Microsoft ships record patch: 622 vulnerabilities and two zero-days already under active attack

Colleagues, a quick cyber update: Microsoft has released its largest security update on record, covering 622 vulnerabilities.
I would prioritize the two zero-days already being exploited:
• CVE-2026-56164 in SharePoint Server
• CVE-2026-56155 in Active Directory Federation Services
Another disclosed BitLocker-bypass issue is less urgent, but still belongs on the remediation plan.
In releases like this, I look not only at severity, but first at exploited status, KEV, and EPSS.
How do you prioritize patches in updates like this?

