Microsoft's largest Patch Tuesday ever: 622 flaws, Kerberos encryption overhaul
The record-breaking update also forces a long-planned authentication change that could disrupt legacy Windows environments.

Image by Cybernews.
- Microsoft's July security update tackles more than 600 flaws, including multiple critical vulnerabilities and exploited zero-days.
- The update also begins mandatory Kerberos RC4 enforcement, potentially affecting organizations using legacy authentication.
- Just days after warning AI would accelerate vulnerability discovery, Microsoft delivered its biggest Patch Tuesday on record.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Microsoft has released its largest Patch Tuesday ever, fixing 622 vulnerabilities, including 59 critical flaws and three zero-days, and is now beginning to force organizations to phase out legacy Kerberos RC4 encryption.
The July security update, released Tuesday, spans Windows, Office, Exchange Server, SharePoint Server, SQL Server, Azure, Visual Studio, and other Microsoft products.
“Windows 11's July 2026 Patch Tuesday is absolutely massive," @WindowsLatest posted on X, describing the numbers as “wild” and providing a compiled list of the more serious bugs.
- 254 elevation of privilege bugs
- 145 remote code execution bugs
- 102 information disclosure bugs
- 35 denial of service bugs
- 17 security bypass bugs
- 16 spoofing bugs
“The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates,”Microsoft said.
Windows accounts for most of the vulnerabilities
Windows accounted for the vast majority of the release, with 416 vulnerabilities addressed, followed by Office with 82 and Microsoft Edge with 46, the Microsoft release notes show.
Across the full update, Microsoft patched 145 remote code execution flaws, including critical bugs affecting Exchange Server, SharePoint Server, SQL Server, DHCP Server, Hyper-V, Office, Word, Excel, and PowerPoint.
Josh Taylor, lead cybersecurity analyst at Fortra, points out that 115 CVEs credit Microsoft in the acknowledgements, suggesting a significant amount of internally identified or AI-assisted vulnerability discovery.
"Whether that reflects stronger internal research, better secure development practices, or more AI-assisted vulnerability discovery, it is not a trivial number," the analyst says.
Taylor also says “discipline” is the key for patching teams to stay on top of Microsoft's extensive list of 622 vulnerabilities.
He notes that “when a release this large still contains active exploitation and public disclosure, the conversation shifts quickly from patch volume to patch order.”
“The right move is not panic, it is sequencing: put exploited issues and exposed infrastructure first, then let the normal validation process do its job,”Taylor says.
Three zero-days demand immediate attention
Two of the zero-days identified by Microsoft – affecting Active Directory Federation Services (AD FS) and Microsoft SharePoint Server (CVE-2026-56155 and CVE-2026-56164) – were actively exploited before patches became available.
The third – a BitLocker security feature bypass (CVE-2026-50661) – was previously publicly disclosed but has not been confirmed as exploited, according to an executive summary of the release published by Zecurit.
The security management company is urging defenders to treat all three zero-days as “immediate patching priorities” within the next 48 hours.
According to the Microsoft Security Update Guide July release notes, the first two actively exploited zero-days can allow attackers to escalate privileges, and in the case of the SharePoint bug, do so remotely.
The third zero-day – affecting Windows BitLocker – can allow an attacker with physical access to bypass device encryption.
CISA urges immediate SharePoint action
The US Cybersecurity and Infrastructure Security Agency (CISA) also issued its own advisory on Tuesday, warning that the newest Microsoft SharePoint vulnerability (CVE-2026-56164) is now being actively exploited alongside two previously disclosed SharePoint flaws.
The threat can allow attackers to compromise on-premises SharePoint servers, steal IIS machine keys, establish persistence, and deploy malware.
The watchdog agency added the vulnerability to its Known Exploited Vulnerabilities catalog and urged organizations to patch immediately, enable AMSI in Full Mode, and closely monitor affected servers.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
When it comes to severity, Taylor points out that this month “has 26 vulnerabilities with a CVSS base score above 9.0, and 13 of those sit at 9.8.”
Still, Taylor says CVSS scoring is only one part of the risk story.
“The real triage problem this month is the mix of exploited issues, a publicly disclosed BitLocker flaw, and a massive concentration of vulnerabilities in Windows and Office,“ he says.
Microsoft warns Patch Tuesday updates will keep growing
The unprecedented release comes just days after Executive VP of Windows + Devices Pavan Davuluri warned security teams to expect a dramatic increase in Patch Tuesday's size due to the integration of AI-assisted vulnerability discovery.
Microsoft said the larger releases do not necessarily mean Windows is becoming less secure, but reflect its ability to find and fix more flaws before attackers can exploit them.
The anticipated changes have also led security experts to speculate that the Patch Tuesday format, as it exists today, may eventually disappear altogether.
Instead, Microsoft’s monthly release cycle could evolve into a more user-friendly rolling release model to accommodate the large volume of newly uncovered security vulnerabilities, fixes, and public disclosures, they say.
Kerberos enforcement phase officially begins
Besides the record-breaking number of patches, Microsoft's July update begins enforcing the transition away from legacy RC4 encryption for Kerberos, the authentication protocol used by Active Directory to verify users and services across Windows domains.
As part of the new update, Windows domain controllers will no longer fall back to RC4-based Kerberos tickets when no explicit configuration exists.
Instead, organizations will be forced to move supported Kerberos configurations to stronger, industry-standard AES-256 based encryption.
The enhanced encryption is aimed at preventing threat actors from carrying out credential-recovery attacks, which often involve cracking stolen credentials offline using brute-force techniques.
Microsoft warns that after installing the update, organizations still relying on RC4-based service accounts, legacy applications, or non-Windows integrations will experience Kerberos authentication failures.
Dell compatibility issue delays update for some PCs
One important note for Dell users finds Microsoft temporarily pausing the Windows 11 security update for some Dell devices with Intel processors.
Microsoft says the update could trigger unexpected shutdowns, degraded performance, overheating, and battery drain. The company said it is working with Dell on a fix before resuming the rollout.
Microsoft and Dell have not yet published a list of the affected models or provided a timeline for resuming the update.
Has your password leaked?