Blog / Patching & Vulnerability Management
570 flaws, 3 zero-days, and a BitLocker bypass: why July’s Patch Tuesday is a wake-up call for unmanaged businesses
Most small businesses think about Windows Update about as often as they think about the building’s sprinkler system — it’s just supposed to work, quietly, in the background. Then a month like July comes along. On July 14, Microsoft shipped its monthly security update and, according to reporting from BleepingComputer, it fixed a record 570 separate flaws — including three zero-day vulnerabilities, two of them already being used in attacks.
That number is the story. Not because you need to understand all 570 — nobody does — but because it makes something concrete that’s usually invisible: the sheer volume of holes being patched in the software your business runs every day, and the fact that some of them are being exploited before the fix lands. “It updates automatically, we’re fine” is a comfortable assumption. A 570-fix month is a good moment to check whether it’s true.
What was actually in this batch
A “zero-day” is a flaw that’s already known to attackers (or the public) before or as the patch arrives — so the window to get exploited isn’t theoretical, it’s open right now. We wrote a plain-English explainer on what zero-days mean for business owners if you want the background. July’s three:
- CVE-2026-56155 — an elevation-of-privilege flaw in Active Directory Federation Services, reported as actively exploited in attacks.
- CVE-2026-56164 — an elevation-of-privilege flaw in SharePoint Server, also reported as actively exploited.
- CVE-2026-50661 — a BitLocker Security Feature Bypass, publicly disclosed. Per Microsoft’s description, an attacker with physical access to the device could use it to reach data on an encrypted drive. It wasn’t reported as exploited in the wild — but a public disclosure means the details are out there.
Notice the pattern: none of these are exotic. They’re in the ordinary plumbing of a Windows business network — identity services, a collaboration server, and full-disk encryption. This is where real attacks live, not in movie-plot exploits.
Why 570 is the real headline
Here’s the uncomfortable math for an unmanaged office. Microsoft ships a batch like this every month. Somewhere in it are the handful of fixes that actually matter to your systems — the CVEs that apply to the exact versions of Windows, SharePoint, or the server roles you happen to run. The other 560-odd don’t. Without an inventory of what you’re running and a process to match it against each month’s fixes, there’s no way to tell the difference. You’re left with two bad options: assume Windows Update caught everything, or try to read a 570-item security bulletin yourself.
And the actively-exploited zero-days are exactly why “we’ll patch eventually” has stopped being safe. When attackers are already using a flaw the day the fix appears, the gap between “patch released” and “patch installed” is the gap they walk through. We’ve watched this window collapse all year — from the firewall flaw exploited four days after its patch shipped to AI-run ransomware that punishes slow patching at machine speed. Volume plus speed is the whole problem, and it’s not going back down.
The checklist: how a patch process actually handles a month like this
Managed patching isn’t “turn on automatic updates and hope.” It’s a repeatable process, and it’s most of what separates a client we manage from an exposed office. When a batch this size lands, here’s the work:
- Inventory what you run. You can’t patch — or prioritize — what you can’t see. The first step is a current picture of every OS version, server role, and business application across the fleet.
- Prioritize the actively-exploited CVEs. The two exploited zero-days this month jump the queue. The other 568 fixes matter, but they don’t all matter today. Triage is the entire value.
- Test, then deploy. Roll updates to a pilot machine or group before the whole office, so a bad patch misbehaves on one PC instead of twenty. We covered why this matters in our guide to managing Windows 11 updates for business.
- Verify — don’t assume — that patches landed. “Windows Update says it’s up to date” and “every machine actually installed this month’s critical fixes” are not the same statement. Confirming the second one is the difference between being patched and believing you are.
For businesses on our managed IT plans, that’s not a to-do list they got handed on July 14 — it’s work that was already done before most of our clients had heard the number 570. That’s the quiet part of managed IT: the goal is for a scary Patch Tuesday to be a non-event for you because it was a normal Tuesday for us. Behind it sits managed endpoint detection and response, which watches for the behavior of an attack even when a not-yet-patched flaw slips through.
A word on that BitLocker bypass
The encryption flaw (CVE-2026-50661) is worth a specific note, because encryption is where patching and data recovery meet. BitLocker and other full-disk encryption exist so that a lost or stolen laptop is a hardware loss, not a data breach. A bypass that lets someone with physical access reach the data chips away at exactly that protection — which is why keeping the encryption layer patched is part of keeping it trustworthy.
The flip side of strong encryption is that it protects data from you just as well when something goes wrong — a failed self-encrypting drive, a forgotten key, a lock you can’t clear. That’s a data-recovery problem, and it’s handled by our sister company, Desert Data Recovery, which works on self-encrypting and locked drives when encryption stands between a business and its own data. The division of labor is simple: ioLogik keeps the patch-and-encryption layer healthy so it protects you; Desert Data Recovery is who you call when an encrypted drive fails or locks you out.
The bottom line
One record-breaking month doesn’t mean the sky is falling — Windows is heavily used and heavily scrutinized, and a big patch count partly reflects that scrutiny working. Skipping updates is far more dangerous than installing them. The point of 570 is what it reveals: patching at this scale and speed isn’t something an unmanaged office can do reliably by reflex, and the actively-exploited flaws don’t wait for anyone to get around to it.
If you’re not sure whether last month’s critical fixes actually made it onto every machine in your office — or who’d be triaging next month’s batch — talk to us. We’ll tell you where you stand, and there’s no pressure either way.