Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation (CVE-2026-56155, CVE-2026-56164)
Microsoft July 2026 Patch Tuesday (TL-2026-1330), also tracked as July 2026 Patch Tuesday, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-07-14. It has no confirmed attribution, affects Microsoft Active Directory Federation Services (AD FS), references 6 CVEs (CVE-2026-56155, CVE-2026-56164, CVE-2026-50661), maps to 15 MITRE ATT&CK techniques (T1005, T1068, T1078), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-1330
- Threat ID
- TL-2026-1330
- Also known as
- July 2026 Patch Tuesday, GreatXML
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, education, manufacturing
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Microsoft July 2026 Patch Tuesday
Malware and tooling: GreatXML
Microsoft's July 2026 Patch Tuesday addresses roughly 570 vulnerabilities (59 Critical) plus 427 additional Chromium flaws affecting Edge. Two vulnerabilities are already under active zero-day exploitation: CVE-2026-56155 (AD FS elevation of privilege, CVSS 7.8) and CVE-2026-56164 (SharePoint Server elevation of privilege, CVSS 5.3), both added to the CISA KEV catalog on 2026-07-14. A previously disclosed BitLocker security-feature-bypass, CVE-2026-50661, is also patched and is believed to correspond to the publicly demonstrated 'GreatXML' WinRE trust-boundary attack. Three additional Critical remote-code-execution flaws in the Windows DHCP Client and Reliable Multicast Transport Driver (RMCAST) round out the highest-priority items in the release.
How Microsoft July 2026 Patch Tuesday works
On 2026-07-14 Microsoft shipped its July Patch Tuesday, addressing approximately 570 CVEs (56-59 rated Critical, ~510 Important, 3 Moderate) plus 427 Chromium/Edge CVEs — reported by different outlets as 569 or 622 depending on counting methodology and Chromium inclusion. Two vulnerabilities are confirmed exploited in the wild as zero-days prior to patch availability.
CVE-2026-56155 is an elevation-of-privilege flaw in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control (CWE-1220). An authenticated, locally-positioned attacker can escalate to administrator privileges. Microsoft attributes discovery to its own Detection and Response Team (DART), indicating the flaw was found during incident-response work on a live compromise. Because AD FS underpins federated authentication trust across hybrid Azure AD/on-premises environments, successful exploitation risks broader identity-infrastructure compromise consistent with prior AD FS 'golden SAML' style attacks. CISA added it to the KEV catalog on 2026-07-14 with a 2026-07-28 remediation deadline.
CVE-2026-56164 is an elevation-of-privilege flaw in Microsoft SharePoint Server caused by missing authentication for a critical function (CWE-306), allowing an unauthenticated network attacker to escalate privileges. It affects SharePoint Enterprise Server 2016 (before build 16.0.5561.1001), SharePoint Server 2019 (before build 16.0.10417.20175), and SharePoint Server Subscription Edition (before build 16.0.19725.20434). It was credited to Jayson Frost (Mandiant) and Genwei Jiang together with the Google Cloud / Mandiant FLARE OTF team. Microsoft's interim mitigation is enabling AMSI integration with Request Body Scan mode set to Full. CISA's KEV entry carries an accelerated 2026-07-17 remediation deadline (3 days from disclosure), reflecting the elevated risk of SharePoint EoP bugs being chained with other flaws for full server takeover — a pattern seen repeatedly in prior on-premises SharePoint campaigns.
CVE-2026-50661 is a security-feature-bypass in Windows BitLocker (protection mechanism failure, CWE-693) requiring physical access to the target device; Microsoft rates it 'Exploitation Less Likely' and credits an anonymous researcher. The advisory description closely matches 'GreatXML,' a BitLocker bypass publicly disclosed on 2026-06-10 (one day after the June Patch Tuesday) by researcher Chaotic Eclipse (aka Nightmare Eclipse / MSNightmare). GreatXML abuses the WinRE (Windows Recovery Environment) trust boundary: on any system that has ever run a Microsoft Defender Offline scan, an attacker with physical access can copy a crafted unattend.xml file and a Recovery directory onto the recovery partition; WinRE processes these on reboot without proper integrity validation, granting full access to the BitLocker-protected volume without the recovery key.
Three further Critical RCEs round out the highest-severity items: CVE-2026-54128 (Windows DHCP Client, use-after-free, CWE-416, CVSS 8.4, rated 'Exploitation More Likely' by Microsoft, triggered by processing a malicious DHCP server response); CVE-2026-54982 (Reliable Multicast Transport Driver, integer underflow, CWE-191, CVSS 8.8, adjacent-network attack vector); and CVE-2026-54995 (RMCAST, use-after-free, CWE-416, CVSS 8.1, network attack vector). All three affect the current Windows 10/11 and Windows Server release matrix (Windows Server 2012 through 2025).
SANS ISC handler Johannes Ullrich, whose diary entry seeded this hunt, noted that despite the record CVE volume, patch workload should not scale proportionally: defenders 'still own the same number of Microsoft products,' with Microsoft attributing part of the volume increase to an internal AI-assisted vulnerability discovery pipeline.
MITRE ATT&CK techniques used in TL-2026-1330
Collection
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts
Discovery
T1082 System Information Discovery
Persistence
T1098 Account Manipulation; T1542 Pre-OS Boot
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Stealth
Credential Access
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
Resource Development
Reconnaissance
Affected products and versions in Microsoft July 2026 Patch Tuesday
- Microsoft — Active Directory Federation Services (AD FS)
Vulnerable versions: Windows Server 2012; Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022; Windows Server 2025
Fixed in: July 2026 cumulative update - Microsoft — SharePoint Enterprise Server 2016
Vulnerable versions: before 16.0.5561.1001
Fixed in: 16.0.5561.1001 and later - Microsoft — SharePoint Server 2019
Vulnerable versions: before 16.0.10417.20175
Fixed in: 16.0.10417.20175 and later - Microsoft — SharePoint Server Subscription Edition
Vulnerable versions: before 16.0.19725.20434
Fixed in: 16.0.19725.20434 and later - Microsoft — Windows BitLocker Device Encryption
Vulnerable versions: Windows 10 1607/1809/21H2/22H2; Windows 11 24H2/25H2/26H1; Windows Server 2016-2025
Fixed in: July 2026 cumulative update - Microsoft — Windows DHCP Client
Vulnerable versions: Windows 10 1607/1809/21H2/22H2; Windows 11 24H2/25H2/26H1; Windows Server 2012-2025
Fixed in: July 2026 cumulative update - Microsoft — Reliable Multicast Transport Driver (RMCAST)
Vulnerable versions: Windows 10 1607/1809/21H2/22H2; Windows 11 24H2/25H2/26H1; Windows Server 2012-2025
Fixed in: July 2026 cumulative update
Remediation for Microsoft July 2026 Patch Tuesday
Patches
- Install the July 2026 Microsoft security updates for AD FS-capable Windows Server builds (2012-2025) to remediate CVE-2026-56155
- Install the July 2026 SharePoint cumulative update remediating CVE-2026-56164 for SharePoint Enterprise Server 2016, Server 2019, and Server Subscription Edition
- Install the July 2026 Windows update remediating CVE-2026-50661 (BitLocker/GreatXML), CVE-2026-54128 (DHCP Client), CVE-2026-54982 and CVE-2026-54995 (RMCAST)
Immediate actions
- Apply the July 2026 cumulative updates covering CVE-2026-56155 and CVE-2026-56164 immediately; both are on the CISA KEV catalog with due dates of 2026-07-28 and 2026-07-17 respectively
- For SharePoint farms that cannot patch immediately, enable AMSI integration with Request Body Scan mode set to Full as an interim mitigation for CVE-2026-56164
- Hunt for AD FS admin-privilege anomalies and unexpected SAML token issuance consistent with golden-SAML-style abuse following CVE-2026-56155 exploitation
- Restrict physical access to endpoints and enforce pre-boot authentication / TPM+PIN to reduce BitLocker/GreatXML (CVE-2026-50661) exposure until patched
- Prioritize patching of internet-facing or DHCP-serving Windows hosts against CVE-2026-54128 given Microsoft's 'Exploitation More Likely' rating
Workarounds
- Disable or restrict the Reliable Multicast Transport Driver (RMCAST) where not required, to reduce exposure to CVE-2026-54982/CVE-2026-54995 pending patch
- Restrict DHCP client exposure to untrusted/adjacent networks where feasible pending patch for CVE-2026-54128
Longer-term hardening
- Deploy EDR/XDR coverage on AD FS and SharePoint servers with alerting on privilege-escalation and unauthenticated critical-function access patterns
- Establish a hybrid-identity monitoring baseline (AD FS token issuance, trust relationships) to catch abuse of federation infrastructure
- Adopt a scaled patch-management cadence for Microsoft's expanding monthly CVE volume, prioritizing KEV-listed and 'Exploitation More Likely' items over raw count
CVEs associated with Microsoft July 2026 Patch Tuesday
CVE-2026-56155, CVE-2026-56164, CVE-2026-50661, CVE-2026-54128, CVE-2026-54982, CVE-2026-54995
Weaknesses (CWE) in Microsoft July 2026 Patch Tuesday
CWE-1220, CWE-306, CWE-693, CWE-416, CWE-191
Timeline of Microsoft July 2026 Patch Tuesday
- GreatXML BitLocker bypass publicly disclosed by researcher Chaotic Eclipse (Nightmare Eclipse / MSNightmare), one day after Microsoft's June 2026 Patch Tuesday
- The Register reports on the 'Nightmare Eclipse' claimed BitLocker bypass, drawing wider security-industry attention to the WinRE trust-boundary issue
- BleepingComputer, Tenable, Security Boulevard, and CyberSecurityNews publish independent technical breakdowns of the July 2026 release, corroborating CVE counts and severity distribution
- SANS ISC handler Johannes Ullrich publishes diary entry 'Microsoft Patch Tuesday July 2026 - The AI Apocalypse is Here,' the sourcing article for this threat
- CVE-2026-50661 (BitLocker security-feature-bypass, believed to correspond to GreatXML) is patched and publicly disclosed but not confirmed as actively exploited
- CISA adds CVE-2026-56164 to the Known Exploited Vulnerabilities catalog with an accelerated remediation due date of 2026-07-17
- CISA adds CVE-2026-56155 to the Known Exploited Vulnerabilities catalog with a remediation due date of 2026-07-28
- Microsoft confirms CVE-2026-56155 (AD FS EoP) and CVE-2026-56164 (SharePoint EoP) were exploited in the wild as zero-days prior to patch release
- Microsoft releases July 2026 Patch Tuesday addressing approximately 570 vulnerabilities (59 Critical) plus 427 Chromium/Edge CVEs
Sources cited for Microsoft July 2026 Patch Tuesday
- Microsoft Patch Tuesday July 2026 - The AI Apocalypse is Here
- Microsoft's July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
- July 2026 Patch Tuesday: Largest Patch Tuesday 569 CVEs
- Record-Breaking Microsoft Patch Tuesday Update: 570 Vulnerabilities Fixed, Including 3 Zero-Days
- CISA KEV Catalog entry: CVE-2026-56155
- CISA KEV Catalog entry: CVE-2026-56164
- NVD CVE-2026-56155 detail
- NVD CVE-2026-56164 detail
- NVD CVE-2026-50661 detail
- NVD CVE-2026-54128 detail
- NVD CVE-2026-54982 detail
- NVD CVE-2026-54995 detail
- New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
- Nightmare Eclipse drops claimed BitLocker bypass for Microsoft Windows
Threats related to Microsoft July 2026 Patch Tuesday
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)
- CVE-2026-56164: Microsoft SharePoint Server Missing-Authentication Vulnerability Actively Exploited, Added to CISA KEV
- Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP)
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164 SharePoint) Among Record 570+ Fixes
Detection coverage for TL-2026-1330
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1330 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.