Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155) — Threadlinqs Intelligence
As of 2026-07-19, Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1325 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-19 · revalidated 1× · latest source
Microsoft's July 2026 Patch Tuesday addressed roughly 570 vulnerabilities, including two actively exploited zero-days -- a SharePoint Server elevation-of-privilege flaw (CVE-2026-56164) and an Active
On 2026-07-14 Microsoft shipped its largest Patch Tuesday to date, fixing approximately 570 vulnerabilities: 254 Elevation of Privilege, 145 Remote Code Execution, 102 Information Disclosure, 35 Denial of Service, 17 Security Feature Bypass, and 16 Spoofing bugs, with 59 rated Critical (48 RCE, 9 EoP, 1 bypass, 1 spoofing). Coverage attributes the record volume in part to Microsoft's newly deployed AI-assisted vulnerability-discovery tooling scanning the Windows codebase.
Two zero-days were confirmed exploited in the wild and immediately added to the CISA Known Exploited Vulnerabilities catalog: CVE-2026-56164, a missing-authentication (CWE-306) elevation-of-privilege flaw in on-premises Microsoft Office SharePoint (SharePoint Enterprise Server 2016, SharePoint Server 2019, SharePoint Server Subscription Edition) that lets an unauthenticated network attacker elevate privileges (CVSS 3.1 5.3, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N); and CVE-2026-56155, an insufficient-access-control-granularity flaw (CWE-1220) in Active Directory Federation Services that lets an authenticated local attacker escalate to full compromise of confidentiality, integrity, and availability (CVSS 3.1 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Both were credited to Jeremy Kingston and Scott Clark of Microsoft's Detection and Response Team (DART), a strong signal both were surfaced during live incident-response investigations rather than proactive research -- Microsoft has not published the specific in-the-wild exploitation methodology for either.
Although CVE-2026-56164 carries only a MEDIUM CVSS base score, its practical risk is amplified because on-prem SharePoint EoP bugs have repeatedly been chained with SharePoint deserialization RCEs (the 2025 'ToolShell' chain of CVE-2025-49706/CVE-2025-49704, and the May-2026-patched CVE-2026-45659 deserialization RCE) to achieve unauthenticated remote code execution and theft of the SharePoint ValidationKey/DecryptionKey machine keys, which grants persistent access surviving a patch. Microsoft's interim mitigation for CVE-2026-56164 is to enable AMSI (Antimalware Scan Interface) with Request Body Scan mode set to Full on affected SharePoint farms. CVE-2026-56155 (AD FS) is significant for hybrid Azure AD/on-premises identity environments: historically, compromise of an AD FS server's token-signing certificate enables 'Golden SAML' forgery, letting an attacker mint arbitrary SAML assertions and impersonate any federated user -- including Global Administrators -- against downstream cloud services, bypassing MFA/SSO controls entirely.
A third zero-day, CVE-2026-50661, is a Windows BitLocker Device Encryption bypass (CWE-693, protection mechanism failure) that was publicly disclosed but is not confirmed exploited (CVSS 3.1 6.1, AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). It requires physical access to the target device and follows the same vulnerability class as the June 2026 'YellowKey' BitLocker Windows Recovery Environment bypass (CVE-2026-45585), which used a crafted 'FsTx' folder staged on removable media or the EFI partition to trigger unrestricted SYSTEM-level shell access to the encrypted volume via WinRE in roughly 60 seconds with no password or recovery key. Microsoft's June 2026 YellowKey mitigation guidance (remove the autofstx.exe BootExecute entry from the WinRE image; enable BitLocker TPM+PIN) is the same defensive posture recommended against CVE-2026-50661-class attacks.
Two Critical-severity RCEs round out the highest-priority set: CVE-2026-58644, a deserialization-of-untrusted-data flaw (CWE-502) in the same three on-premises SharePoint products (CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) -- an unauthenticated, network-exploitable RCE in the same product family as the actively-exploited EoP, meaning a SharePoint farm unpatched against both CVE-2026-56164 and CVE-2026-58644 is exposed to a full ToolShell-style unauthenticated RCE chain; and CVE-2026-58608, a race-condition/use-after-free flaw (CW
Weaknesses (CWE)
CWE-306, CWE-1220, CWE-693, CWE-502, CWE-362, CWE-416, CWE-79, CWE-359, CWE-269, CWE-290
Target sectors: government administration, finance, health, technology, education, manufacturing, critical-infrastructure
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-56164, CVE-2026-56155, CVE-2026-50661, CVE-2026-58644, CVE-2026-58608, CVE-2026-48561, CVE-2026-55011, CVE-2026-55012, CVE-2026-54982, CVE-2026-54995, T1190, T1059, T1203, T1505, T1078, T1068, T1078, T1211, T1556, T1550