July 31, 2026

July 2026 Patch Tuesday: What Boston Businesses Need to Patch This Week

Microsoft’s July 2026 Patch Tuesday fixed roughly 569 vulnerabilities, the largest single release in the program’s history, and two of them were already being used in real attacks before the fixes shipped. If your business runs an on-premises SharePoint Server or Active Directory Federation Services (AD FS), the short version is: patch this week. Everyone else should still work through the regular Windows and Office updates, since dozens of the newly fixed bugs touch everyday desktop software.

What actually got exploited this month?

The SharePoint flaw, CVE-2026-56164, is a missing-authentication bug. An attacker does not need a password or any interaction from an employee to use it, just network access to a vulnerable SharePoint Server. BleepingComputer’s coverage of the release notes it was one of two bugs already confirmed as exploited before Microsoft shipped a fix. The AD FS flaw, CVE-2026-56155, lets an attacker who already has some foothold escalate to administrator-level privileges, which is exactly the kind of move that turns a minor break-in into a full domain compromise.

Both of these only matter if you run the on-premises version of SharePoint Server or your own AD FS servers for single sign-on. Most small businesses on Microsoft 365 without a hybrid identity setup are not directly exposed to either one. If you are not sure whether your business runs either product, that uncertainty is itself worth a call to whoever manages your infrastructure.

Why does a server-room bug matter to a 20-person company?

Smaller firms sometimes assume attackers are chasing bigger targets. They are not choosy. Automated scanning tools sweep the internet for any system still running a vulnerable version, and a law office, medical practice, or accounting firm with an old SharePoint install is just as visible to those scans as a Fortune 500 subsidiary. Our post on last month’s Patch Tuesday covered the same pattern: the businesses that got hit hardest were the ones running software several versions behind, not the ones targeted specifically by name.

How fast should a small business actually patch?

Split it into two speeds. Anything CISA lists as actively exploited, like this month’s SharePoint and AD FS bugs, should go out within days once you have tested it on one machine. Everything else in a normal Patch Tuesday batch, meaning dozens of lower-severity fixes for Office, Windows, and other Microsoft products, can follow your regular weekly or biweekly patch window. Rushing every single patch out the same night tends to cause more outages than it prevents, since untested updates occasionally break line-of-business software.

If you are still running Windows Server 2016 anywhere in your office, patch urgency gets more complicated fast. That version’s mainstream support already ended, and as we covered in our Windows Server 2016 end-of-support piece, security updates for it stop entirely in January 2027. A server that misses patches now is a server you will need to replace under a much tighter deadline later.

What if we do not manage our own servers?

If a managed service provider or internal IT team handles your patching, your job this week is simple: ask them directly whether your environment includes SharePoint Server or AD FS, and if so, whether the July fixes are already deployed. A provider that cannot answer that question quickly is a provider worth reconsidering. If nobody is currently responsible for confirming that patches actually installed, rather than just scheduled, that gap is worth closing before the next Patch Tuesday rolls around in August.

Frequently asked questions

What is Patch Tuesday and why does it matter to a small business?
Patch Tuesday is the second Tuesday of every month, when Microsoft releases security fixes for Windows, Office, and related products in one batch. It matters to small businesses because unpatched systems are the easiest way in for attackers, and this month included two flaws already being exploited before fixes shipped.

Do I need to worry about the SharePoint and AD FS bugs if I use Microsoft 365 in the cloud?
If you use Microsoft 365 without an on-premises SharePoint Server or your own AD FS servers, these two specific flaws do not apply to you directly. You should still apply your regular Windows and Office updates, since dozens of other flaws in this release affect standard desktop and laptop software.

How quickly should a small business apply July’s patches?
Treat the SharePoint and AD FS fixes as urgent and apply them within days, ideally after a quick test on one machine. The remaining patches can follow your normal weekly or biweekly patch schedule unless CISA or your IT provider flags something else as actively exploited.

What happens if we skip a Patch Tuesday cycle?
Each skipped cycle leaves known, documented vulnerabilities open on your network, and attackers actively scan the internet for exactly those gaps. The longer a critical or actively exploited flaw sits unpatched, the more likely it is to be the reason behind a future breach or ransomware incident.

Not sure your business is fully patched against this month’s SharePoint and AD FS flaws? Boston Managed IT will review your patch status and flag what’s still exposed in a free 15-minute check. Call (617) 322-5155 or book at bostonmit.com/contact.

— Boston Managed IT

About the Author

Your IT Partner Is Just a Click Away. Are you ready to stop thinking about IT?

We handle the infrastructure, helpdesk, and security — Boston businesses rely on us so they never have to think about IT again.