Skip to content
Rush Commerce
Software & Dev3 min read

621 CVEs in one month: patch by exploitation, not severity

Microsoft shipped 621 CVEs in July 2026 and three mattered on day one. How to triage a patch backlog when the volume has outgrown your change window.

If your patch policy is "apply everything rated Critical," the arithmetic stopped working sometime this year. Microsoft's July release was the largest on record, and the gap between how many vulnerabilities shipped and how many were being used against anyone has become the only number worth acting on.

What actually happened

The Zero Day Initiative's July 2026 security update review counted 621 Microsoft CVEs for the month. Sixty-three rated Critical. Six Moderate, one Low, the rest Important.

Two were under active exploitation at release. One other was publicly known. Three, out of 621.

ZDI also noted that the year-to-date CVE count already exceeds every prior full year in a twenty-year comparison. This is not a bad month. It's the new baseline.

Ahead of August's release, Help Net Security published a Patch Tuesday forecast in which Ivanti's Todd Schell argues the volume has broken the traditional model outright. His position: stop treating the patch list as a queue to drain and start treating it as a risk-ranked set — prioritize known-exploited and internet-facing vulnerabilities, then match remaining patches to systems by network exposure and business criticality. Schell attributes the volume growth to AI-assisted vulnerability discovery, which is a reasonable read given how much of this year's disclosure flow has come from automated tooling.

Why patch triage matters for your business

A small business has one change window, usually a weekend, usually one person. Six hundred patches do not fit in it. So the real question is not "did we patch" — it's "what did we choose not to patch, and did we choose on purpose."

Three filters, in order:

  1. Known exploited. CISA's KEV catalog is the shortest useful list in security. If a CVE is on it and the software is in your environment, that patch jumps the queue regardless of its CVSS score. A 6.5 under active exploitation outranks a 9.8 nobody has weaponized.
  2. Internet-facing. Anything reachable from outside your network — the VPN appliance, the mail server, the CMS, the file transfer box — gets patched before anything that requires a foothold first.
  3. Money and data. Your accounting system, your payment stack, your customer database. These get patched before the conference room display.

Everything else goes on a monthly cadence and you stop feeling guilty about it.

The part people skip: you cannot triage an inventory you don't have. If you can't answer "what versions of what are running where" in under ten minutes, that's the actual project — not the patching. Severity ratings describe a vulnerability in the abstract. Exposure describes it in your building, and only you have that data.

Key takeaways

  • Microsoft shipped 621 CVEs in July 2026 — 63 Critical, 2 actively exploited, 1 publicly known
  • Year-to-date CVE volume already exceeds every prior full year over a 20-year span
  • Severity ratings are a poor queue; known-exploited plus internet-facing is a better one
  • Patch order: KEV-listed, then internet-facing, then money and customer data systems
  • An accurate asset inventory is the prerequisite — you can't prioritize what you can't see

Know what you're running before you decide what to patch. We build asset and dependency inventories that answer "what version, where, exposed how" from one query — so patch decisions take minutes instead of a weekend. See how we build operational tooling or tell us what's in your stack and we'll map the exposure.

Sources: Zero Day Initiative, Help Net Security.

  • #patching
  • #vulnerability-management
  • #security
  • #microsoft
  • #operations
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.