Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft has released its largest-ever security update, addressing 622 vulnerabilities, including two zero-day flaws currently being exploited in the wild. The critical patches target SharePoint Server and Active Directory Federation Services, both of which are essential for enterprise identity and document management.
Why it matters
The scale of these vulnerabilities poses a significant risk to global enterprise security, particularly for organizations relying on self-hosted infrastructure.
Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200 .
Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Services.
Neither is one of the splashy remote code execution criticals. They are privilege bugs in two systems that matter more than their scores suggest: the company document store, and the box that signs its logins.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in