
SANS StormCast Highlights Record Microsoft Patch Tuesday and Critical Vulnerabilities Across Platforms
The July 15, 2026, edition of the SANS Internet Storm Center StormCast, presented by Johannes Ullrich from Washington D.C., highlighted a record-breaking Microsoft Patch Tuesday addressing 622 vulnerabilities, alongside over 400 Chromium-related flaws affecting Microsoft Edge. Two actively exploited vulnerabilities were noted: an Active Directory Federation Services elevation of privilege flaw (rated 'important') and a Microsoft SharePoint Server elevation of privilege issue (rated 'moderate'), while a disclosed but unexploited BitLocker security feature bypass was also patched. SonicWall released an urgent update for its SMA 1000 series appliances to fix a critical server-side request forgery (SSRF) vulnerability (CVSS 10.0) already under exploitation. Progress Software confirmed an actively exploited zero-day in its ShareFile storage zone controllers, prompting a prior shutdown directive before releasing a patch. Additionally, X AI’s Croc tool was found to upload entire Git repositories—including secrets—despite user restrictions, with Elon Musk acknowledging the issue and pledging to delete the collected data. The episode emphasized that while patch volumes surged, the actual deployment workload did not scale proportionally due to bundled updates.