← All posts

Microsoft Just Dropped 570 Patches in a Single Day. Your Board Needs to Know Why.

On July 14, Microsoft released fixes for approximately 570 vulnerabilities in its own products — the largest Patch Tuesday in the program's history. Two of those flaws were already being exploited in the wild. CISA gave federal agencies three days to patch the worst one.

Three days.

I want you to sit with that number, because it tells you something important about where we are. Not about patching. About the pace of the game itself.

The Machine That Finds More Holes Than Humans Can Fill

Here's what most of the coverage missed. The reason July's count tripled June's record of 206 isn't that Microsoft's code suddenly got three times worse. It's that Microsoft deployed an AI system called MDASH — a multi-model agentic scanning harness — that orchestrates over 100 specialized AI agents to hunt for exploitable bugs across the Windows codebase. In May, MDASH found 16 previously unknown vulnerabilities in the Windows networking and authentication stack alone, including four critical remote code execution flaws.

Microsoft told customers to expect higher volumes going forward. Their words, not mine.

In my experience advising organizations through incidents, the hardest conversation isn't about a single vulnerability. It's about capacity. Every security team I've worked with has a finite number of patches they can test, stage, and deploy in a given window. When that window held 50 to 70 CVEs a month, most teams could keep up. At 570, the math breaks.

The question your CISO should be bringing to the board: how do we decide what not to patch — and who owns the risk of what we defer?

The Three-Day Deadline That Changed the Rules

The SharePoint Server zero-day — CVE-2026-56164 — deserves special attention. It's a missing-authentication vulnerability, meaning an attacker doesn't need valid credentials to exploit it. No phishing required. No stolen passwords. Just a vulnerable SharePoint server exposed to the network.

CISA added it to the Known Exploited Vulnerabilities catalog on July 14, the same day the patch shipped, and set a remediation deadline of July 17 for all Federal Civilian Executive Branch agencies. Three calendar days, including a weekend.

If your organization does business with the federal government, that deadline matters to you whether you're a federal agency or not. And if you're not subject to CISA's binding directives, ask yourself a different question: if the federal government considers three days an acceptable window for a vulnerability this severe, what's your window? If the answer is "we'll get to it in the next maintenance cycle," you have a gap between your risk posture and the threat environment.

This is the kind of moment I write about in Cyber Risk Is Business Risk when I talk about the Three Questions framework. What can go wrong? An unauthenticated attacker gains elevated privileges on your SharePoint server — the system that probably holds your board documents, your M&A files, your strategy decks. How likely is it? CISA confirmed active exploitation before the patch even shipped. What would it cost? That depends on what's sitting on your SharePoint instance, but if the answer is "I don't know," that's its own problem.

AI Is Finding Bugs Faster Than Teams Can Fix Them

Microsoft's MDASH system isn't a one-off experiment. It scored 96.55% on the CyberGym industry benchmark, and Microsoft is expanding it across the Windows codebase with Defender Portal integration announced at Build 2026. Other major vendors will follow — they have no choice. The competitive pressure to find and disclose vulnerabilities before attackers do will drive every major software company to deploy similar AI-powered scanning.

What does that mean for you? The patch treadmill is about to speed up permanently. June was 206 CVEs. July was 570. Microsoft's own engineers have said they expect 100-plus CVEs per month to become the floor, not the ceiling.

This is a resource allocation problem that belongs in the boardroom, not the SOC. In my experience, the organizations that handle this well do three things:

They triage ruthlessly — the team has board-backed authority to accept risk on low-impact vulnerabilities rather than chasing a patch-everything fantasy.

They fund the tooling — automated patch management, asset inventory that actually reflects reality, and vulnerability prioritization that accounts for what's exposed and what's being actively exploited.

They measure what matters — mean time to remediate actively exploited vulnerabilities, not "percentage of patches applied." The first metric rewards judgment. The second rewards busywork.

What to Ask Your CISO This Week

If you're a board member or executive reading this, here's the conversation to have before your next committee meeting:

"Our primary software vendor just shipped 570 patches in a single day, and the government gave agencies three days to apply the most critical one. Walk me through how our team triages that volume. What gets patched first, what gets deferred, and who owns the risk of what we defer?"

If your CISO can answer that clearly, you're in better shape than most. If the answer involves a lot of hand-waving about "following best practices," dig deeper. Best practices were designed for a world where Patch Tuesday meant 70 fixes, not 570.

That world ended on July 14.