Microsoft's July update addressed 622 vulnerabilities, including a SharePoint remote-code-execution chain and several actively exploited zero-days. On-premises SharePoint servers are the standout risk and should be patched without waiting.
The scale is a reminder that patch volume keeps climbing, and that attackers move fastest in the window between a fix shipping and admins applying it.
Why it matters: A remote-code-execution chain plus live exploitation is the combination defenders least want to sit on. If you run SharePoint yourself, this is not a week to skip.