Robotics & Physical AIJul 14, 2026

Patch now: record 570 Microsoft fixes, and CISA flags actively exploited AD FS, SharePoint, and SonicWall flaws

Microsoft's July Patch Tuesday shipped fixes for a record ~570 security flaws. The same day, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: Microsoft AD FS (CVE-2026-56155), SharePoint Server missing authentication (CVE-2026-56164), and two SonicWall SMA1000 flaws (SSRF and code injection). KEV listing means US federal agencies are required to remediate on a deadline — and everyone else should treat it as a patch-first list.

What it means If you run AD FS, SharePoint, or SonicWall appliances, these are known-exploited-in-the-wild — patch before the weekend, not after.

Where it came from CISA / Microsoft

Back to the Stream