Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP) — Threadlinqs Intelligence
As of 2026-07-14, Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-1327 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Microsoft's July 2026 Patch Tuesday is its largest release on record (569 CVEs, 56-59 rated Critical), fixing two zero-days confirmed exploited in the wild by Microsoft's DART incident-response team:
On July 14, 2026, Microsoft released its largest Patch Tuesday to date, addressing 569 vulnerabilities across the Windows and Microsoft 365 ecosystem (56-59 rated Critical, ~510 Important; figures vary slightly by counting methodology and exclude the 468 separately-tracked Chromium/Edge fixes). Three zero-days were disclosed, two of which CISA confirmed as actively exploited in the wild and added to the Known Exploited Vulnerabilities (KEV) catalog on the same day.
CVE-2026-56155 is an Insufficient Granularity of Access Control (CWE-1220) vulnerability in Active Directory Federation Services (AD FS), CVSS 3.1 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). A locally-authorized attacker can elevate to administrator privileges. It was reported by Jeremy Kingston and Scott Clark of Microsoft's Detection and Response Team (DART), strongly suggesting it was discovered during incident response to an active intrusion rather than proactive research. Microsoft has not disclosed exploitation methodology. Because AD FS underpins federated authentication trust across hybrid Azure AD/on-premises environments, exploitation risks pivoting toward broader identity-infrastructure compromise, structurally similar in impact to prior AD FS golden-SAML style token-forging abuse (though no confirmed golden-SAML linkage has been published for this CVE). CISA KEV due date: 2026-07-28.
CVE-2026-56164 is a Missing Authentication for Critical Function (CWE-306) vulnerability in Microsoft SharePoint Server, CVSS 3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). An unauthenticated network attacker can send a crafted POST request to elevate privileges over the network without credentials or user interaction. Affects SharePoint Server 2019, SharePoint Server Subscription Edition, SharePoint Server 2016, and SharePoint Enterprise Server 2016. Microsoft credits Jayson Frost (Mandiant), Genwei Jiang (Google Cloud FLARE/OTF), and an anonymous researcher. Microsoft's guidance recommends enabling Antimalware Scan Interface (AMSI) with Request Body Scan set to Full mode to detect malicious POST requests as a compensating control. CISA KEV due date: 2026-07-17 (accelerated, reflecting active exploitation urgency). Despite the 'Moderate' CVSS label, on-prem SharePoint farms are a top patch priority: SharePoint EoP bugs have repeatedly been chained by attackers with separate RCE vulnerabilities for full server takeover (as seen with the concurrently-exploited, CISA-KEV-listed CVE-2026-45659 SharePoint RCE, a related but distinct flaw in the same product patched around the same period).
CVE-2026-55944 is a Deserialization of Untrusted Data (CWE-502) RCE in Microsoft Dynamics NAV and Dynamics 365 Business Central (On-Premises), CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An unauthenticated remote attacker sends a crafted login request that triggers deserialization of attacker-controlled data, resulting in code execution with no authentication or user interaction required. Affects Dynamics NAV 2018 versions prior to 11.0.50704.0. Microsoft rates this 'Exploitation More Likely' though it is not (yet) confirmed exploited in the wild.
CVE-2026-50518 is a Critical Windows DHCP Server RCE, CVSS 9.8, also rated 'Exploitation More Likely' by Microsoft. Related DHCP-stack flaws patched the same day include CVE-2026-50370 (DHCP Server RCE, CVSS 8.8, Exploitation More Likely) and CVE-2026-54128 (DHCP Client RCE, CVSS 8.4, Exploitation More Likely), plus CVE-2026-56159 (DHCP Server RCE, CVSS 9.8, Exploitation Unlikely) — collectively indicating a concentrated set of weaknesses in the Windows DHCP implementation this cycle that warrant prioritized patching of DHCP infrastructure regardless of individual likelihood ratings.
CVE-2026-50661 is a Windows BitLocker Security Feature Bypass, CVSS 6.1, publicly disclosed prior to patch availability (Microsoft 'Exploitation Less Likely'). Exploitation requires physical access to the target device to bypass Device Encryption and access d
Weaknesses (CWE)
CWE-1220, CWE-306, CWE-502
Target sectors: government administration, finance, health, technology, manufacturing, education, retail, energy
Target regions: North America, Europe, Asia Pacific, Global
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-56155, CVE-2026-56164, CVE-2026-55944, CVE-2026-50518, CVE-2026-50661, CVE-2026-50370, CVE-2026-54128, CVE-2026-56159, CVE-2026-48564, CVE-2026-54118, T1068, T1190, T1203, T1211, T1528, T1606, T1078, T1082, T1210, T1140