Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation
Microsoft July 2026 Patch Tuesday (TL-2026-1324), also tracked as July 2026 Patch Tuesday, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-14 and last reviewed 2026-07-16. It has no confirmed attribution, affects Microsoft Active Directory Federation Services (AD FS), references 51 CVEs (CVE-2026-56155, CVE-2026-56164, CVE-2026-50661), maps to 31 MITRE ATT&CK techniques (T1003, T1005, T1006), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-1324
- Threat ID
- TL-2026-1324
- Also known as
- July 2026 Patch Tuesday
- Severity
- CRITICAL
- CVSS
- 9.8
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-14
- Last reviewed
- 2026-07-16
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, education, manufacturing, energy, retail
- Target regions
- North America, Europe, Asia Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 30
- Updates
- 2026-07-16 · revalidated 1× · latest source
Malware and tooling in Microsoft July 2026 Patch Tuesday
Malware and tooling: Antimalware Scan Interface (AMSI)
Microsoft's July 2026 Patch Tuesday addressed 570 vulnerabilities, including three zero-days: two actively exploited (CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server) and one publicly disclosed BitLocker encryption bypass (CVE-2026-50661) requiring physical access. 59 vulnerabilities were rated Critical, led by elevation-of-privilege (254) and remote code execution (145) flaws.
How Microsoft July 2026 Patch Tuesday works
Microsoft's July 2026 Patch Tuesday is one of the largest cumulative releases on record, addressing 570 vulnerabilities across Windows, Office, SharePoint, Exchange, SQL Server, Hyper-V, Defender, Dynamics NAV, and Minecraft Bedrock. Of the 570, 59 are rated Critical (48 RCE, 9 EoP, 1 security-feature bypass, 1 spoofing), 254 are elevation-of-privilege, 145 are remote code execution, 102 are information disclosure, 35 are denial of service, 17 are security-feature bypasses, and 16 are spoofing.
Three zero-days anchor the release. CVE-2026-56155 is an Active Directory Federation Services (AD FS) elevation-of-privilege flaw caused by insufficient granularity of access control, letting an already-authorized attacker escalate to administrative privileges locally; it is rated Important and is confirmed under active exploitation, credited to Jeremy Kingston and Scott Clark of Microsoft's Detection and Response Team (DART), implying it was discovered via incident-response engagements rather than proactive research. CVE-2026-56164 is a SharePoint Server elevation-of-privilege vulnerability rooted in missing authentication for a critical function, allowing an unauthorized network attacker to elevate privileges without credentials; it is rated Moderate but is also confirmed under active exploitation, credited to Jayson Frost (Mandiant Incident Response), Genwei Jiang and the FLARE OTF team (Google Cloud/Mandiant), and an anonymous researcher — the multi-vendor incident-response credit pattern mirrors prior SharePoint zero-day chains (e.g., ToolShell-class CVE-2026-45659/CVE-2026-45484) that were exploited for unauthenticated pre-auth access before privilege escalation. Microsoft's interim guidance for SharePoint defenders is to enable the Antimalware Scan Interface (AMSI) integration and set Request Body Scan mode to Full to gain visibility into exploitation attempts ahead of patch deployment. CVE-2026-50661 is a Windows BitLocker Device Encryption security-feature bypass that lets an attacker with physical access to a device's storage recover encrypted data; it is publicly disclosed but not reported as exploited in the wild, and was reported anonymously. It follows a pattern of BitLocker bypass disclosures across 2026 (e.g., CVE-2026-45585 'YellowKey', CVE-2026-50507), reflecting sustained researcher interest in cold-boot/physical-access attacks against Windows full-disk encryption.
Beyond the three zero-days, the release carries a heavy critical-RCE load across Office and PowerPoint (document-based code execution), SharePoint (additional critical bypass/RCE beyond the zero-day), Windows Media Foundation, DirectX Graphics, Windows GDI+, Remote Desktop Client, the RMCAST multicast driver, DHCP Client and Server, Windows Media, and Hyper-V (host-escape-class). Additional critical fixes land in Microsoft Defender, Microsoft Copilot, Dynamics NAV, Exchange, Minecraft Bedrock, and SQL Server. The same cycle saw major non-Microsoft vendors ship their own critical fixes — Adobe (ColdFusion/Campaign, including a flaw later exploited), SAP (NetWeaver, Commerce Cloud, AppRouter), BeyondTrust (Remote Support/Privileged Remote Access auth bypass), Cisco (Identity Services Engine, Catalyst Center, ClamAV, with CVE-2026-20230 confirmed exploited), Fortinet (FortiOS, FortiSandbox, FortiPAM, FortiSASE, FortiProxy), Gitea (Docker image auth bypass), Ivanti (Xtraction), Linux Kernel (VM escape), NVIDIA (Triton Inference Server, TensorRT-LLM), Progress Software (ShareFile path-traversal zero-day), Ubiquiti (UniFi OS command injection), U-Boot (firmware attack flaws), VMware (Avi Load Balancer auth bypass/RCE), and Zimbra (web client XSS) — underscoring a broad, concentrated patch-management burden across enterprise identity, collaboration, network, and virtualization stacks in the same week.
MITRE ATT&CK techniques used in TL-2026-1324
Credential Access
T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1606 Forge Web Credentials
Collection
Defense Evasion
T1006 Direct Volume Access; T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1211 Exploitation for Stealth
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts; T1484 Domain or Tenant Policy Modification; T1548 Abuse Elevation Control Mechanism; T1611 Escape to Host
Discovery
T1069 Permission Groups Discovery; T1087 Account Discovery
Command and Control
T1071 Application Layer Protocol
Persistence
T1098 Account Manipulation; T1505 Server Software Component; T1556 Modify Authentication Process
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1486 Data Encrypted for Impact; T1499 Endpoint Denial of Service
lateral-movement
T1550 Use Alternate Authentication Material
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1587 Develop Capabilities; T1588 Obtain Capabilities
defense-impairment
Affected products and versions in Microsoft July 2026 Patch Tuesday
- Microsoft — Active Directory Federation Services (AD FS)
Vulnerable versions: all supported AD FS releases prior to July 2026 cumulative update
Fixed in: July 2026 cumulative security update - Microsoft — SharePoint Server
Vulnerable versions: on-premises SharePoint Server releases prior to July 2026 update
Fixed in: July 2026 cumulative security update - Microsoft — Windows (BitLocker Device Encryption)
Vulnerable versions: supported Windows client/server releases prior to July 2026 update
Fixed in: July 2026 cumulative security update - Microsoft — Office / PowerPoint
Vulnerable versions: supported Microsoft 365 Apps / Office releases prior to July 2026 update
Fixed in: July 2026 cumulative security update - Microsoft — Windows Media Foundation / DirectX / GDI+ / RDP Client / RMCAST / DHCP Client-Server / Hyper-V
Vulnerable versions: supported Windows releases prior to July 2026 update
Fixed in: July 2026 cumulative security update - Microsoft — Exchange Server / SQL Server / Dynamics NAV / Defender / Copilot
Vulnerable versions: supported releases prior to July 2026 update
Fixed in: July 2026 cumulative security update
Remediation for Microsoft July 2026 Patch Tuesday
Patches
- Microsoft July 2026 cumulative security updates addressing CVE-2026-56155, CVE-2026-56164, CVE-2026-50661, and 567 additional CVEs
Immediate actions
- Apply the July 2026 cumulative updates for Windows, AD FS, and SharePoint Server without delay, prioritizing systems running AD FS or SharePoint Server
- For SharePoint Server, enable AMSI integration and set Request Body Scan mode to Full to gain detection visibility for CVE-2026-56164 exploitation attempts pending patch rollout
- Audit AD FS server administrative access and review recent privilege-escalation activity for indicators of CVE-2026-56155 exploitation
- Enforce full-disk encryption compensating controls (e.g., pre-boot PIN, TPM+PIN) on devices at elevated physical-theft risk to reduce CVE-2026-50661 exposure ahead of patching
- Prioritize the 59 Critical-rated fixes (48 RCE, 9 EoP, 1 bypass, 1 spoofing) across Office, SharePoint, Windows Media Foundation, DirectX, GDI+, RDP Client, RMCAST, DHCP Client/Server, and Hyper-V
Workarounds
- SharePoint: enable AMSI with Request Body Scan mode Full as an interim mitigation for CVE-2026-56164 until patched
- BitLocker: restrict physical access to unpatched endpoints and enforce pre-boot authentication as a compensating control for CVE-2026-50661
Longer-term hardening
- Establish a monitoring baseline for AD FS privilege changes and SharePoint authentication/authorization events tied to critical-function endpoints
- Adopt hardware-backed pre-boot authentication (PIN/TPM) as standard configuration to reduce impact of future BitLocker security-feature bypasses
- Track cross-vendor Patch Tuesday-cycle advisories (Adobe, SAP, Cisco, Fortinet, VMware, Progress Software) as part of the same monthly remediation window given the concentrated 2026 disclosure cadence
CVEs associated with Microsoft July 2026 Patch Tuesday
- CVE-2026-56155
- CVE-2026-56164
- CVE-2026-50661
CVE-2026-55129CVE-2026-55049CVE-2026-55045CVE-2026-55140CVE-2026-55056CVE-2026-50314CVE-2026-50467CVE-2026-55022CVE-2026-55018CVE-2026-55127CVE-2026-55033CVE-2026-55132CVE-2026-55120CVE-2026-55043CVE-2026-55123- CVE-2026-55040
- CVE-2026-58644
- CVE-2026-50522
CVE-2026-56189CVE-2026-57087CVE-2026-57094CVE-2026-57090CVE-2026-50382CVE-2026-54122CVE-2026-50380CVE-2026-50474CVE-2026-54995CVE-2026-54982CVE-2026-54128CVE-2026-50518CVE-2026-50370CVE-2026-56159CVE-2026-48564CVE-2026-58542CVE-2026-50327CVE-2026-50655CVE-2026-50680CVE-2026-54127CVE-2026-55012CVE-2026-55011CVE-2026-48561CVE-2026-55944CVE-2026-55008CVE-2026-55010CVE-2026-54118CVE-2026-54117- CVE-2026-32201
- CVE-2026-45659
Weaknesses (CWE) in Microsoft July 2026 Patch Tuesday
CWE-284, CWE-306, CWE-1230, CWE-1220
Timeline of Microsoft July 2026 Patch Tuesday
- CVE-2026-32201, an actively-exploited SharePoint spoofing zero-day, is patched — the first of three 2026 SharePoint zero-day incidents in a recurring pattern.
- CVE-2026-45659, an actively-exploited SharePoint RCE zero-day, is patched out-of-band.
- Cisco first publishes its Unified Communications Manager SSRF advisory (CVE-2026-20230), later folded into the same July patch-cycle analysis as an actively-exploited concurrent vendor flaw.
- CISA adds Cisco CVE-2026-20230 (Unified CM SSRF) to the Known Exploited Vulnerabilities catalog after confirming in-the-wild exploitation via an unvetted public PoC.
- Adobe discloses nine ColdFusion 2023/2025 and Campaign Classic v7 vulnerabilities (seven rated CVSS 10.0, enabling arbitrary code execution); one, CVE-2026-48282, is exploited within hours of disclosure from an IP geolocated to India.
- Cisco publishes an updated advisory for CVE-2026-20230 confirming active exploitation of Unified CM/Unified CM SME, cited alongside Microsoft's release as part of the same concentrated patch-management week.
- CISA urges organizations to patch the actively-exploited Adobe ColdFusion path-traversal flaw (CVE-2026-48282) before this date, placing it in the same remediation window as Microsoft's July zero-days.
- Microsoft's update introduces an AD FS DKM ACL audit mode (Event ID 1132) and the RemediateDkmAcl registry key for immediate remediation of CVE-2026-56155.
- CISA adds both CVE-2026-56164 and CVE-2026-56155 specifically to the Known Exploited Vulnerabilities (KEV) catalog the same day patches ship.
- BleepingComputer publishes analysis of the July 2026 Patch Tuesday release, detailing the three zero-days and the 59 Critical-rated vulnerabilities.
- Adobe CSO Aanchal Gupta announces a shift to a biweekly security-bulletin release schedule (second and fourth Tuesdays each month) beginning this date, aligning Adobe's cadence with Microsoft's Patch Tuesday cycle.
- Microsoft publishes interim SharePoint mitigation guidance for CVE-2026-56164: enable AMSI integration and set Request Body Scan mode to Full ahead of full patch deployment.
- CVE-2026-50661 (Windows BitLocker Device Encryption bypass requiring physical access) publicly disclosed by an anonymous researcher; not reported as exploited in the wild.
- CVE-2026-56164 (SharePoint Server elevation of privilege via missing authentication for a critical function) confirmed under active exploitation; credited to Mandiant Incident Response and Google Cloud's FLARE OTF team.
- CVE-2026-56155 (AD FS elevation of privilege) confirmed under active exploitation; credited to Microsoft's Detection and Response Team (DART), indicating discovery through incident-response engagements.
- Microsoft ships the July 2026 cumulative security updates, resolving 570 vulnerabilities across Windows, Office, SharePoint, Exchange, SQL Server, Hyper-V, Defender, Dynamics NAV, and Minecraft Bedrock.
- CISA BOD 26-04 remediation deadline for CVE-2026-56164 for U.S. federal civilian executive branch agencies.
- CISA BOD 26-04 remediation deadline for CVE-2026-56155 for U.S. federal civilian executive branch agencies.
- Microsoft's scheduled date after which AD FS environments with an unconfigured DKM container ACL are automatically remediated.
Update history for TL-2026-1324
- 2026-07-16 — CVE-2026-56164 (SharePoint Server Unauthenticated Network Privilege Escalation) and CVE-2026-56155 (AD FS DKM ACL Privilege Escalation) Actively Exploited in Microsoft's Record 622-CVE July 2026 Patch Tuesday: What changed CVSS score added (9.8, NVD rating for CVE-2026-56164) where the existing record had none; the report also surfaces the Microsoft-vs-NVD scoring discrepancy (5.3 vs 9.8) as a notable data point, but the underlying severity/explo
Sources cited for Microsoft July 2026 Patch Tuesday
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
- CVE-2026-56155 - Security Update Guide - Microsoft - Active Directory Federation Services Elevation of Privilege Vulnerability
- CVE-2026-56164 - Security Update Guide - Microsoft - Microsoft SharePoint Elevation of Privilege Vulnerability
- CVE-2026-50661 - Security Update Guide - Microsoft - Windows BitLocker Security Feature Bypass Vulnerability
- CISA Known Exploited Vulnerabilities Catalog
- CISA Adds Three Known Exploited Vulnerabilities to Catalog
- July 2026 Patch Tuesday forecast: Is CVE tracking still practical?
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
- CVE-2026-20230 Detail
- Adobe patches seven max severity ColdFusion, Campaign flaws
- Adobe Security Bulletin - ColdFusion (APSB26-64)
Threats related to Microsoft July 2026 Patch Tuesday
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164 SharePoint) Among Record 570+ Fixes
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)
- July 2026 Patch Tuesday: Two Actively Exploited Microsoft Zero-Days (SharePoint EoP CVE-2026-56164, AD FS EoP CVE-2026-56155) Plus SharePoint JWT Auth Bypass CVE-2026-55040
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)
- Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP)
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)
Detection coverage for TL-2026-1324
As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1324 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.