Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation (CVE-2026-56155, CVE-2026-56164)

Microsoft July 2026 Patch Tuesday (TL-2026-1330), also tracked as July 2026 Patch Tuesday, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-07-14. It has no confirmed attribution, affects Microsoft Active Directory Federation Services (AD FS), references 6 CVEs (CVE-2026-56155, CVE-2026-56164, CVE-2026-50661), maps to 15 MITRE ATT&CK techniques (T1005, T1068, T1078), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-1330

Threat ID
TL-2026-1330
Also known as
July 2026 Patch Tuesday, GreatXML
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-14
Last reviewed
2026-07-14
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, education, manufacturing
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
30

Malware and tooling in Microsoft July 2026 Patch Tuesday

Malware and tooling: GreatXML

Microsoft's July 2026 Patch Tuesday addresses roughly 570 vulnerabilities (59 Critical) plus 427 additional Chromium flaws affecting Edge. Two vulnerabilities are already under active zero-day exploitation: CVE-2026-56155 (AD FS elevation of privilege, CVSS 7.8) and CVE-2026-56164 (SharePoint Server elevation of privilege, CVSS 5.3), both added to the CISA KEV catalog on 2026-07-14. A previously disclosed BitLocker security-feature-bypass, CVE-2026-50661, is also patched and is believed to correspond to the publicly demonstrated 'GreatXML' WinRE trust-boundary attack. Three additional Critical remote-code-execution flaws in the Windows DHCP Client and Reliable Multicast Transport Driver (RMCAST) round out the highest-priority items in the release.

How Microsoft July 2026 Patch Tuesday works

On 2026-07-14 Microsoft shipped its July Patch Tuesday, addressing approximately 570 CVEs (56-59 rated Critical, ~510 Important, 3 Moderate) plus 427 Chromium/Edge CVEs — reported by different outlets as 569 or 622 depending on counting methodology and Chromium inclusion. Two vulnerabilities are confirmed exploited in the wild as zero-days prior to patch availability.

CVE-2026-56155 is an elevation-of-privilege flaw in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control (CWE-1220). An authenticated, locally-positioned attacker can escalate to administrator privileges. Microsoft attributes discovery to its own Detection and Response Team (DART), indicating the flaw was found during incident-response work on a live compromise. Because AD FS underpins federated authentication trust across hybrid Azure AD/on-premises environments, successful exploitation risks broader identity-infrastructure compromise consistent with prior AD FS 'golden SAML' style attacks. CISA added it to the KEV catalog on 2026-07-14 with a 2026-07-28 remediation deadline.

CVE-2026-56164 is an elevation-of-privilege flaw in Microsoft SharePoint Server caused by missing authentication for a critical function (CWE-306), allowing an unauthenticated network attacker to escalate privileges. It affects SharePoint Enterprise Server 2016 (before build 16.0.5561.1001), SharePoint Server 2019 (before build 16.0.10417.20175), and SharePoint Server Subscription Edition (before build 16.0.19725.20434). It was credited to Jayson Frost (Mandiant) and Genwei Jiang together with the Google Cloud / Mandiant FLARE OTF team. Microsoft's interim mitigation is enabling AMSI integration with Request Body Scan mode set to Full. CISA's KEV entry carries an accelerated 2026-07-17 remediation deadline (3 days from disclosure), reflecting the elevated risk of SharePoint EoP bugs being chained with other flaws for full server takeover — a pattern seen repeatedly in prior on-premises SharePoint campaigns.

CVE-2026-50661 is a security-feature-bypass in Windows BitLocker (protection mechanism failure, CWE-693) requiring physical access to the target device; Microsoft rates it 'Exploitation Less Likely' and credits an anonymous researcher. The advisory description closely matches 'GreatXML,' a BitLocker bypass publicly disclosed on 2026-06-10 (one day after the June Patch Tuesday) by researcher Chaotic Eclipse (aka Nightmare Eclipse / MSNightmare). GreatXML abuses the WinRE (Windows Recovery Environment) trust boundary: on any system that has ever run a Microsoft Defender Offline scan, an attacker with physical access can copy a crafted unattend.xml file and a Recovery directory onto the recovery partition; WinRE processes these on reboot without proper integrity validation, granting full access to the BitLocker-protected volume without the recovery key.

Three further Critical RCEs round out the highest-severity items: CVE-2026-54128 (Windows DHCP Client, use-after-free, CWE-416, CVSS 8.4, rated 'Exploitation More Likely' by Microsoft, triggered by processing a malicious DHCP server response); CVE-2026-54982 (Reliable Multicast Transport Driver, integer underflow, CWE-191, CVSS 8.8, adjacent-network attack vector); and CVE-2026-54995 (RMCAST, use-after-free, CWE-416, CVSS 8.1, network attack vector). All three affect the current Windows 10/11 and Windows Server release matrix (Windows Server 2012 through 2025).

SANS ISC handler Johannes Ullrich, whose diary entry seeded this hunt, noted that despite the record CVE volume, patch workload should not scale proportionally: defenders 'still own the same number of Microsoft products,' with Microsoft attributing part of the volume increase to an internal AI-assisted vulnerability discovery pipeline.

MITRE ATT&CK techniques used in TL-2026-1330

Collection

T1005 Data from Local System

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts

Discovery

T1082 System Information Discovery

Persistence

T1098 Account Manipulation; T1542 Pre-OS Boot

Initial Access

T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution

Lateral Movement

T1210 Exploitation of Remote Services

Defense Evasion

T1211 Exploitation for Stealth

Credential Access

T1552 Unsecured Credentials

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Resource Development

T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning

Affected products and versions in Microsoft July 2026 Patch Tuesday

  • Microsoft — Active Directory Federation Services (AD FS)
    Vulnerable versions: Windows Server 2012; Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022; Windows Server 2025
    Fixed in: July 2026 cumulative update
  • Microsoft — SharePoint Enterprise Server 2016
    Vulnerable versions: before 16.0.5561.1001
    Fixed in: 16.0.5561.1001 and later
  • Microsoft — SharePoint Server 2019
    Vulnerable versions: before 16.0.10417.20175
    Fixed in: 16.0.10417.20175 and later
  • Microsoft — SharePoint Server Subscription Edition
    Vulnerable versions: before 16.0.19725.20434
    Fixed in: 16.0.19725.20434 and later
  • Microsoft — Windows BitLocker Device Encryption
    Vulnerable versions: Windows 10 1607/1809/21H2/22H2; Windows 11 24H2/25H2/26H1; Windows Server 2016-2025
    Fixed in: July 2026 cumulative update
  • Microsoft — Windows DHCP Client
    Vulnerable versions: Windows 10 1607/1809/21H2/22H2; Windows 11 24H2/25H2/26H1; Windows Server 2012-2025
    Fixed in: July 2026 cumulative update
  • Microsoft — Reliable Multicast Transport Driver (RMCAST)
    Vulnerable versions: Windows 10 1607/1809/21H2/22H2; Windows 11 24H2/25H2/26H1; Windows Server 2012-2025
    Fixed in: July 2026 cumulative update

Remediation for Microsoft July 2026 Patch Tuesday

Patches

  • Install the July 2026 Microsoft security updates for AD FS-capable Windows Server builds (2012-2025) to remediate CVE-2026-56155
  • Install the July 2026 SharePoint cumulative update remediating CVE-2026-56164 for SharePoint Enterprise Server 2016, Server 2019, and Server Subscription Edition
  • Install the July 2026 Windows update remediating CVE-2026-50661 (BitLocker/GreatXML), CVE-2026-54128 (DHCP Client), CVE-2026-54982 and CVE-2026-54995 (RMCAST)

Immediate actions

  • Apply the July 2026 cumulative updates covering CVE-2026-56155 and CVE-2026-56164 immediately; both are on the CISA KEV catalog with due dates of 2026-07-28 and 2026-07-17 respectively
  • For SharePoint farms that cannot patch immediately, enable AMSI integration with Request Body Scan mode set to Full as an interim mitigation for CVE-2026-56164
  • Hunt for AD FS admin-privilege anomalies and unexpected SAML token issuance consistent with golden-SAML-style abuse following CVE-2026-56155 exploitation
  • Restrict physical access to endpoints and enforce pre-boot authentication / TPM+PIN to reduce BitLocker/GreatXML (CVE-2026-50661) exposure until patched
  • Prioritize patching of internet-facing or DHCP-serving Windows hosts against CVE-2026-54128 given Microsoft's 'Exploitation More Likely' rating

Workarounds

  • Disable or restrict the Reliable Multicast Transport Driver (RMCAST) where not required, to reduce exposure to CVE-2026-54982/CVE-2026-54995 pending patch
  • Restrict DHCP client exposure to untrusted/adjacent networks where feasible pending patch for CVE-2026-54128

Longer-term hardening

  • Deploy EDR/XDR coverage on AD FS and SharePoint servers with alerting on privilege-escalation and unauthenticated critical-function access patterns
  • Establish a hybrid-identity monitoring baseline (AD FS token issuance, trust relationships) to catch abuse of federation infrastructure
  • Adopt a scaled patch-management cadence for Microsoft's expanding monthly CVE volume, prioritizing KEV-listed and 'Exploitation More Likely' items over raw count

CVEs associated with Microsoft July 2026 Patch Tuesday

CVE-2026-56155, CVE-2026-56164, CVE-2026-50661, CVE-2026-54128, CVE-2026-54982, CVE-2026-54995

Weaknesses (CWE) in Microsoft July 2026 Patch Tuesday

CWE-1220, CWE-306, CWE-693, CWE-416, CWE-191

Timeline of Microsoft July 2026 Patch Tuesday

  • GreatXML BitLocker bypass publicly disclosed by researcher Chaotic Eclipse (Nightmare Eclipse / MSNightmare), one day after Microsoft's June 2026 Patch Tuesday
  • The Register reports on the 'Nightmare Eclipse' claimed BitLocker bypass, drawing wider security-industry attention to the WinRE trust-boundary issue
  • BleepingComputer, Tenable, Security Boulevard, and CyberSecurityNews publish independent technical breakdowns of the July 2026 release, corroborating CVE counts and severity distribution
  • SANS ISC handler Johannes Ullrich publishes diary entry 'Microsoft Patch Tuesday July 2026 - The AI Apocalypse is Here,' the sourcing article for this threat
  • CVE-2026-50661 (BitLocker security-feature-bypass, believed to correspond to GreatXML) is patched and publicly disclosed but not confirmed as actively exploited
  • CISA adds CVE-2026-56164 to the Known Exploited Vulnerabilities catalog with an accelerated remediation due date of 2026-07-17
  • CISA adds CVE-2026-56155 to the Known Exploited Vulnerabilities catalog with a remediation due date of 2026-07-28
  • Microsoft confirms CVE-2026-56155 (AD FS EoP) and CVE-2026-56164 (SharePoint EoP) were exploited in the wild as zero-days prior to patch release
  • Microsoft releases July 2026 Patch Tuesday addressing approximately 570 vulnerabilities (59 Critical) plus 427 Chromium/Edge CVEs

Sources cited for Microsoft July 2026 Patch Tuesday

Threats related to Microsoft July 2026 Patch Tuesday

Detection coverage for TL-2026-1330

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1330 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats