Filed under: Cybersecurity · Patching · July 2026

What happened

On July 14, 2026, Microsoft released its monthly “Patch Tuesday” update — the largest in the company’s history, fixing a record 570 security flaws. Two of them are already being used in real attacks: a privilege-escalation bug in Active Directory Federation Services (CVE-2026-56155) and one in SharePoint Server (CVE-2026-50661 — a BitLocker bypass — was publicly disclosed but not yet exploited). More important for most small offices, the same update quietly fixes several “critical” flaws in Excel, Word, and PowerPoint that could let a booby-trapped document run malicious code the moment it’s opened, plus critical Windows bugs in DHCP and graphics.

Why it matters to your business

Every Phoenix small business runs Windows and Office, so this update touches essentially every PC in your office. The scary-sounding zero-days are in server products (AD FS and SharePoint) that most small firms don’t run on their own hardware — but the very same July patch closes the Office and Windows holes on your everyday laptops and desktops. A single un-patched machine where someone opens an emailed spreadsheet can be all an attacker needs to get a foothold, then move to your files, QuickBooks, and email.

What to do this week

Install the July updates on every computer now: Start → Settings → Windows Update → Check for updates, then reboot when prompted (the fixes don’t fully apply until you restart). Update Office too — in any Office app go to File → Account → Update Options → Update Now. If any machine is still on Windows 10, know that it stopped getting free security updates in October 2025 — those PCs should be upgraded to Windows 11 or replaced, because they will not receive these fixes. Turn on automatic updates so you’re not doing this by hand each month (Settings → Windows Update → Advanced options). If you happen to run SharePoint Server or AD FS on-premises, patch those immediately or call us — those are the ones already under active attack.

The bigger picture

A record-breaking patch is a reminder that the number of flaws keeps climbing, and attackers move within days of each release to hit whoever hasn’t updated yet. Staying patched on a schedule is the cheapest, highest-return security work you’ll ever do — far cheaper than cleaning up after the one machine everyone forgot. Proactive vs. Reactive IT Management: Lessons from Healthcare for SMBs

Confident every computer in your office actually installed this month’s updates? Book a free consult → https://micro1tech.com/contact/