.9 and 5.0.6, and the federal patch deadline was set for July 19. (BleepingComputer; The Hacker News; Infosecurity Magazine)
Cyberattacks & Breaches
Coca-Cola discloses ransomware at fairlife; U.S. dairy production halted. In an SEC 8-K, Coca-Cola said its fairlife subsidiary found unauthorized third-party access to systems “including its production-related systems” in a ransomware event, forcing a temporary suspension of U.S. production; Canadian production is unaffected, and the company says product quality and safety were not impacted. No ransomware group has been named, and Coca-Cola has not confirmed data theft or extortion. The notable angle is blast radius: an IT and ransomware incident that stopped a physical production line for a roughly $4B brand. (Coca-Cola SEC 8-K; BleepingComputer; TechCrunch; The Register)
So what: The lesson here is operational, not privacy: when ransomware reaches production systems, “the data is safe” is cold comfort if the line is down. Watch for IT/OT-convergence framing.
AI Impact on Security
Prompt injection hardens into a containment problem for agentic AI. Fresh 2026 analysis reinforces that prompt injection remains OWASP’s number-one LLM risk and, as agents gain tools like email and database access, a landed injection lets an attacker act through the system rather than just produce a bad answer. The working posture in 2026 is containment — assume some injections succeed, and ensure a successful one can’t do much. Unit 42 documented real in-the-wild indirect injection earlier this year, moving this from theory to observed. (Help Net Security; Unit 42)
So what: This cycle’s vuln story (patch by exploitation) and the agent thread (contain the injection you can’t prevent) share one spine — defend by seeing and constraining what actually happens, not by trusting a count or a prompt.
Sources & further reading (14)
- The Hacker News — “Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack”
- SecurityWeek — “Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days”
- Dark Reading — “Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes”
- The Hacker News — “CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV”
- CISA — “CISA Adds Three Known Exploited Vulnerabilities to Catalog” (July 16)
- BleepingComputer — “Critical Fortinet FortiSandbox flaws now exploited in attacks”
- The Hacker News — “Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week”
- Infosecurity Magazine — “CISA Mandates Urgent Patch for Actively Exploited Fortinet Flaws”
- U.S. SEC — Coca-Cola Form 8-K, “Technology Disruption Involving fairlife Operations” (July 16, 2026)
- BleepingComputer — “Coca-Cola says Fairlife ransomware attack halts US dairy production”
- TechCrunch — “Coca-Cola suspended production at its Fairlife dairy after a ransomware attack”
- The Register — “Ransomware curdles production at Coca-Cola’s Fairlife dairy biz”
- Help Net Security — “Prompt injection still drives most agentic AI security failures in production”
- Unit 42 — “Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild”