Microsoft's July update is one of the biggest of the year, fixing a record 570 security flaws across Windows, Office and related services, including two vulnerabilities that attackers are already using.
- What it is: This month's Patch Tuesday release addresses 570 vulnerabilities, 59 of them rated critical, plus two zero-day flaws in Active Directory Federation Services and SharePoint Server that are being actively exploited, and a publicly disclosed flaw in Windows BitLocker.
- Who is affected: Any business running Windows, Microsoft 365 Apps, or on-premises servers using Active Directory Federation Services or SharePoint Server.
- The risk: Unpatched systems are exposed to attackers who can gain access, escalate privileges, or bypass BitLocker disk encryption on devices that fall into the wrong hands.
- What to do: Updates roll out automatically through Windows Update and Microsoft 365 Apps update channels for most small businesses. We recommend confirming your devices have installed the July updates and are not showing a pending restart.
Businesses on a managed update plan do not need to take any action, updates are already being applied. If you manage your own devices, install this month's updates as soon as possible.