Skip to main content

Morning Overview

Microsoft just fixed a record 570 security holes, and hackers were already exploiting three

Every IT administrator running Microsoft software now faces a sprint to patch after the company released fixes for 570 security vulnerabilities in a single monthly update, the largest batch on record. Federal cybersecurity records confirm that attackers were already exploiting at least three of those flaws before patches became available, turning what would normally be routine maintenance into an urgent defensive operation for businesses, government agencies, and individual users alike.

Why 570 patches in one release changes the risk calculation

The sheer volume of fixes is not just a headline number. When Microsoft ships hundreds of patches at once, security teams at every organization must sort through them, test compatibility, and deploy updates across networks that can span thousands of machines. That process takes time, and attackers know it. The presence of three vulnerabilities already under active exploitation compresses the window between disclosure and real damage.

Two of those actively exploited flaws are documented in federal government databases. CVE-2026-56155 carries an active exploitation marker in the National Vulnerability Database, complete with a CISA timestamp confirming that the agency verified real-world attacks. CVE-2026-56164, a separate flaw tied to Microsoft SharePoint, holds the same designation in its own NVD record, with KEV inclusion and a direct link to Microsoft’s remediation guidance. Both entries point back to Microsoft vendor advisories, creating a clear chain from federal confirmation to corporate fix.

The pattern here is telling. Multiple flaws flagged as actively exploited landing inside a single Patch Tuesday cycle suggests that threat actors are not stumbling onto isolated bugs. They appear to be conducting faster reconnaissance of enterprise update schedules, identifying and weaponizing vulnerabilities in the gap between discovery and patch deployment. Organizations that treat monthly updates as routine housekeeping rather than a security event are the ones most exposed.

Federal records trace the exploitation chain

The strongest evidence for active exploitation comes from two federal institutions. CISA, the U.S. Cybersecurity and Infrastructure Security Agency, maintains the Known Exploited Vulnerabilities catalog, the authoritative public list of software flaws confirmed to have been used in attacks outside of research settings. Inclusion in this catalog is not speculative; it requires evidence that a vulnerability has been exploited against real targets.

The National Vulnerability Database, operated by NIST, provides the technical backbone. Each CVE entry includes severity scores, affected product details, and structured metadata. For CVE-2026-56155, the NVD record includes a CISA exploitation flag with a timestamp, meaning the agency reviewed evidence and confirmed active attacks at a specific point. The record also links directly to Microsoft’s own advisory, giving administrators a single path from federal alert to vendor patch. CVE-2026-56164 follows the same structure, with KEV inclusion noted and exploitation status marked as active.

This two-layer verification system, where CISA confirms exploitation and NIST catalogs the technical details, gives the claims about active attacks a high degree of reliability. These are not researcher-reported theoretical risks. They are flaws that someone, somewhere, has already used to compromise systems.

The practical effect is straightforward. Federal civilian agencies are typically required to patch KEV-listed vulnerabilities within tight deadlines. Private organizations face no such mandate, but the same risk applies. Every day a system remains unpatched against a KEV-listed flaw is a day that known attack techniques can be used against it.

Three gaps in the public record that IT teams should track

The available federal records confirm active exploitation for CVE-2026-56155 and CVE-2026-56164, but the identity of the third exploited vulnerability has not been verified through the primary sources reviewed here. No NVD record or CISA catalog entry in the available evidence set names a third specific CVE with the same exploitation confirmation. Organizations should monitor the KEV catalog directly for updates, as CISA adds entries on a rolling basis rather than on a fixed schedule.

A second open question involves attribution. The NVD records and CISA catalog confirm that exploitation occurred, but neither source publicly identifies who carried out the attacks, what sectors were targeted, or how widespread the campaigns were. That kind of detail sometimes emerges weeks or months later through incident response reports or threat intelligence briefings, but right now the public record stops at “exploitation: active.”

The third gap is Microsoft’s own public posture. The NVD records link to Microsoft vendor advisories for both confirmed CVEs, but no direct statement or quote from Microsoft acknowledging prior exploitation of these specific flaws appears in the available primary documentation. Microsoft’s Security Response Center typically publishes its own exploitation assessments alongside each patch, and those pages will be the next place to watch for confirmation or additional context.

For IT teams and security professionals, the immediate action is clear: prioritize patching CVE-2026-56155 and CVE-2026-56164 above the other items in this month’s release. Both carry federal confirmation of active exploitation, both link to Microsoft remediation guidance, and both sit inside a record-sized patch batch that will strain update workflows. Organizations should check the CISA catalog daily over the coming weeks to see whether additional Microsoft vulnerabilities from this release are added to the list of known exploited flaws.

How to triage this month’s Microsoft updates

Faced with 570 separate fixes, many organizations will not be able to treat every patch as equally urgent. A structured triage process can help. First, identify all systems running products affected by CVE-2026-56155 and CVE-2026-56164, using asset inventories and configuration management tools where available. Those systems should be placed in the highest-priority group for immediate patching or compensating controls.

Second, group the remaining patches by exposure. Internet-facing services, remote access tools, and collaboration platforms such as SharePoint or Exchange should be next in line, because they provide the most direct path for external attackers. Internal-only services and workstation software can follow, with additional testing for business-critical applications that are sensitive to configuration changes.

Third, define clear maintenance windows and rollback plans. The risk of exploitation is real, but so is the risk of downtime from a failed update across thousands of endpoints. Standard practices such as phased rollouts, pilot groups, and snapshot-based backups can reduce the impact of any unforeseen compatibility issues while still moving quickly enough to close the most dangerous holes.

Operational pressure on security and IT teams

A release of this size places unusual pressure on organizations that are already stretched thin. Security teams must analyze vulnerability details, map them to internal assets, and communicate risk to business leadership. IT operations must schedule and execute deployments, often outside of normal business hours to minimize disruption. Help desks must prepare for a spike in user questions and potential issues after patches are applied.

This operational burden can tempt organizations to delay updates until the next quarter or to focus only on a small subset of systems. In the context of confirmed exploitation, that delay carries its own liability. If attackers are already using CVE-2026-56155 and CVE-2026-56164 in the wild, unpatched systems effectively represent known, documented entry points into the network.

One practical response is to formalize a “rapid patch” track for vulnerabilities with federal exploitation confirmation. Under this model, any flaw that appears in both the NVD with a CISA flag and the KEV catalog automatically triggers an accelerated patch cycle, with pre-approved maintenance windows and streamlined testing for affected systems. That kind of policy-based approach can help organizations respond consistently even when individual staff members are overloaded.

What comes next

Over the next several weeks, more detail is likely to emerge about how these vulnerabilities were discovered, how attackers are exploiting them, and which sectors are being targeted. Threat intelligence vendors and incident response firms often publish technical analyses once organizations have had time to apply patches and share anonymized data. Those reports may eventually fill in some of the gaps that currently exist around attribution and attack scale.

In the meantime, the public record is clear enough to guide action. Two Microsoft vulnerabilities from this record-setting patch release are confirmed as actively exploited, with federal agencies and NIST documenting both the technical details and the exploitation status. A third exploited flaw is referenced but not yet clearly identified in those same sources, underscoring how quickly the situation can evolve.

For administrators, the lesson is not just about this month’s 570 patches. It is about treating every Patch Tuesday as a potential incident response event, especially when federal data shows that attackers are already ahead of the update cycle. Organizations that build repeatable processes for rapid triage, prioritized deployment, and continuous monitoring will be better positioned not only to handle this surge of fixes, but also to withstand whatever comes with the next one.

More from Morning Overview

*This article was researched with the help of AI, with human editors creating the final content.