Executive Summary
July 2026 produced an exceptionally large Microsoft security release, but the number of vulnerabilities patched should not dictate patching priority. The Patch Priority Index focuses instead on vulnerabilities that provide meaningful attack paths into enterprise environments and on patches that customers can actually deploy.
This month, perimeter access infrastructure and on-premises SharePoint Server demand immediate attention. SonicWall disclosed two vulnerabilities affecting SMA1000 appliances after investigating active exploitation, while Microsoft addressed multiple SharePoint vulnerabilities that appeared in CISA's Known Exploited Vulnerabilities catalog.
July also contains an unusually strong collection of vulnerabilities in genuine network services. DHCP Server, Windows Server networking, Active Directory Domain Services, and Secure Socket Tunneling Protocol all have vulnerabilities capable of being reached over a network. These should be distinguished from vulnerabilities Microsoft labels 'Remote Code Execution' in Office applications. Office vulnerabilities remain important client-side attack surfaces, but Word, Excel, and PowerPoint are not listening network services.
Public disclosure also changes the priority of two identity-related vulnerabilities this month. CVE-2026-56155 affects Active Directory Federation Services and is being actively exploited, while CVE-2026-54121, dubbed Certighost, now has a public proof-of-concept capable of turning an ordinary domain foothold into a potentially much more serious Active Directory compromise.
Patch Priority Table
The list below ranks the July patching priorities using the PPI criteria established in prior reports: customer actionability, true network exposure, internet-facing deployment, exploitation status, PoC availability, and operational patch value.
| Priority | CVE | Product |
|---|---|---|
1 | CVE-2026-15409, CVE-2026-15410 | SonicWall SMA1000 |
2 | CVE-2026-56164, CVE-2026-50522, CVE-2026-58644 | Microsoft SharePoint Server |
3 | CVE-2026-50518 | Windows DHCP Server |
4 | CVE-2026-56188 | Windows Server Network Driver |
5 | CVE-2026-49164 | Active Directory Domain Services |
6 | CVE-2026-50694 | Windows Secure Socket Tunneling Protocol |
7 | CVE-2026-54121 (Certighost) | Active Directory Certificate Services |
8 | CVE-2026-56155 | Active Directory Federation Services |
9 | CVE-2026-50314, CVE-2026-50467, CVE-2026-55018, CVE-2026-55022, CVE-2026-55045, CVE-2026-55049, CVE-2026-55129, CVE-2026-55056, CVE-2026-55140, CVE-2026-55043, CVE-2026-55123, CVE-2026-55120, CVE-2026-55033, CVE-2026-55127, CVE-2026-55132, CVE-2026-55041 | Microsoft Office / Word / Excel / PowerPoint |
10 | CVE-2026-57092 | Windows VMSwitch / Hyper-V |
Priority Tiers
Tier 1
The SonicWall SMA1000 vulnerabilities should lead July's patching effort. Remote-access appliances occupy one of the most sensitive positions in an enterprise network, and SonicWall has confirmed exploitation associated with CVE-2026-15409 and CVE-2026-15410. Organizations with affected appliances should patch immediately and assess whether exploitation occurred before remediation. On-premises SharePoint belongs in the same emergency tier because CVE-2026-56164, CVE-2026-50522, and CVE-2026-58644 combine network-facing exposure, unauthenticated attack paths, and evidence of exploitation. CVE-2026-50518 and CVE-2026-56188 also fit this tier because both represent genuine network-service vulnerabilities with AV:N, no required privileges, and no user interaction.
Tier 2
Active Directory Domain Services, SSTP, AD CS, and AD FS form the second tier. CVE-2026-49164 affects a core identity service with a genuine network attack vector, while CVE-2026-50694 affects VPN tunneling functionality and should be prioritized according to where SSTP is exposed. Certighost (CVE-2026-54121) requires an authenticated domain foothold, but the availability of a public proof-of-concept lowers the research barrier for attackers and increases the urgency for organizations operating AD CS. CVE-2026-56155 also deserves accelerated deployment because exploitation has already occurred, even though its prerequisites keep it below unauthenticated network vulnerabilities.
Tier 3
Microsoft Office remains a high-value patch target, but its vulnerabilities should be described as client-side code-execution risks rather than network-service RCEs. Word, Excel, PowerPoint, and the broader Office suite do not expose listening services simply because Microsoft's impact label says Remote Code Execution. They remain important because of broad enterprise deployment and the relative ease of patch deployment. CVE-2026-57092 rounds out the list: its Hyper-V virtualization-boundary impact is significant, but it represents a post-compromise scenario rather than unauthenticated initial access.
CSO Takeaway
July demonstrates why vulnerability management cannot be reduced to sorting a spreadsheet by CVSS score. The first question security leaders should ask is not whether a vendor calls a vulnerability Remote Code Execution. The more useful question is: what does an attacker need to reach the vulnerable code?
A vulnerability in a VPN appliance, SharePoint web application, DHCP server, or other listening service represents a fundamentally different attack surface from a vulnerability in Word or Excel. Both may ultimately result in attacker-controlled code execution, but the route to that outcome is different. The SonicWall and SharePoint issues therefore belong at the top of July's list because they combine network reachability with evidence of exploitation and high-value enterprise placement.
July's Windows vulnerabilities reinforce the importance of examining the CVSS Attack Vector rather than accepting remote terminology at face value. DHCP Server, the Windows Server Network Driver, Active Directory Domain Services, and SSTP contain vulnerabilities with genuine network attack paths. These services process network traffic as part of their normal operation and should generally outrank comparable client-side issues.
Office still deserves a prominent place in the patching schedule. The distinction is not that Office vulnerabilities are harmless; it is that they represent a different attack model. An attacker typically needs to place malicious content in front of a user or otherwise cause the application to process attacker-controlled content. Because Office is broadly deployed and generally straightforward to update, organizations should still move quickly once the higher-risk network-service patches are underway.
Certighost illustrates another important part of the equation: public exploit availability can change priority after Patch Tuesday. CVE-2026-54121 requires an existing domain foothold, which normally keeps it below an unauthenticated network vulnerability. Once a working PoC becomes public, however, the amount of specialized research required by an attacker falls considerably. Likewise, active exploitation of CVE-2026-56155 should shorten remediation windows without changing the underlying prerequisites of the vulnerability.
The objective of the Patch Priority Index is not to identify the ten vulnerabilities with the highest numerical scores. It is to identify the patches most likely to reduce meaningful enterprise exposure this month. For July, that means patching exploited perimeter and SharePoint infrastructure first, followed by genuine network services and identity infrastructure, then broadly deployed client applications and post-compromise vulnerabilities.
Vendor References
Cybercrime Intelligence Shouldn't Be Siloed
Fortra® experts are dedicated to protecting organizations and the public by delivering the latest insights, data, and defenses to strengthen security against emerging cyber threats.