Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation

Microsoft July 2026 Patch Tuesday (TL-2026-1324), also tracked as July 2026 Patch Tuesday, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-14 and last reviewed 2026-07-16. It has no confirmed attribution, affects Microsoft Active Directory Federation Services (AD FS), references 51 CVEs (CVE-2026-56155, CVE-2026-56164, CVE-2026-50661), maps to 31 MITRE ATT&CK techniques (T1003, T1005, T1006), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-1324

Threat ID
TL-2026-1324
Also known as
July 2026 Patch Tuesday
Severity
CRITICAL
CVSS
9.8
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-14
Last reviewed
2026-07-16
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, education, manufacturing, energy, retail
Target regions
North America, Europe, Asia Pacific, Global
Detection rules
9
Indicators of compromise
30
Updates
2026-07-16 · revalidated 1× · latest source

Malware and tooling in Microsoft July 2026 Patch Tuesday

Malware and tooling: Antimalware Scan Interface (AMSI)

Microsoft's July 2026 Patch Tuesday addressed 570 vulnerabilities, including three zero-days: two actively exploited (CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server) and one publicly disclosed BitLocker encryption bypass (CVE-2026-50661) requiring physical access. 59 vulnerabilities were rated Critical, led by elevation-of-privilege (254) and remote code execution (145) flaws.

How Microsoft July 2026 Patch Tuesday works

Microsoft's July 2026 Patch Tuesday is one of the largest cumulative releases on record, addressing 570 vulnerabilities across Windows, Office, SharePoint, Exchange, SQL Server, Hyper-V, Defender, Dynamics NAV, and Minecraft Bedrock. Of the 570, 59 are rated Critical (48 RCE, 9 EoP, 1 security-feature bypass, 1 spoofing), 254 are elevation-of-privilege, 145 are remote code execution, 102 are information disclosure, 35 are denial of service, 17 are security-feature bypasses, and 16 are spoofing.

Three zero-days anchor the release. CVE-2026-56155 is an Active Directory Federation Services (AD FS) elevation-of-privilege flaw caused by insufficient granularity of access control, letting an already-authorized attacker escalate to administrative privileges locally; it is rated Important and is confirmed under active exploitation, credited to Jeremy Kingston and Scott Clark of Microsoft's Detection and Response Team (DART), implying it was discovered via incident-response engagements rather than proactive research. CVE-2026-56164 is a SharePoint Server elevation-of-privilege vulnerability rooted in missing authentication for a critical function, allowing an unauthorized network attacker to elevate privileges without credentials; it is rated Moderate but is also confirmed under active exploitation, credited to Jayson Frost (Mandiant Incident Response), Genwei Jiang and the FLARE OTF team (Google Cloud/Mandiant), and an anonymous researcher — the multi-vendor incident-response credit pattern mirrors prior SharePoint zero-day chains (e.g., ToolShell-class CVE-2026-45659/CVE-2026-45484) that were exploited for unauthenticated pre-auth access before privilege escalation. Microsoft's interim guidance for SharePoint defenders is to enable the Antimalware Scan Interface (AMSI) integration and set Request Body Scan mode to Full to gain visibility into exploitation attempts ahead of patch deployment. CVE-2026-50661 is a Windows BitLocker Device Encryption security-feature bypass that lets an attacker with physical access to a device's storage recover encrypted data; it is publicly disclosed but not reported as exploited in the wild, and was reported anonymously. It follows a pattern of BitLocker bypass disclosures across 2026 (e.g., CVE-2026-45585 'YellowKey', CVE-2026-50507), reflecting sustained researcher interest in cold-boot/physical-access attacks against Windows full-disk encryption.

Beyond the three zero-days, the release carries a heavy critical-RCE load across Office and PowerPoint (document-based code execution), SharePoint (additional critical bypass/RCE beyond the zero-day), Windows Media Foundation, DirectX Graphics, Windows GDI+, Remote Desktop Client, the RMCAST multicast driver, DHCP Client and Server, Windows Media, and Hyper-V (host-escape-class). Additional critical fixes land in Microsoft Defender, Microsoft Copilot, Dynamics NAV, Exchange, Minecraft Bedrock, and SQL Server. The same cycle saw major non-Microsoft vendors ship their own critical fixes — Adobe (ColdFusion/Campaign, including a flaw later exploited), SAP (NetWeaver, Commerce Cloud, AppRouter), BeyondTrust (Remote Support/Privileged Remote Access auth bypass), Cisco (Identity Services Engine, Catalyst Center, ClamAV, with CVE-2026-20230 confirmed exploited), Fortinet (FortiOS, FortiSandbox, FortiPAM, FortiSASE, FortiProxy), Gitea (Docker image auth bypass), Ivanti (Xtraction), Linux Kernel (VM escape), NVIDIA (Triton Inference Server, TensorRT-LLM), Progress Software (ShareFile path-traversal zero-day), Ubiquiti (UniFi OS command injection), U-Boot (firmware attack flaws), VMware (Avi Load Balancer auth bypass/RCE), and Zimbra (web client XSS) — underscoring a broad, concentrated patch-management burden across enterprise identity, collaboration, network, and virtualization stacks in the same week.

MITRE ATT&CK techniques used in TL-2026-1324

Credential Access

T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1606 Forge Web Credentials

Collection

T1005 Data from Local System

Defense Evasion

T1006 Direct Volume Access; T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1211 Exploitation for Stealth

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts; T1484 Domain or Tenant Policy Modification; T1548 Abuse Elevation Control Mechanism; T1611 Escape to Host

Discovery

T1069 Permission Groups Discovery; T1087 Account Discovery

Command and Control

T1071 Application Layer Protocol

Persistence

T1098 Account Manipulation; T1505 Server Software Component; T1556 Modify Authentication Process

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1486 Data Encrypted for Impact; T1499 Endpoint Denial of Service

lateral-movement

T1550 Use Alternate Authentication Material

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Microsoft July 2026 Patch Tuesday

  • Microsoft — Active Directory Federation Services (AD FS)
    Vulnerable versions: all supported AD FS releases prior to July 2026 cumulative update
    Fixed in: July 2026 cumulative security update
  • Microsoft — SharePoint Server
    Vulnerable versions: on-premises SharePoint Server releases prior to July 2026 update
    Fixed in: July 2026 cumulative security update
  • Microsoft — Windows (BitLocker Device Encryption)
    Vulnerable versions: supported Windows client/server releases prior to July 2026 update
    Fixed in: July 2026 cumulative security update
  • Microsoft — Office / PowerPoint
    Vulnerable versions: supported Microsoft 365 Apps / Office releases prior to July 2026 update
    Fixed in: July 2026 cumulative security update
  • Microsoft — Windows Media Foundation / DirectX / GDI+ / RDP Client / RMCAST / DHCP Client-Server / Hyper-V
    Vulnerable versions: supported Windows releases prior to July 2026 update
    Fixed in: July 2026 cumulative security update
  • Microsoft — Exchange Server / SQL Server / Dynamics NAV / Defender / Copilot
    Vulnerable versions: supported releases prior to July 2026 update
    Fixed in: July 2026 cumulative security update

Remediation for Microsoft July 2026 Patch Tuesday

Patches

  • Microsoft July 2026 cumulative security updates addressing CVE-2026-56155, CVE-2026-56164, CVE-2026-50661, and 567 additional CVEs

Immediate actions

  • Apply the July 2026 cumulative updates for Windows, AD FS, and SharePoint Server without delay, prioritizing systems running AD FS or SharePoint Server
  • For SharePoint Server, enable AMSI integration and set Request Body Scan mode to Full to gain detection visibility for CVE-2026-56164 exploitation attempts pending patch rollout
  • Audit AD FS server administrative access and review recent privilege-escalation activity for indicators of CVE-2026-56155 exploitation
  • Enforce full-disk encryption compensating controls (e.g., pre-boot PIN, TPM+PIN) on devices at elevated physical-theft risk to reduce CVE-2026-50661 exposure ahead of patching
  • Prioritize the 59 Critical-rated fixes (48 RCE, 9 EoP, 1 bypass, 1 spoofing) across Office, SharePoint, Windows Media Foundation, DirectX, GDI+, RDP Client, RMCAST, DHCP Client/Server, and Hyper-V

Workarounds

  • SharePoint: enable AMSI with Request Body Scan mode Full as an interim mitigation for CVE-2026-56164 until patched
  • BitLocker: restrict physical access to unpatched endpoints and enforce pre-boot authentication as a compensating control for CVE-2026-50661

Longer-term hardening

  • Establish a monitoring baseline for AD FS privilege changes and SharePoint authentication/authorization events tied to critical-function endpoints
  • Adopt hardware-backed pre-boot authentication (PIN/TPM) as standard configuration to reduce impact of future BitLocker security-feature bypasses
  • Track cross-vendor Patch Tuesday-cycle advisories (Adobe, SAP, Cisco, Fortinet, VMware, Progress Software) as part of the same monthly remediation window given the concentrated 2026 disclosure cadence

CVEs associated with Microsoft July 2026 Patch Tuesday

  • CVE-2026-56155
  • CVE-2026-56164
  • CVE-2026-50661
  • CVE-2026-55129
  • CVE-2026-55049
  • CVE-2026-55045
  • CVE-2026-55140
  • CVE-2026-55056
  • CVE-2026-50314
  • CVE-2026-50467
  • CVE-2026-55022
  • CVE-2026-55018
  • CVE-2026-55127
  • CVE-2026-55033
  • CVE-2026-55132
  • CVE-2026-55120
  • CVE-2026-55043
  • CVE-2026-55123
  • CVE-2026-55040
  • CVE-2026-58644
  • CVE-2026-50522
  • CVE-2026-56189
  • CVE-2026-57087
  • CVE-2026-57094
  • CVE-2026-57090
  • CVE-2026-50382
  • CVE-2026-54122
  • CVE-2026-50380
  • CVE-2026-50474
  • CVE-2026-54995
  • CVE-2026-54982
  • CVE-2026-54128
  • CVE-2026-50518
  • CVE-2026-50370
  • CVE-2026-56159
  • CVE-2026-48564
  • CVE-2026-58542
  • CVE-2026-50327
  • CVE-2026-50655
  • CVE-2026-50680
  • CVE-2026-54127
  • CVE-2026-55012
  • CVE-2026-55011
  • CVE-2026-48561
  • CVE-2026-55944
  • CVE-2026-55008
  • CVE-2026-55010
  • CVE-2026-54118
  • CVE-2026-54117
  • CVE-2026-32201
  • CVE-2026-45659

Weaknesses (CWE) in Microsoft July 2026 Patch Tuesday

CWE-284, CWE-306, CWE-1230, CWE-1220

Timeline of Microsoft July 2026 Patch Tuesday

  • CVE-2026-32201, an actively-exploited SharePoint spoofing zero-day, is patched — the first of three 2026 SharePoint zero-day incidents in a recurring pattern.
  • CVE-2026-45659, an actively-exploited SharePoint RCE zero-day, is patched out-of-band.
  • Cisco first publishes its Unified Communications Manager SSRF advisory (CVE-2026-20230), later folded into the same July patch-cycle analysis as an actively-exploited concurrent vendor flaw.
  • CISA adds Cisco CVE-2026-20230 (Unified CM SSRF) to the Known Exploited Vulnerabilities catalog after confirming in-the-wild exploitation via an unvetted public PoC.
  • Adobe discloses nine ColdFusion 2023/2025 and Campaign Classic v7 vulnerabilities (seven rated CVSS 10.0, enabling arbitrary code execution); one, CVE-2026-48282, is exploited within hours of disclosure from an IP geolocated to India.
  • Cisco publishes an updated advisory for CVE-2026-20230 confirming active exploitation of Unified CM/Unified CM SME, cited alongside Microsoft's release as part of the same concentrated patch-management week.
  • CISA urges organizations to patch the actively-exploited Adobe ColdFusion path-traversal flaw (CVE-2026-48282) before this date, placing it in the same remediation window as Microsoft's July zero-days.
  • Microsoft's update introduces an AD FS DKM ACL audit mode (Event ID 1132) and the RemediateDkmAcl registry key for immediate remediation of CVE-2026-56155.
  • CISA adds both CVE-2026-56164 and CVE-2026-56155 specifically to the Known Exploited Vulnerabilities (KEV) catalog the same day patches ship.
  • BleepingComputer publishes analysis of the July 2026 Patch Tuesday release, detailing the three zero-days and the 59 Critical-rated vulnerabilities.
  • Adobe CSO Aanchal Gupta announces a shift to a biweekly security-bulletin release schedule (second and fourth Tuesdays each month) beginning this date, aligning Adobe's cadence with Microsoft's Patch Tuesday cycle.
  • Microsoft publishes interim SharePoint mitigation guidance for CVE-2026-56164: enable AMSI integration and set Request Body Scan mode to Full ahead of full patch deployment.
  • CVE-2026-50661 (Windows BitLocker Device Encryption bypass requiring physical access) publicly disclosed by an anonymous researcher; not reported as exploited in the wild.
  • CVE-2026-56164 (SharePoint Server elevation of privilege via missing authentication for a critical function) confirmed under active exploitation; credited to Mandiant Incident Response and Google Cloud's FLARE OTF team.
  • CVE-2026-56155 (AD FS elevation of privilege) confirmed under active exploitation; credited to Microsoft's Detection and Response Team (DART), indicating discovery through incident-response engagements.
  • Microsoft ships the July 2026 cumulative security updates, resolving 570 vulnerabilities across Windows, Office, SharePoint, Exchange, SQL Server, Hyper-V, Defender, Dynamics NAV, and Minecraft Bedrock.
  • CISA BOD 26-04 remediation deadline for CVE-2026-56164 for U.S. federal civilian executive branch agencies.
  • CISA BOD 26-04 remediation deadline for CVE-2026-56155 for U.S. federal civilian executive branch agencies.
  • Microsoft's scheduled date after which AD FS environments with an unconfigured DKM container ACL are automatically remediated.

Update history for TL-2026-1324

Sources cited for Microsoft July 2026 Patch Tuesday

Threats related to Microsoft July 2026 Patch Tuesday

Detection coverage for TL-2026-1324

As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1324 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats