This week was a busy one. Microsoft broke patch records and new data confirmed that attackers are getting into networks through identity and not vulnerabilities. Here is what you need to know.
Microsoft’s Largest Ever Patch Tuesday Includes Two Zero-Days Already Under Attack
Microsoft’s July 2026 Patch Tuesday was the biggest on record. It covered 622 CVEs — more than triple June’s previous high of around 200. However, the sheer volume isn’t the story. Two of those fixes close holes that attackers are already exploiting.
Both are elevation-of-privilege flaws. First, CVE-2026-56164 affects on-premises SharePoint Server. Specifically, it lets an unauthenticated attacker escalate privileges remotely with no user interaction required. Microsoft credited discovery to Mandiant incident responders — a strong signal this was found inside active attacks. Furthermore, SharePoint 2016 and 2019 reached end of extended support on the same day, leaving unpatched servers with no safety net.
Second, CVE-2026-56155 affects Active Directory Federation Services. Unlike the SharePoint bug, this one requires an authenticated attacker. Nevertheless, AD FS signs the tokens for everything else in the estate — meaning a privilege gain there reaches far wider than the label suggests. Microsoft’s own incident response team discovered it.
A third notable fix was also included. Rapid7 chained CVE-2026-55040, a JWT authentication bypass in SharePoint, with a separate RCE flaw to achieve unauthenticated remote code execution at Pwn2Own Berlin. The bypass is now patched. The RCE half, however, is not. Microsoft has slated that fix for August.
Additionally, the July update removes the Kerberos RC4 rollback switch permanently. Any service account still relying on RC4 Kerberos tickets may break authentication after patching. Audit service accounts before deploying.
Microsoft Patch Tuesday – TL;DR
Microsoft patched a record 622 CVEs this month. Two zero-days, in SharePoint and AD FS, are already being exploited in the wild. Patch both immediately, audit service accounts before the Kerberos RC4 change lands, and don’t wait for CISA’s KEV to confirm. Both flaws are confirmed exploited by Microsoft itself.
Identity Has Overtaken Exploits as the Leading Cause of Ransomware
Sophos’ State of Ransomware 2026 report, published 15 July, surveyed 2,158 IT and security leaders across 17 countries. The findings mark a significant shift. For the first time in three years, ransomware identity attacks in 2026 have overtaken vulnerability exploitation as the leading entry point.
Specifically, malicious email accounted for 26% of ransomware root causes. Phishing followed at 24%. Together, they make up exactly half of all cases. Meanwhile, vulnerabilities fell sharply, from 32% down to 18%. Compromised credentials ranked third at 23%.
What makes the identity finding particularly alarming is the MFA data. In 97% of credential-based ransomware attacks, MFA was already deployed. It failed anyway. Sophos attributes this to two factors. First, MFA was often not deployed consistently across all relevant systems. Second, bypass techniques have matured significantly. One-time passwords and push-based MFA are increasingly defeated by adversary-in-the-middle tooling.
Consequently, experts are recommending a shift from MFA as a standalone control to a broader identity threat detection and response (ITDR) strategy. Sophos also highlighted that the best-performing organisations combined MFA with segmentation, ZTNA to replace legacy VPNs, and 24/7 threat detection. In other words, MFA is still necessary, but it is no longer sufficient.
Identity & Ransomware – TL;DR
Phishing and malicious email now cause 50% of ransomware attacks, overtaking vulnerability exploitation for the first time. MFA was present in 97% of credential-based cases, and still failed. The shift is clear: layered identity defences and ITDR are now essential, not optional.
Conclusion
This week’s stories share a common thread: attackers are finding gaps in the foundations, core platforms, identity infrastructure, and the trust we place in widely-used software. Patching fast, auditing identities, and hardening endpoints remain the most reliable response. ThinScale helps organisations secure the endpoint layer where many of these threats land first. Get in touch to find out how.


