Patchy Chaos: Microsoft Sets New Record with 622 Bug Corrections

Patching Records Like It’s a Fad

Recall last month when we were astounded by Microsoft’s patch extravaganza with 206 CVEs? That was merely a warm-up for this month. Microsoft has just launched patches for an astounding 622 CVEs related to its products, tripling the previous month’s record. Redmond’s Patch Tuesday release is shattering records with an abundance of fixes, including 428 non-Microsoft Chromium CVEs impacting Edge that don’t even factor into that 622. Fifty-eight of those are critical, two are currently under active exploitation, and one has been publicly revealed, making it a race against the clock. With such a vast amount to sift through, we can’t tackle everything, but as noted last month, there was buzz about AI-assisted bug hunting potentially making large patch workloads the new standard. Microsoft hasn’t disclosed how much AI contributed to this patch spree, but given this magnitude, it’s reasonable to say the humans received some robo-support.

Microsoft’s Gigantic Patch Month

Exploited Issues – Fix ‘Em Quickly

First, let’s discuss the actively exploited vulnerabilities that Microsoft has tackled. The first, CVE-2026-56155, is a privilege escalation vulnerability in Active Directory Federation Services. Attackers exploiting this vulnerability could gain admin rights, but they require local access first, which is reflected in the CVSS score of 7.8.

The second exploited vulnerability is CVE-2026-56164, another privilege escalation flaw, but in Microsoft SharePoint. Lack of authentication for a vital function could enable an unauthorized attacker on the network to elevate their SharePoint permissions. This one scores only 5.3, but don’t let that provide a false sense of security – patch it immediately!

Regarding the publicly acknowledged but not-yet-exploited issue, CVE-2026-50661, it pertains to BitLocker being bypassed by anyone with local access to a BitLocker-secured system. Implement those patches before someone has a field day with your information!

Critical and Baffling Vulnerabilities

Our favorite unreliable AI, Copilot, features a CVSS 9.6 remote code execution vulnerability. CVE-2026-48561 has Copilot inadequately neutralizing its input, allowing attackers to execute code with basic Hyper-V guest access. Remind you of leaving your front door wide open?

Microsoft Exchange has its own set of problems with a CVSS 9.6 spoofing vulnerability due to failure to neutralize input, leading to potential cross-site scripting via a malicious email. CVE-2026-55008 allows an attacker to spoof over a network and execute arbitrary JavaScript.

And not to be outdone, Microsoft Office has a collection of 16 remote code execution vulnerabilities of its own, resulting from issues like heap-based buffer overflow and use-after-free vulnerabilities, all scored around CVSS 7.8.

Adobe Joins the Patch Fest

While Microsoft is stealing the spotlight with over 600 CVEs, Adobe is also stepping up with 64 CVEs spread across seven bulletins. From Commerce to Animate, they’ve got challenges in every section of their ecosystem.

ColdFusion takes home the highest score with a CVSS 9.9 path traversal vulnerability that enables arbitrary code execution. CVE-2026-48318 isn’t in the directories yet, but a 9.9-level issue? Patch it faster than a Jack Russell pursuing a squirrel!

Close behind is Commerce with a CVSS 9.6 privilege escalation vulnerability due to unrestricted perilous file uploads. Adobe Experience Manager also includes a couple of CVSS 9.6 issues that permit full code execution due to a server-side request forgery vulnerability and improper XML handling.

Other Patch Tuesday Highlights

Broadcom’s Avi Load Balancer resolved seven CVEs with CVSS scores ranging from 7.1 to 9.8, addressing problems from authentication bypass to directory traversal.

SAP is active as well, with 16 updates and a GitHub advisory. Nine of these updates have scores exceeding 8.1, including a memory corruption issue in NetWeaver and an HTTP request smuggling vulnerability in SAP Approuter.

Summary: Patch-tastic Journeys – Who Needs Sleep Anyway?

Let’s hope August is a bit calmer, shall we? With two record-setting months back-to-back, sysadmins and security teams will need a lengthy rest. Good luck out there!