622 CVEs: Prioritize Over Panic Patching
Microsoft’s July 2026 Patch Tuesday lists 622 CVEs – record volume. Anyone planning everything “immediately” is courting chaos. Those prioritizing AD FS (Active Directory Federation Services), On-Premises SharePoint and physically accessible endpoints first steer the change window.
Key Takeaways
- First exploit signal. Actively exploited AD FS and SharePoint vulnerabilities ahead of breadth and CVSS racing.
- Then exposure. Internet-facing and identity stack before internal clients without a lateral path.
- BitLocker and Client EoP (Endpoint Protection) tracked separately. Physical access and local privileges require separate owners and separate change windows.
Related:
SharePoint JWT Bypass Opens On-Premises Sites / BitLocker Bypass via Physical Access
Why 622 Isn’t a Patch Strategy
What is Patch Tuesday prioritization? Patch Tuesday prioritization sorts monthly Microsoft updates by proven exploitation and attack surface rather than by CVSS score or catalog order. Actively exploited gaps in internet-facing identity and collaboration systems take priority, with breadth following in rings. The goal is reliable P0 coverage within the tight change window, not completing an entire catalog in 48 hours.
On July 14, 2026, Microsoft released fixes for 622 vulnerabilities – the largest known Patch Tuesday package – according to the Security Update Guide and industry analyses. Among them are actively exploited gaps in Active Directory Federation Services and on-premises SharePoint Server, publicly discussed BitLocker bypass topics, and hundreds of Windows findings.
Volume creates board pressure and ticket avalanches. It doesn’t create priority. Priority arises from exploit status, accessibility, privilege path, and business impact. Those who process the list linearly burn the scarce change window on client noise, while identity and collaboration stacks remain exposed.
CVEs in July-2026 Patch Tuesday (according to MSRC Security Update Guide and Patch Tuesday analyses, 14.07.2026)
Source: Microsoft Security Update Guide / Patch Tuesday analyses 14.07.2026
Prioritization Ladder for DACH Environments
Stage 1 – actively exploited, both in CISA KEV (Known Exploited Vulnerabilities). AD FS (including CVE-2026-56155 per MSRC Security Update Guide) and SharePoint Server (including CVE-2026-56164) take top priority in every playbook. The attack vectors differ markedly: SharePoint can be attacked unauthenticated over the network, whereas AD FS requires a local foothold with a valid account. For AD FS, the July KB does not resolve the issue alone. It initially audits the ACL of the DKM container, with automatic remediation scheduled only for the October 13, 2026 update. Identity and Document Hubs are the classic pivot for ransomware and data theft. On-premises SharePoint with internet exposure is a separate escalation ticket, not a maintenance item.
Stage 2 – Internet-facing and Hybrid Identity. Exchange, AD FS proxies, reverse proxies, VPN entry points, publicly reachable SharePoint web apps. Here, patching plus hardening is required: shut down unnecessary endpoints, verify MFA and Conditional Access, log for compromise indicators.
Stage 3 – Endpoint and Physical Exposure. BitLocker bypass and local privilege escalation (including publicly discussed PoCs after the patch tag) require separate tracks: laptops with theft risk, admin workstations, jump hosts. This is not the same queue as the SharePoint farm patch.
Stage 4 – Broad Scope. Remaining Windows, Office, and developer tool fixes by asset class and maintenance window. Here automation and ring deployments are used; this does not require the entire incident team’s night.
| Priority | Focus | Owner Type |
|---|---|---|
| P0 | AD FS / SharePoint with Exploit Signal | IAM + Collaboration, 24/48h |
| P1 | Internet-facing Hybrid Stack | Infra + SOC Hunting |
| P2 | BitLocker / Local Endpoint Privilege Escalation (EoP) on High-Risk Hosts | Endpoint + Security |
| P3 | Remaining Scope by Asset Class | Patch Operations / Rings |
Source: SecurityToday Prioritization Model, based on MSRC Exploit Flags July 2026
Controlling Change Windows Instead of Reporting Them
A record Patch Tuesday demands a communications template for leadership and business units: What exactly is a P0, why does it matter, what risk remains until P1, and which systems are frozen. Without this narrative, every ticket escalates at the same volume-and the truly critical stack gets lost.
Technically: Ring 0 for identity and collaboration servers with Pre-Prod Canary, then critical servers, then workstations. Measured by the percentage of patched assets per P‑stage, not just “tickets closed”. SOC works in parallel: hunting for AD‑FS and SharePoint compromise traces from the pre‑patch window, not only after the final client reboot.
RUNBOOK MINIMUM
- ✓P0 Assets inventory (Active Directory Federation Services (AD FS), SharePoint farms, Exposure)
- ✓Canary patch + rollback plan before mass rollout
- ✓SOC hunting queries for pre‑patch windows start
- ✓Board update: P0 status, residual risk, next window
Distinction from Single Advisories
Individual articles on SharePoint-JWT, BitLocker or post-patch PoCs remain valid. This text serves as the prioritization layer on top: how to sort a massive volume of tickets without fragmenting the situation into 622 equally loud items. Those who have already handled the individual topics use them as P0/P2 documentation-not as a replacement for the staircase.
Those who take the staircase separate board communication from the ticket mountain: leadership receives P0 coverage and residual risk instead of the raw count of CVEs. At the same time, the single advisories on SharePoint, BitLocker and post-patch PoCs remain the detailed runbooks. This text merely controls the order within the narrow change window.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Must everything really be done within 48 hours?
No. Prioritize actively exploited and internet-facing identity and collaboration systems first. Scale follows in rings.
Is CVSS sufficient for sorting?
No. Exploit status and exposure outperform pure score lists. A moderate score with active exploitation wins against critical, but isolated client bugs.
Where do I assign BitLocker?
For endpoints that face physical theft or access risk as a separate P2 track—parallel, but not before the P0 identity stack.
What should I report to management?
P0 coverage in percent, open internet-facing assets, residual risk until next window – not the raw number 622.
Does prioritization replace the single-patch article?
No. It controls the order. Technical details remain in the respective advisories and runbooks.
Lesetipps der Redaktion
LesetippCursor startet git.exe aus dem Repo-RootLesetippLegacyHive-PoC trifft frische Windows-PatchesLesetippZwei Joomla-Uploads landen im CISA-KEV
Mehr aus dem MBF Media Netzwerk
cloudmagazinWenn KI-Agenten reisen: Data-Residency als Operating-ProblemMyBusinessFutureMehr Insolvenzen, kleinere Fälle: Was zähltDigital ChiefsToken-OPEX: Inference steuert, nicht das Seat-Budget





