Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS (CVE-2026-56155), SharePoint (CVE-2026-56164) Exploited; BitLocker (CVE-2026-50661) Publicly Disclosed
Windows 10 KB5099539 Extended Security Update Patches July (TL-2026-1326), also tracked as July 2026 Patch Tuesday, is a high-severity software vulnerability scored CVSS 7.8, first published 2026-07-14. It has no confirmed attribution, affects Microsoft Windows 10, references 3 CVEs (CVE-2026-56155, CVE-2026-56164, CVE-2026-50661), maps to 14 MITRE ATT&CK techniques (T1005, T1068, T1082), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-1326
- Threat ID
- TL-2026-1326
- Also known as
- July 2026 Patch Tuesday, KB5099539
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, education, manufacturing, enterprise, critical-infrastructure
- Target regions
- Global, North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in Windows 10 KB5099539 Extended Security Update Patches July
Malware and tooling: AMSI (Antimalware Scan Interface)
Microsoft's KB5099539 (Windows 10 build 19045.7548 / Windows 10 Enterprise LTSC 2021 build 19044.7548) rolls in the July 2026 Patch Tuesday rollup of 570 vulnerabilities, including two actively exploited elevation-of-privilege zero-days in Active Directory Federation Services (CVE-2026-56155) and SharePoint Server (CVE-2026-56164), plus one publicly disclosed BitLocker Security Feature Bypass (CVE-2026-50661). CISA added CVE-2026-56164 to the KEV catalog on 2026-07-14 with a July 17, 2026 remediation deadline under BOD 26-04.
How Windows 10 KB5099539 Extended Security Update Patches July works
On July 14, 2026 Microsoft released KB5099539 for Windows 10 (build 19045.7548) and Windows 10 Enterprise LTSC 2021 (build 19044.7548) as part of the Extended Security Update (ESU) program, extending support through October 12, 2027. The update is bundled into Microsoft's broader July 2026 Patch Tuesday release, which fixed 570 vulnerabilities — the largest monthly total to date, attributed by Microsoft to an AI-powered vulnerability discovery system scanning the Windows codebase. The breakdown across the full rollup is 254 elevation-of-privilege, 145 remote code execution, 102 information disclosure, 35 denial-of-service, 17 security-feature-bypass, and 16 spoofing bugs, with 59 rated Critical (48 RCE, 9 EoP, 1 security bypass, 1 spoofing).
Three zero-days anchor the release. CVE-2026-56155 is an Active Directory Federation Services (AD FS) elevation-of-privilege flaw (CWE-1220, insufficient granularity of access control) rated CVSS 3.1 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) that lets an authorized local attacker escalate to full administrative privileges; Microsoft credited its own Detection and Response Team (DART) researchers Jeremy Kingston and Scott Clark, a credit pattern that typically indicates the bug was found while investigating live intrusions. CVE-2026-56164 is a SharePoint Server elevation-of-privilege vulnerability (CWE-306, missing authentication for a critical function) rated CVSS 3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) allowing an unauthenticated network attacker to elevate privileges; it was credited to Jayson Frost (Mandiant), Genwei Jiang (Google Cloud), and an anonymous researcher, and Microsoft's interim mitigation is to enable AMSI and set SharePoint's Request Body Scan mode to Full. CISA added CVE-2026-56164 to its Known Exploited Vulnerabilities catalog on 2026-07-14 with a mandated remediation deadline of 2026-07-17 under Binding Operational Directive 26-04. CVE-2026-50661 is a publicly disclosed Windows BitLocker Security Feature Bypass (CWE-693, protection mechanism failure) rated CVSS 3.1 6.1 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) that lets an attacker with physical access to a device bypass BitLocker Device Encryption and read the underlying encrypted volume; Microsoft credited an anonymous researcher and has not disclosed in-the-wild exploitation.
The source article does not enumerate the remaining 567 CVEs, so this record documents only the three zero-days plus the notable Critical RCEs Microsoft separately called out (Defender: CVE-2026-55011/CVE-2026-55012; Copilot: CVE-2026-48561; DHCP: CVE-2026-54128, CVE-2026-50518, CVE-2026-50370, CVE-2026-56159, CVE-2026-48564; Graphics/Media: CVE-2026-50382, CVE-2026-49796, CVE-2026-50380, CVE-2026-50655, CVE-2026-50327, CVE-2026-58542). KB5099539 also carries non-security hardening (TDI transport registration enforcement, flagged via Event ID 16003 for legacy third-party transports; SHA-2 certificate thumbprint support for RDP publishers; enhanced Secure Boot certificate deployment) and fixes for OLE Automation compatibility, OneDrive shortcuts in File Explorer admin mode, Recycle Bin file naming, and input hotkey lifecycle behavior.
MITRE ATT&CK techniques used in TL-2026-1326
Collection
T1005 Data from Local System; T1213 Data from Information Repositories
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1484 Domain or Tenant Policy Modification; T1548 Abuse Elevation Control Mechanism
Discovery
T1082 System Information Discovery
Persistence
Initial Access
T1190 Exploit Public-Facing Application; T1200 Hardware Additions
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Stealth
defense-impairment
T1556 Modify Authentication Process; T1600 Weaken Encryption
Credential Access
Affected products and versions in Windows 10 KB5099539 Extended Security Update Patches July
- Microsoft — Windows 10
Vulnerable versions: 1607; 1809; 21H2; 22H2
Fixed in: 19045.7548 (KB5099539) - Microsoft — Windows 10 Enterprise LTSC 2021
Vulnerable versions: 19044.x
Fixed in: 19044.7548 (KB5099539) - Microsoft — Windows 11
Vulnerable versions: 24H2; 25H2; 26H1
Fixed in: July 2026 cumulative update - Microsoft — Windows Server (Active Directory Federation Services role)
Vulnerable versions: 2012; 2012 R2; 2016; 2019; 2022; 2025
Fixed in: July 2026 cumulative update - Microsoft — SharePoint Enterprise Server 2016
Vulnerable versions: < 16.0.5561.1001
Fixed in: 16.0.5561.1001 - Microsoft — SharePoint Server 2019
Vulnerable versions: < 16.0.10417.20175
Fixed in: 16.0.10417.20175 - Microsoft — SharePoint Server Subscription Edition
Vulnerable versions: < 16.0.19725.20434
Fixed in: 16.0.19725.20434
Remediation for Windows 10 KB5099539 Extended Security Update Patches July
Patches
- KB5099539 (Windows 10 19045.7548 / Windows 10 Enterprise LTSC 2021 19044.7548)
- Cumulative update remediating CVE-2026-56155 on affected Windows Server 2012/2012 R2/2016/2019/2022/2025 AD FS role hosts
- SharePoint Enterprise Server 2016 update to 16.0.5561.1001 or later
- SharePoint Server 2019 update to 16.0.10417.20175 or later
- SharePoint Server Subscription Edition update to 16.0.19725.20434 or later
- Cumulative update remediating CVE-2026-50661 on affected Windows 10/11 and Windows Server builds
Immediate actions
- Deploy KB5099539 to all Windows 10 (19045.7548) and Windows 10 Enterprise LTSC 2021 (19044.7548) ESU-enrolled endpoints
- Patch CVE-2026-56164 (SharePoint EoP) by 2026-07-17 per CISA BOD 26-04 KEV deadline
- Patch CVE-2026-56155 (AD FS EoP) by 2026-07-28 per CISA mandatory mitigation guidance
- Enable AMSI and set SharePoint Request Body Scan mode to Full as an interim mitigation for CVE-2026-56164 pending patch deployment
- Audit AD FS server local-admin membership and access-control granularity for signs of privilege abuse consistent with CVE-2026-56155
- Monitor Event Viewer for Event ID 16003 on systems using third-party TDI network transports before deploying KB5099539
Workarounds
- SharePoint: enable AMSI + Request Body Scan mode Full where patching CVE-2026-56164 cannot occur immediately
- BitLocker: enforce pre-boot authentication (PIN/TPM+PIN) to reduce the CVE-2026-50661 physical-access attack window
Longer-term hardening
- Enforce physical security controls (full-disk pre-boot PIN, TPM+PIN) to reduce exposure to the CVE-2026-50661 BitLocker physical bypass
- Establish SLA-driven patch cadence for Patch Tuesday releases given the 570-vulnerability scale of this rollup
- Extend AD FS Golden-SAML detection tooling (token-signing certificate monitoring, SAML assertion anomaly detection) given the federation-server exposure introduced by CVE-2026-56155
- Review legacy third-party TDI transport dependencies ahead of future enforcement changes
CVEs associated with Windows 10 KB5099539 Extended Security Update Patches July
Weaknesses (CWE) in Windows 10 KB5099539 Extended Security Update Patches July
CWE-1220, CWE-306, CWE-693
Timeline of Windows 10 KB5099539 Extended Security Update Patches July
- Microsoft's June 2026 Patch Tuesday fixed a then-record 206 flaws including the RoguePlanet Windows Defender zero-day, setting the baseline that July 2026's 570-flaw rollup would dwarf.
- CISA separately warned of active exploitation of a different SharePoint RCE (CVE-2026-45659) days ahead of the July rollup, heightening scrutiny on SharePoint patching.
- CISA added CVE-2026-56164 to the Known Exploited Vulnerabilities catalog, setting a mandatory federal remediation deadline of 2026-07-17 under BOD 26-04.
- CVE-2026-50661 (Windows BitLocker Security Feature Bypass, publicly disclosed) patched, credited to an anonymous researcher; no in-the-wild exploitation confirmed by Microsoft.
- CVE-2026-56164 (SharePoint Server elevation of privilege, actively exploited) disclosed and patched, credited to Jayson Frost (Mandiant), Genwei Jiang (Google Cloud), and an anonymous researcher.
- CVE-2026-56155 (AD FS elevation of privilege, actively exploited) disclosed and patched, credited to Microsoft DART researchers Jeremy Kingston and Scott Clark.
- Microsoft released KB5099539 for Windows 10 (build 19045.7548) and Windows 10 Enterprise LTSC 2021 (build 19044.7548) as part of the Extended Security Update program, bundling the July rollup fixes.
- Microsoft published its July 2026 Patch Tuesday release addressing 570 vulnerabilities, including two actively exploited zero-days (CVE-2026-56155, CVE-2026-56164) and one publicly disclosed zero-day (CVE-2026-50661).
- CISA-mandated remediation deadline for CVE-2026-56164 under BOD 26-04.
- CISA-flagged mandatory mitigation deadline for CVE-2026-56155 (AD FS elevation of privilege).
Sources cited for Windows 10 KB5099539 Extended Security Update Patches July
- Microsoft releases Windows 10 KB5099539 Extended Security Update
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation (July 2026 SharePoint threat landscape context)
- CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
- July 2026 Patch Tuesday forecast: Is CVE tracking still practical?
- Microsoft Security Update Guide: CVE-2026-56155
- Microsoft Security Update Guide: CVE-2026-56164
- Microsoft Security Update Guide: CVE-2026-50661
- CISA Known Exploited Vulnerabilities Catalog
Threats related to Windows 10 KB5099539 Extended Security Update Patches July
- Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164)
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164 SharePoint) Among Record 570+ Fixes
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)
- Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP)
Detection coverage for TL-2026-1326
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1326 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.