In May 2026, Microsoft announced it had built an AI system that hunts for security flaws in its own software, and warned customers that security updates would get bigger as a result. Two months later, its July update fixed a record 622 vulnerabilities in a single day, roughly triple the previous month. Two of those flaws were already being used in real attacks before the fix existed.
If you lead a business that runs on Microsoft (Windows, Office, SharePoint, Azure), this isn’t an IT news item. It’s a change in the operating environment your company runs on, and it raises questions most leadership teams haven’t asked yet.
To see how sharp the shift is, here’s what a normal month looked like just weeks earlier:
| May 2026 | June 2026 | July 2026 | |
| Security fixes released | ~130 | ~206 | 622 |
| What it signaled | Normal month | New record | AI-driven volume is here |
The AI system behind the surge (over 100 specialized AI agents auditing Microsoft’s own code) found 16 previously unknown Windows flaws in its first public outing. Microsoft then told customers plainly: as AI finds more issues, every release will contain more fixes. July proved the point. Flaws found by Microsoft are flaws attackers don’t find first, which is genuinely good news. The catch is that fixes now arrive faster, and in far bigger piles, than most mid-size businesses’ routines were built to handle.
The Five Takeaways That Matter
1. The patching workload just tripled.
Microsoft has told customers directly to expect larger security releases from now on, because AI is finding flaws faster than human review ever could. July isn’t a spike to wait out. It’s the new baseline.
Most mid-size businesses built their update routine (who handles it, when, how it’s tracked) around a workload of 100 to 150 fixes a month. That routine doesn’t break loudly when the volume triples. It breaks quietly: things get deferred, queues grow, and the dangerous fixes sit next to the trivial ones. The question for leadership: was our process designed for the volume that’s now arriving, and would we know if something slipped through?
2. “We patch monthly” is becoming a liability.
The traditional rhythm (updates land, IT gets to them at the next maintenance window) was built for an era of 100 to 150 fixes a month. Security experts now expect Microsoft to move toward rolling updates that arrive closer to real time, and guidance is already shifting toward deploying fixes within days, not weeks. In July, Microsoft patched 2 zero-day exploits.
For regulated industries this matters beyond security. Healthcare groups under HIPAA, defense suppliers working toward CMMC, and any firm facing a cyber insurance renewal will recognize the question “how quickly do you remediate known vulnerabilities?” It’s standard on applications and audits, and a monthly answer is starting to read as a documented weakness.
3. Severity scores are no longer a safe shortcut.
Here’s the detail that should change how you talk to your IT team. Of July’s 622 fixes, one of the two flaws attackers were actively exploiting (in SharePoint Server) carried only a “Moderate” severity score. Any business that told IT “just rush the Critical ones” would have skipped the exact flaw being used in real attacks.
The right question for your IT lead or provider isn’t “are we patched?” It’s “how do you decide what gets patched first?” If the answer is a severity score alone, there’s a gap. The correct answer involves tracking which flaws are actually being exploited in the wild.
4. Attackers have the same AI tools.
Microsoft’s own threat intelligence reports that criminal groups are also using AI to accelerate finding and exploiting flaws, which means the window between a vulnerability becoming public and being weaponized keeps shrinking.
It’s also why “we’re too small to be a target” no longer holds. AI-driven scanning is automated and indiscriminate. A 40-person logistics firm near the ports, a mid-size medical group, or an entertainment vendor running an exposed SharePoint server carries the same exploitable flaw as a Fortune 500 running the same version. The scan doesn’t check your headcount.
5. The one question to ask this week.
“Did our July patch cycle cover the two actively exploited flaws (in Active Directory Federation Services and SharePoint Server), and how do we know?”
If nobody in your organization can answer with a date, that’s your finding. Both flaws were serious enough that the U.S. Cybersecurity and Infrastructure Security Agency added them to its catalog of vulnerabilities confirmed to be used in attacks.
What This Means for Southern California’s Mid-Market
Los Angeles and the surrounding region run heavily on exactly the Microsoft infrastructure in the crosshairs. Entertainment and production vendors, healthcare groups, port-adjacent logistics and trade firms, aerospace suppliers, and professional services firms all tend to share two traits:
- They run internet-facing Microsoft systems (SharePoint, remote access, identity services) without a dedicated security team watching exploitation status daily.
- Several carry compliance or insurance obligations where patching speed is now an auditable question, not an internal preference.
That combination is precisely where a tripled patch volume does damage. The risk isn’t the flaws everyone hears about; it’s the ones that sit in a queue during a busy month.
Two Ways to Handle It
Keep it internal. If your IT staff can triage by real-world exploitation status rather than patching everything on one schedule, you’re ahead of most. Just confirm July’s two exploited flaws didn’t slip through.
Have it managed. If patching has been “next maintenance window” regardless of what’s actively under attack, this is the year that habit catches up. A managed partner tracks exploitation status continuously and patches actively attacked flaws first, at a cadence that scales with release volume instead of a fixed calendar.
How Crimson IT Approaches This
Crimson IT treats patch management as a security discipline, not a maintenance checkbox:
- Exploitation-first triage. Actively attacked flaws get patched first, regardless of severity score.
- Cadence that scales. Patch schedules flex with actual release volume, not a fixed calendar.
- Priority on internet-facing systems. SharePoint, identity services, and other externally reachable infrastructure get direct oversight, because that’s where automated attacks look first.
- Clear reporting. You know what’s patched, what’s pending, and why, in language you can hand to an auditor or insurer.
Not sure whether your July patch cycle caught the two exploited flaws? Request a patch-status review and we’ll confirm it in one call.






