Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation (CVE-2026-56155, CVE-2026-56164) — Threadlinqs Intelligence
As of 2026-07-14, Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation (CVE-2026-56155, CVE-2026-56164) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1330 · Severity: HIGH · CVSS: 8.8 · Status: ACTIVE · Category: VULNERABILITY
Microsoft's July 2026 Patch Tuesday addresses roughly 570 vulnerabilities (59 Critical) plus 427 additional Chromium flaws affecting Edge. Two vulnerabilities are already under active zero-day
On 2026-07-14 Microsoft shipped its July Patch Tuesday, addressing approximately 570 CVEs (56-59 rated Critical, ~510 Important, 3 Moderate) plus 427 Chromium/Edge CVEs — reported by different outlets as 569 or 622 depending on counting methodology and Chromium inclusion. Two vulnerabilities are confirmed exploited in the wild as zero-days prior to patch availability.
CVE-2026-56155 is an elevation-of-privilege flaw in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control (CWE-1220). An authenticated, locally-positioned attacker can escalate to administrator privileges. Microsoft attributes discovery to its own Detection and Response Team (DART), indicating the flaw was found during incident-response work on a live compromise. Because AD FS underpins federated authentication trust across hybrid Azure AD/on-premises environments, successful exploitation risks broader identity-infrastructure compromise consistent with prior AD FS 'golden SAML' style attacks. CISA added it to the KEV catalog on 2026-07-14 with a 2026-07-28 remediation deadline.
CVE-2026-56164 is an elevation-of-privilege flaw in Microsoft SharePoint Server caused by missing authentication for a critical function (CWE-306), allowing an unauthenticated network attacker to escalate privileges. It affects SharePoint Enterprise Server 2016 (before build 16.0.5561.1001), SharePoint Server 2019 (before build 16.0.10417.20175), and SharePoint Server Subscription Edition (before build 16.0.19725.20434). It was credited to Jayson Frost (Mandiant) and Genwei Jiang together with the Google Cloud / Mandiant FLARE OTF team. Microsoft's interim mitigation is enabling AMSI integration with Request Body Scan mode set to Full. CISA's KEV entry carries an accelerated 2026-07-17 remediation deadline (3 days from disclosure), reflecting the elevated risk of SharePoint EoP bugs being chained with other flaws for full server takeover — a pattern seen repeatedly in prior on-premises SharePoint campaigns.
CVE-2026-50661 is a security-feature-bypass in Windows BitLocker (protection mechanism failure, CWE-693) requiring physical access to the target device; Microsoft rates it 'Exploitation Less Likely' and credits an anonymous researcher. The advisory description closely matches 'GreatXML,' a BitLocker bypass publicly disclosed on 2026-06-10 (one day after the June Patch Tuesday) by researcher Chaotic Eclipse (aka Nightmare Eclipse / MSNightmare). GreatXML abuses the WinRE (Windows Recovery Environment) trust boundary: on any system that has ever run a Microsoft Defender Offline scan, an attacker with physical access can copy a crafted unattend.xml file and a Recovery directory onto the recovery partition; WinRE processes these on reboot without proper integrity validation, granting full access to the BitLocker-protected volume without the recovery key.
Three further Critical RCEs round out the highest-severity items: CVE-2026-54128 (Windows DHCP Client, use-after-free, CWE-416, CVSS 8.4, rated 'Exploitation More Likely' by Microsoft, triggered by processing a malicious DHCP server response); CVE-2026-54982 (Reliable Multicast Transport Driver, integer underflow, CWE-191, CVSS 8.8, adjacent-network attack vector); and CVE-2026-54995 (RMCAST, use-after-free, CWE-416, CVSS 8.1, network attack vector). All three affect the current Windows 10/11 and Windows Server release matrix (Windows Server 2012 through 2025).
SANS ISC handler Johannes Ullrich, whose diary entry seeded this hunt, noted that despite the record CVE volume, patch workload should not scale proportionally: defenders 'still own the same number of Microsoft products,' with Microsoft attributing part of the volume increase to an internal AI-assisted vulnerability discovery pipeline.
Weaknesses (CWE)
CWE-1220, CWE-306, CWE-693, CWE-416, CWE-191
Target sectors: government administration, finance, health, technology, education, manufacturing
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-56155, CVE-2026-56164, CVE-2026-50661, CVE-2026-54128, CVE-2026-54982, CVE-2026-54995, T1190, T1203, T1098, T1068, T1078, T1211, T1553, T1552, T1210, T1005