Microsoft released fixes for 570 security flaws on July 14, the largest Patch Tuesday in the company’s history. But the record-breaking number isn’t a sign of improvement—it’s a backlog, fueled by an AI model called Claude Mythos Preview that finds vulnerabilities faster than engineers can close them.
According to internal documents and a recording of a May meeting obtained by ProPublica, Microsoft’s own engineers are in “a mad dash” to keep up. The AI, part of Anthropic’s Project Glasswing, uncovered 90 critical and 141 important bugs in SharePoint alone during April. Halfway through May, it had found even more.
Those findings are now spilling into public patches. The July release addressed hundreds of newly cataloged vulnerabilities across Windows, Microsoft 365, Teams, Copilot, and SharePoint—many of them flagged by Mythos. Seven of those flaws were already being actively exploited in the wild before the fix arrived. The message for Windows and Microsoft 365 administrators is no longer “patch quickly,” but “patch faster, and rethink what you prioritize.”
The Numbers Behind the Record
The July 2026 Patch Tuesday delivered:
- 570 newly cataloged CVEs in the core release, with broader counts (including non-Microsoft CVEs) pushing the total above 600.
- 7 flaws rated low or moderate severity—one of which was under active attack.
- The remaining 563+ all scored critical or important, with multiple zero-days requiring immediate attention.
- SharePoint absorbed the heaviest hit, with hundreds of bugs across critical and important categories still awaiting fixes as of late May.
Those figures eclipse the previous record set in June 2026, when Microsoft patched more than 200 bugs. Dustin Childs, head of Trend Micro’s Zero Day Initiative, captured the mood: “Well folks. Here we are. The bug apocalypse has fully descended upon us.”
But the volume alone isn’t the whole story. The real shock is how quickly these vulnerabilities are being discovered—and why.
A New Kind of Disruption: AI That Hunts at Scale
On April 7, 2026, Anthropic unveiled Project Glasswing and a restricted preview model called Claude Mythos. The pitch was straightforward: give select organizations early access to an AI that could find code weaknesses before adversaries developed similar capabilities. Microsoft was among the first partners.
By May, the experiment had become a firehose. ProPublica reviewed an internal meeting recording and slides where Microsoft engineers were told that Mythos was living up to the hype—and exceeding the company’s capacity to fix what it found. In SharePoint, the discovery rate was so high that one engineering manager, Hans Andersen, pleaded with teams: “Please, please, please if your org has any April bugs, drive those down.” The deadline was May 31, the date Microsoft believed comparable public AI tools would become available.
Mythos doesn’t just find individual flaws. It can chain multiple low- or moderate-severity bugs into high-impact attack paths. That capability upends decades of vulnerability triage, where low-priority items often languish indefinitely. As Vinh Nguyen, a former NSA chief AI officer and now senior adviser to Anthropic, noted: “The problem now is that you can chain four low-level flaws, and that can equal a high severity. If you’re Microsoft, the current triage strategy may be underpricing risks.”
Why SharePoint and Microsoft 365 Are the New Front Lines
For everyday Windows users, Patch Tuesday often means applying the latest cumulative update and moving on. But the Mythos-driven wave changes the calculus—especially for organizations running SharePoint, Teams, or Microsoft 365 services.
SharePoint is a linchpin. It connects to document repositories, identity systems, and internal workflows. A compromised SharePoint server can give attackers a foothold into sensitive intellectual property, employee credentials, and line-of-business applications. The internal presentation showed that SharePoint alone accounted for 231 critical and important bugs discovered by Mythos in a single month, with hundreds more expected as the model churned through its backlog.
Microsoft 365 and Teams, similarly, are deeply integrated into how businesses communicate and collaborate. A flaw in these platforms is rarely contained to one application; it can propagate across cloud identities and linked services. Copilot, which layers AI assistance over organizational data, adds another attractive target for attackers looking to extract information.
In short, the July patches are not just a Windows update. They represent a forced march to harden the entire Microsoft ecosystem against an AI-assisted offensive that is no longer theoretical.
What to Do Right Now
Admins and security teams should take immediate, concrete steps.
1. Deploy the July 2026 patches immediately for internet-facing and identity-adjacent systems. Microsoft rates the vast majority of these vulnerabilities critical or important. Even one unpatched internet-facing SharePoint server could be enough for an attacker to establish a beachhead.
2. Re-validate your patching priorities for SharePoint, Microsoft 365, and Teams. These are not secondary concerns to the Windows OS update. Map all SharePoint farms, Teams-connected services, and hybrid identities, and confirm they receive the same patch urgency as domain controllers or Exchange servers.
3. Rehearse faster patch deployment. Monthly patch volumes are unlikely to shrink. If your change-management process still treats Patch Tuesday as a once-a-month event with multi-week testing cycles, you are already behind. Consider staged ring deployments, automated testing of critical service flows, and pre-approved emergency change windows for zero-day scenarios.
4. Revisit your risk assessment for moderate and low-severity bugs. Chaining means that a cluster of individually minor flaws can be weaponized into a critical exploit. While you can’t install every patch instantly, you should map which moderate flaws exist in the same components or attack surfaces. Patch clusters of adjacent low- and moderate-severity issues sooner than your standard SLA allows.
5. Pressure-test your incident response plan for fast-moving, AI-discovered vulnerabilities. Traditional vulnerability disclosure windows often provide days or weeks of lead time. Mythos-class AI can collapse that to hours. Ensure your SOC and IT teams can deploy out-of-band patches without waiting for a full monthly cycle.
How We Got Here
The timeline is dizzying, but it explains why July 2026 became a turning point.
- April 7, 2026: Anthropic announces Project Glasswing and Claude Mythos Preview, partnering with a handful of organizations including Microsoft. The goal: find and fix vulnerabilities before similar AI tools become publicly available.
- April–May 2026: Microsoft deploys Mythos internally, focusing roughly 50 employees on the effort. Findings pour in: 90 critical and 141 important SharePoint bugs in April alone; the pace accelerates in May.
- May 2026: Internal meeting reveals the scale of the problem. Microsoft sets May 31 as the informal deadline before comparable AI capability spreads beyond Glasswing partners. Engineers are told to prioritize critical and important findings for SharePoint, with moderate-severity bugs (roughly 300) to be addressed later.
- June 2026: Patch Tuesday fixes more than 200 vulnerabilities, then a record. Industry experts warn of a rapid escalation.
- Late June 2026: The Five Eyes intelligence alliance issues a joint statement warning that the window to fix AI-discoverable flaws is closing “in a matter of months.”
- July 14, 2026: Patch Tuesday releases 570 fixes, shattering the June record. Only 7 are low/moderate, but one is under active attack.
- Ongoing: Microsoft tells ProPublica that overall vulnerability volume “will not be plateauing for a bit,” and the company is investing in AI-powered triage tools and staff to handle the surge.
Microsoft has been dealing with a growing vulnerability load for years, but Mythos has compressed the timeline to an extreme. Former employees and industry analysts have long noted that Microsoft’s security response center was understaffed relative to the volume of incoming reports, and the company’s incentive structure historically favored new product development over patching legacy code. Mythos didn’t create technical debt—it just invoiced it.
What Comes Next for Windows and Microsoft 365 Admins
August’s Patch Tuesday will be the next stress test. If Mythos-related findings continue at the same pace, administrators should expect another triple-digit release, with SharePoint and cloud services again in the crosshairs.
Longer term, the industry’s patching model will need to evolve. Monthly update cadences were designed for an era when vulnerability discovery was a slow, human-driven process. AI flips that assumption. Microsoft may need to move toward more frequent, smaller security updates, or invest heavily in automated validation that lets moderate-severity patches ship faster without destabilizing production systems.
For now, the operational mandate is clear: treat every Patch Tuesday as a potential zero-day event. The bugs may be publicly disclosed on schedule, but the attackers are moving on AI time.