Microsoft's July 2026 Patch Tuesday is one of the largest on record, with the company issuing fixes for roughly 570 vulnerabilities, including three zero-day flaws that were already being exploited or publicly disclosed. For anyone who runs Windows — which is to say almost every organization — this is not a routine month. It is a drop-everything-and-patch month.

What was fixed

The update spans Microsoft's usual broad surface: the Windows operating system, Office, developer tools, and cloud-adjacent components. Within that mass of fixes, security teams should focus first on the zero-days — vulnerabilities that attackers can use before defenders even know they exist — and on any flaw rated critical with a path to remote code execution.

Beyond Microsoft's own patch cycle, July 2026 has been noisy for defenders more broadly. Security agencies flagged an actively exploited SharePoint Server deserialization flaw serious enough to carry a near-maximum severity score, and separate critical fixes landed for widely used collaboration software. The through-line is familiar: internet-facing enterprise software remains the most attacked surface on the network.

Why zero-days change the math

A normal vulnerability is a race: vendors ship a patch, and defenders apply it before attackers weaponize it. A zero-day removes the head start. Because it is already being exploited when disclosed, every hour before patching is a window attackers can walk through. That is why security teams triage by exploitation status first and theoretical severity second.

What to do this week

For IT and security teams, the priority order is straightforward:

  • Patch the zero-days first on internet-facing and high-value systems.
  • Prioritize critical remote-code-execution flaws next, especially on servers.
  • Confirm your inventory — you cannot patch what you don't know you run.
  • Check vendor and government advisories for known-exploited lists and hard deadlines.
  • Verify backups before large-scale patching, in case an update needs rolling back.

For individuals, the advice is simpler: let Windows Update install this month's patches, and don't defer the restart.

Background: why patch volumes keep climbing

A 570-fix month is not necessarily a sign that software is getting worse. It also reflects better detection: more researchers, more automated fuzzing, and more coordinated disclosure mean more bugs are found and fixed before they cause damage. The uncomfortable trade-off is patch fatigue — the sheer volume makes it harder for stretched teams to separate the urgent from the routine. That is exactly why exploitation-based prioritization matters more every year.

Why it matters

Unpatched, known vulnerabilities remain one of the most common root causes of real-world breaches. The 2026 breach headlines — from healthcare giants compromised through phishing to ransomware crews leaking corporate data — repeatedly trace back to access that patching and basic hygiene could have closed. Patch Tuesday is unglamorous, but it is frontline defense.

Key takeaways

  • Microsoft's July 2026 Patch Tuesday fixes roughly 570 vulnerabilities, including three zero-days.
  • Zero-days are already being exploited, so they take priority over higher-scored but un-exploited flaws.
  • Teams should patch internet-facing and high-value systems first, then critical RCE bugs.
  • Rising patch volumes reflect better detection as much as buggier software — prioritization is the real skill.
  • Unpatched known flaws remain a leading cause of breaches; timely patching is core defense.

The bottom line

Not every Patch Tuesday deserves urgency, but this one does. With three actively dangerous zero-days in a 570-fix release, the difference between patching this week and patching "when we get to it" is the difference between a quiet month and an incident report.

Related: Passkeys Explained — why 5 billion people are ditching passwords.