Microsoft’s July 2026 Patch Tuesday fixed roughly 569 vulnerabilities, the largest single release in the program’s history, and two of them were already being used in real attacks before the fixes shipped. If your business runs an on-premises SharePoint Server or Active Directory Federation Services (AD FS), the short version is: patch this week. Everyone else should still work through the regular Windows and Office updates, since dozens of the newly fixed bugs touch everyday desktop software.
- Two zero-days, CVE-2026-56164 (SharePoint Server) and CVE-2026-56155 (AD FS), were exploited in the wild before patches were available.
- A third zero-day, CVE-2026-50661 in BitLocker, was publicly disclosed but has not been confirmed in active attacks.
- CISA added both exploited flaws to its Known Exploited Vulnerabilities Catalog on July 14, 2026 and set federal patch deadlines of July 17 and July 28.
- Fifty-nine of the 569 fixes are rated Critical, and most of those allow remote code execution with no user interaction.
- Businesses without their own SharePoint or AD FS servers are not exposed to those two specific bugs, but standard Windows and Office patching still applies.
What actually got exploited this month?
The SharePoint flaw, CVE-2026-56164, is a missing-authentication bug. An attacker does not need a password or any interaction from an employee to use it, just network access to a vulnerable SharePoint Server. BleepingComputer’s coverage of the release notes it was one of two bugs already confirmed as exploited before Microsoft shipped a fix. The AD FS flaw, CVE-2026-56155, lets an attacker who already has some foothold escalate to administrator-level privileges, which is exactly the kind of move that turns a minor break-in into a full domain compromise.
Both of these only matter if you run the on-premises version of SharePoint Server or your own AD FS servers for single sign-on. Most small businesses on Microsoft 365 without a hybrid identity setup are not directly exposed to either one. If you are not sure whether your business runs either product, that uncertainty is itself worth a call to whoever manages your infrastructure.
Why does a server-room bug matter to a 20-person company?
Smaller firms sometimes assume attackers are chasing bigger targets. They are not choosy. Automated scanning tools sweep the internet for any system still running a vulnerable version, and a law office, medical practice, or accounting firm with an old SharePoint install is just as visible to those scans as a Fortune 500 subsidiary. Our post on last month’s Patch Tuesday covered the same pattern: the businesses that got hit hardest were the ones running software several versions behind, not the ones targeted specifically by name.
How fast should a small business actually patch?
Split it into two speeds. Anything CISA lists as actively exploited, like this month’s SharePoint and AD FS bugs, should go out within days once you have tested it on one machine. Everything else in a normal Patch Tuesday batch, meaning dozens of lower-severity fixes for Office, Windows, and other Microsoft products, can follow your regular weekly or biweekly patch window. Rushing every single patch out the same night tends to cause more outages than it prevents, since untested updates occasionally break line-of-business software.
If you are still running Windows Server 2016 anywhere in your office, patch urgency gets more complicated fast. That version’s mainstream support already ended, and as we covered in our Windows Server 2016 end-of-support piece, security updates for it stop entirely in January 2027. A server that misses patches now is a server you will need to replace under a much tighter deadline later.
What if we do not manage our own servers?
If a managed service provider or internal IT team handles your patching, your job this week is simple: ask them directly whether your environment includes SharePoint Server or AD FS, and if so, whether the July fixes are already deployed. A provider that cannot answer that question quickly is a provider worth reconsidering. If nobody is currently responsible for confirming that patches actually installed, rather than just scheduled, that gap is worth closing before the next Patch Tuesday rolls around in August.
Frequently asked questions
What is Patch Tuesday and why does it matter to a small business?
Patch Tuesday is the second Tuesday of every month, when Microsoft releases security fixes for Windows, Office, and related products in one batch. It matters to small businesses because unpatched systems are the easiest way in for attackers, and this month included two flaws already being exploited before fixes shipped.
Do I need to worry about the SharePoint and AD FS bugs if I use Microsoft 365 in the cloud?
If you use Microsoft 365 without an on-premises SharePoint Server or your own AD FS servers, these two specific flaws do not apply to you directly. You should still apply your regular Windows and Office updates, since dozens of other flaws in this release affect standard desktop and laptop software.
How quickly should a small business apply July’s patches?
Treat the SharePoint and AD FS fixes as urgent and apply them within days, ideally after a quick test on one machine. The remaining patches can follow your normal weekly or biweekly patch schedule unless CISA or your IT provider flags something else as actively exploited.
What happens if we skip a Patch Tuesday cycle?
Each skipped cycle leaves known, documented vulnerabilities open on your network, and attackers actively scan the internet for exactly those gaps. The longer a critical or actively exploited flaw sits unpatched, the more likely it is to be the reason behind a future breach or ransomware incident.
Not sure your business is fully patched against this month’s SharePoint and AD FS flaws? Boston Managed IT will review your patch status and flag what’s still exposed in a free 15-minute check. Call (617) 322-5155 or book at bostonmit.com/contact.
— Boston Managed IT