PGH Networks

Microsoft's Record 622-CVE Patch Tuesday: Two Zero-Days to Fix Now

July 18, 2026· PGH Networks Team· 4 min readBusiness & Tech Insights
Microsoft's Record 622-CVE Patch Tuesday: Two Zero-Days to Fix Now

What happened

Microsoft just delivered the largest Patch Tuesday in its history. According to reporting from The Hacker News (via feeds.feedburner.com), this month's release addresses 622 Microsoft CVEs — more than triple June's prior record of roughly 200 — and two of those vulnerabilities are already being exploited in the wild.

The two actively exploited zero-days were flagged with help from incident responders, which typically means real victims have already been hit. The source article doesn't spell out every technical detail of the two bugs, and rather than guess we'd encourage you to review Microsoft's Security Update Guide directly (or ask us) for the specific CVE IDs, affected products, and whether workarounds exist for anything you can't patch immediately.

Retro Apple computers with keyboards displayed in a Tokyo store window, showcasing early tech design.

Why this matters for Pittsburgh SMBs

A 622-CVE release isn't just a bigger-than-usual patch cycle — it's an operational event. For a 25-person CPA firm in the Strip District or a 150-person manufacturer in the Mon Valley, the practical implications are the same three problems, only the scale differs:

  • Attack window compression. Once Microsoft publishes fixes, attackers reverse-engineer them fast. Two of these are already weaponized. Every day you're unpatched, you're on a shrinking timer — and threat actors don't skip Pittsburgh because you're not on the coasts. SMBs are the preferred target precisely because patching lags.
  • Compliance exposure. If you're subject to HIPAA, SOC 2, CMMC, FTC Safeguards, or GLBA, your written policy almost certainly commits you to patching critical vulnerabilities within a defined window (often 14 or 30 days, shorter for actively exploited flaws). A record release means a record volume of evidence auditors will want to see. Defense contractors on the CMMC path should be particularly mindful — SI.L1-3.14.1 (flaw remediation) is one of the controls assessors probe hardest.
  • Cyber insurance. Most renewal questionnaires now ask specifically about time-to-patch for critical CVEs and about whether zero-days are handled out-of-band. A miss here can affect both premiums and, more importantly, whether a claim gets paid.

For legal, healthcare, and financial services clients specifically, the concern isn't only your endpoints — it's the servers hosting PMS, EHR, document management, and file shares, plus any Windows-based line-of-business appliances that vendors have quietly stopped updating.

What to do about it this week

You don't need to panic-patch 622 CVEs by Friday. You do need a triaged plan. Here's a practical order of operations:

  1. Identify the two zero-days first. Pull the CVE numbers from Microsoft's Security Update Guide (filter on "Exploited: Yes"). Confirm which of your systems — workstations, servers, Exchange, SQL, Edge, Office — are affected. These get patched or mitigated ahead of everything else, ideally within 72 hours.
  2. Verify your patch management tool actually ran. Whether you use Intune, WSUS, ConnectWise Automate, or something else, don't trust the dashboard at face value this month. Spot-check a sample of endpoints and servers to confirm the July updates installed and rebooted. A 622-CVE payload is larger than usual and reboot failures are more common.
  3. Prioritize by exposure, not by CVSS alone. Internet-facing systems (VPN concentrators, Exchange, RDP gateways, anything published through a reverse proxy) go before internal-only workstations. Domain controllers and identity systems go before file servers.
  4. Don't forget the servers people forget. The old 2019 box running the estimating software. The Hyper-V host in the closet. The scanner appliance running embedded Windows. Manufacturing and legal shops especially tend to have one or two of these.
  5. Check Microsoft 365 and Azure tenant health. Some of these CVEs will touch cloud-side components you don't patch directly, but you should still review Secure Score, Defender for Endpoint alerts, and any new advisories in the Microsoft 365 Message Center this week.
  6. Log the work for your auditor. Screenshot or export patch compliance reports dated after this cycle. If you're pursuing SOC 2 or CMMC, this is exactly the kind of evidence assessors ask for — capture it now, not in Q4.
  7. Brief your team. Expect a fresh wave of phishing lures referencing "critical Microsoft updates." Remind users that legitimate patches come through your IT provider or Windows Update, never via an email link or a phone call asking them to "run this tool."

If you run older, unsupported Windows versions (Server 2012 R2, Windows 10 outside ESU, etc.), assume the two zero-days may affect you and that no fix is coming. That's a segmentation-and-replacement conversation, not a patching one.

How PGH Networks helps

Patch Tuesdays like this one are exactly what a managed IT partner is for. Our team is already reviewing the release against the Pittsburgh-area environments we manage — mapping the two exploited CVEs to specific client systems, deploying updates through our RMM, validating reboots, and documenting the evidence your compliance framework requires. If you're a current client, you'll see this work reflected in your next report; if you're not sure whether your current provider has a handle on it, or you'd like a second set of eyes on your patch posture ahead of a SOC 2, HIPAA, or CMMC milestone, call us at 724.888.7007 or reach out through our contact form and we'll walk through your exposure this week.

Share

Related reading