Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation — Threadlinqs Intelligence
As of 2026-07-16, Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1324 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-16 · revalidated 1× · latest source
Microsoft's July 2026 Patch Tuesday addressed 570 vulnerabilities, including three zero-days: two actively exploited (CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in
Microsoft's July 2026 Patch Tuesday is one of the largest cumulative releases on record, addressing 570 vulnerabilities across Windows, Office, SharePoint, Exchange, SQL Server, Hyper-V, Defender, Dynamics NAV, and Minecraft Bedrock. Of the 570, 59 are rated Critical (48 RCE, 9 EoP, 1 security-feature bypass, 1 spoofing), 254 are elevation-of-privilege, 145 are remote code execution, 102 are information disclosure, 35 are denial of service, 17 are security-feature bypasses, and 16 are spoofing.
Three zero-days anchor the release. CVE-2026-56155 is an Active Directory Federation Services (AD FS) elevation-of-privilege flaw caused by insufficient granularity of access control, letting an already-authorized attacker escalate to administrative privileges locally; it is rated Important and is confirmed under active exploitation, credited to Jeremy Kingston and Scott Clark of Microsoft's Detection and Response Team (DART), implying it was discovered via incident-response engagements rather than proactive research. CVE-2026-56164 is a SharePoint Server elevation-of-privilege vulnerability rooted in missing authentication for a critical function, allowing an unauthorized network attacker to elevate privileges without credentials; it is rated Moderate but is also confirmed under active exploitation, credited to Jayson Frost (Mandiant Incident Response), Genwei Jiang and the FLARE OTF team (Google Cloud/Mandiant), and an anonymous researcher — the multi-vendor incident-response credit pattern mirrors prior SharePoint zero-day chains (e.g., ToolShell-class CVE-2026-45659/CVE-2026-45484) that were exploited for unauthenticated pre-auth access before privilege escalation. Microsoft's interim guidance for SharePoint defenders is to enable the Antimalware Scan Interface (AMSI) integration and set Request Body Scan mode to Full to gain visibility into exploitation attempts ahead of patch deployment. CVE-2026-50661 is a Windows BitLocker Device Encryption security-feature bypass that lets an attacker with physical access to a device's storage recover encrypted data; it is publicly disclosed but not reported as exploited in the wild, and was reported anonymously. It follows a pattern of BitLocker bypass disclosures across 2026 (e.g., CVE-2026-45585 'YellowKey', CVE-2026-50507), reflecting sustained researcher interest in cold-boot/physical-access attacks against Windows full-disk encryption.
Beyond the three zero-days, the release carries a heavy critical-RCE load across Office and PowerPoint (document-based code execution), SharePoint (additional critical bypass/RCE beyond the zero-day), Windows Media Foundation, DirectX Graphics, Windows GDI+, Remote Desktop Client, the RMCAST multicast driver, DHCP Client and Server, Windows Media, and Hyper-V (host-escape-class). Additional critical fixes land in Microsoft Defender, Microsoft Copilot, Dynamics NAV, Exchange, Minecraft Bedrock, and SQL Server. The same cycle saw major non-Microsoft vendors ship their own critical fixes — Adobe (ColdFusion/Campaign, including a flaw later exploited), SAP (NetWeaver, Commerce Cloud, AppRouter), BeyondTrust (Remote Support/Privileged Remote Access auth bypass), Cisco (Identity Services Engine, Catalyst Center, ClamAV, with CVE-2026-20230 confirmed exploited), Fortinet (FortiOS, FortiSandbox, FortiPAM, FortiSASE, FortiProxy), Gitea (Docker image auth bypass), Ivanti (Xtraction), Linux Kernel (VM escape), NVIDIA (Triton Inference Server, TensorRT-LLM), Progress Software (ShareFile path-traversal zero-day), Ubiquiti (UniFi OS command injection), U-Boot (firmware attack flaws), VMware (Avi Load Balancer auth bypass/RCE), and Zimbra (web client XSS) — underscoring a broad, concentrated patch-management burden across enterprise identity, collaboration, network, and virtualization stacks in the same week.
Weaknesses (CWE)
CWE-284, CWE-306, CWE-1230, CWE-1220
Target sectors: government administration, finance, health, technology, education, manufacturing, energy, retail
Target regions: North America, Europe, Asia Pacific, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-56155, CVE-2026-56164, CVE-2026-50661, CVE-2026-55129, CVE-2026-55049, CVE-2026-55045, CVE-2026-55140, CVE-2026-55056, CVE-2026-50314, CVE-2026-50467, T1190, T1203, T1204, T1068, T1078, T1548, T1611, T1006, T1562, T1211