Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS (CVE-2026-56155), SharePoint (CVE-2026-56164) Exploited; BitLocker (CVE-2026-50661) Publicly Disclosed — Threadlinqs Intelligence
As of 2026-07-14, Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS (CVE-2026-56155), SharePoint (CVE-2026-56164) Exploited; BitLocker (CVE-2026-50661) Publicly Disclosed is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1326 · Severity: HIGH · CVSS: 7.8 · Status: ACTIVE · Category: VULNERABILITY
Microsoft's KB5099539 (Windows 10 build 19045.7548 / Windows 10 Enterprise LTSC 2021 build 19044.7548) rolls in the July 2026 Patch Tuesday rollup of 570 vulnerabilities, including two actively
On July 14, 2026 Microsoft released KB5099539 for Windows 10 (build 19045.7548) and Windows 10 Enterprise LTSC 2021 (build 19044.7548) as part of the Extended Security Update (ESU) program, extending support through October 12, 2027. The update is bundled into Microsoft's broader July 2026 Patch Tuesday release, which fixed 570 vulnerabilities — the largest monthly total to date, attributed by Microsoft to an AI-powered vulnerability discovery system scanning the Windows codebase. The breakdown across the full rollup is 254 elevation-of-privilege, 145 remote code execution, 102 information disclosure, 35 denial-of-service, 17 security-feature-bypass, and 16 spoofing bugs, with 59 rated Critical (48 RCE, 9 EoP, 1 security bypass, 1 spoofing).
Three zero-days anchor the release. CVE-2026-56155 is an Active Directory Federation Services (AD FS) elevation-of-privilege flaw (CWE-1220, insufficient granularity of access control) rated CVSS 3.1 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) that lets an authorized local attacker escalate to full administrative privileges; Microsoft credited its own Detection and Response Team (DART) researchers Jeremy Kingston and Scott Clark, a credit pattern that typically indicates the bug was found while investigating live intrusions. CVE-2026-56164 is a SharePoint Server elevation-of-privilege vulnerability (CWE-306, missing authentication for a critical function) rated CVSS 3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) allowing an unauthenticated network attacker to elevate privileges; it was credited to Jayson Frost (Mandiant), Genwei Jiang (Google Cloud), and an anonymous researcher, and Microsoft's interim mitigation is to enable AMSI and set SharePoint's Request Body Scan mode to Full. CISA added CVE-2026-56164 to its Known Exploited Vulnerabilities catalog on 2026-07-14 with a mandated remediation deadline of 2026-07-17 under Binding Operational Directive 26-04. CVE-2026-50661 is a publicly disclosed Windows BitLocker Security Feature Bypass (CWE-693, protection mechanism failure) rated CVSS 3.1 6.1 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) that lets an attacker with physical access to a device bypass BitLocker Device Encryption and read the underlying encrypted volume; Microsoft credited an anonymous researcher and has not disclosed in-the-wild exploitation.
The source article does not enumerate the remaining 567 CVEs, so this record documents only the three zero-days plus the notable Critical RCEs Microsoft separately called out (Defender: CVE-2026-55011/CVE-2026-55012; Copilot: CVE-2026-48561; DHCP: CVE-2026-54128, CVE-2026-50518, CVE-2026-50370, CVE-2026-56159, CVE-2026-48564; Graphics/Media: CVE-2026-50382, CVE-2026-49796, CVE-2026-50380, CVE-2026-50655, CVE-2026-50327, CVE-2026-58542). KB5099539 also carries non-security hardening (TDI transport registration enforcement, flagged via Event ID 16003 for legacy third-party transports; SHA-2 certificate thumbprint support for RDP publishers; enhanced Secure Boot certificate deployment) and fixes for OLE Automation compatibility, OneDrive shortcuts in File Explorer admin mode, Recycle Bin file naming, and input hotkey lifecycle behavior.
Weaknesses (CWE)
CWE-1220, CWE-306, CWE-693
Target sectors: government administration, finance, health, technology, education, manufacturing, enterprise, critical-infrastructure
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-56155, CVE-2026-56164, CVE-2026-50661, T1190, T1200, T1068, T1484, T1556, T1548, T1600, T1211, T1556, T1606