Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164)
Microsoft July 2026 Patch Tuesday (TL-2026-1331), also tracked as July 2026 Patch Tuesday, is a critical-severity software vulnerability scored CVSS 7.8, first published 2026-07-14. It has no confirmed attribution, affects Microsoft Active Directory Federation Services (AD FS), references 17 CVEs (CVE-2026-56155, CVE-2026-56164, CVE-2026-50661), maps to 15 MITRE ATT&CK techniques (T1046, T1068, T1078), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-1331
- Threat ID
- TL-2026-1331
- Also known as
- July 2026 Patch Tuesday, MSRC July 2026 Release, Microsoft Bug Apocalypse July 2026
- Severity
- CRITICAL
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, education, critical-infrastructure, professional-services
- Target regions
- North America, Europe, Asia Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 17
Microsoft's July 2026 Patch Tuesday shattered all prior records, addressing roughly 570-622 CVEs (source counts vary: 569, 570, 621, 622) including two zero-days confirmed under active exploitation and added to the CISA KEV catalog: CVE-2026-56155, an Active Directory Federation Services (AD FS) elevation-of-privilege flaw (CVSS 7.8), and CVE-2026-56164, a SharePoint Server missing-authentication elevation-of-privilege flaw (CVSS 5.3). A third zero-day, CVE-2026-50661 (Windows BitLocker security-feature bypass), was publicly disclosed but not confirmed exploited. 56-63 of the CVEs fixed this cycle were rated Critical, including several CVSS 9.8-9.9 remote code execution flaws.
How Microsoft July 2026 Patch Tuesday works
On July 14, 2026, Microsoft released its largest Patch Tuesday on record, addressing between 569 and 622 CVEs depending on the counting methodology used by different research teams (Trend Micro/ZDI cites 569-621; other outlets cite 570 or 622) — more than triple June 2026's prior record of 206. Security researchers including Dustin Childs of Trend Micro's Zero Day Initiative called it 'the mother of all releases' and 'the bug apocalypse,' while Satnam Narang of Tenable attributed the volume growth to AI-assisted vulnerability discovery tooling (referred to in coverage as MDASH) rather than a genuine spike in underlying risk. Microsoft is now projecting it will exceed 2,000-3,000 disclosed CVEs for calendar year 2026, well above 2020's prior full-year record of 1,245.
Two vulnerabilities in this release were confirmed as zero-days under active exploitation in the wild and were added to CISA's Known Exploited Vulnerabilities (KEV) catalog on the release date:
1. **CVE-2026-56155** — an elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control (CWE-1220). CVSS 3.1 base score 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) — a locally-authenticated, low-privileged attacker can escalate to administrator. Microsoft credits the discovery to Jeremy Kingston and Scott Clark of its own Detection and Response Team (DART), the incident-response unit that investigates active intrusions — a strong signal the bug was found via forensics on a real compromise rather than proactive research. Because AD FS underpins federated authentication trust across hybrid Azure AD / on-premises environments, ZDI analysts flagged it as a high-value pivot point for identity-infrastructure compromise, drawing comparisons to historical 'Golden SAML' token-forgery attack patterns against AD FS token-signing certificates. Affects Windows Server 2012 through Windows Server 2025 and Windows 10 hosts running the AD FS role. CISA set a remediation due date of July 28, 2026.
2. **CVE-2026-56164** — an elevation-of-privilege vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function (CWE-306). CVSS 3.1 base score 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) — despite the 'Moderate' label, it is unauthenticated, network-reachable, and requires no user interaction, letting a remote attacker elevate privileges over the network. Credited to Jayson Frost (Mandiant) and Genwei Jiang (Google Cloud) — both threat-intelligence firms with histories of tracking SharePoint on-prem exploitation by espionage actors. Affects SharePoint Enterprise Server 2016 (< 16.0.5561.1001), SharePoint Server 2019 (< 16.0.10417.20175), and SharePoint Server Subscription Edition (< 16.0.19725.20434). Microsoft's stated mitigation is enabling Antimalware Scan Interface (AMSI) integration with Request Body Scan mode set to Full, which can detect malicious POST requests exploiting the flaw. CISA set an accelerated remediation due date of July 17, 2026 (3 days), reflecting the low exploitation bar and SharePoint's history as a preferred on-prem target for state-linked intrusion sets (ToolShell/CVE-2025-53770 lineage).
A third notable zero-day, **CVE-2026-50661**, is a Windows BitLocker Device Encryption security-feature-bypass vulnerability that was publicly disclosed prior to patch availability, though not confirmed as actively exploited. It requires physical access to the target device and exploits weaknesses in BitLocker's recovery environment rather than the core encryption implementation — researchers drew a direct parallel to the earlier 2026 BitLocker recovery-environment bypass tracked as CVE-2026-45585.
Beyond the zero-days, the release included a large cluster of Critical-rated remote code execution flaws: CVE-2026-57092 (Windows VMSwitch EoP, CVSS 9.9, use-after-free enabling guest-to-host VM escape — the highest score of the cycle); a matched pair of SharePoint deserialization RCEs, CVE-2026-50522 and CVE-2026-58644 (CVSS 9.8 each, unauthenticated, no user interaction — CVE-2026-50522 was previously demonstrated live at Pwn2Own Berlin); CVE-2026-56190 (RDP client/server RCE, CVSS 9.8, use-of-uninitialized-resource); CVE-2026-50518 (Windows DHCP Server RCE, CVSS 9.8, heap-based buffer overflow, unauthenticated network-reachable); CVE-2026-56188 (Windows Server network driver RCE, CVSS 9.8, TOCTOU race condition, assessed as potentially wormable); CVE-2026-55008 (Exchange/Outlook Web Access stored XSS, CVSS 9.6, triggered simply by opening a crafted email); and CVE-2026-55944 and CVE-2026-56159 (Dynamics NAV/365 Business Central and DHCP Server, CVSS 9.8 each). Additional Critical RCE flaws spanned Microsoft Copilot (CVE-2026-48561), Microsoft Defender (CVE-2026-55011, CVE-2026-55012), Microsoft Office (CVE-2026-55129, CVE-2026-55049, CVE-2026-55045, CVE-2026-50314, CVE-2026-50467, CVE-2026-55022, CVE-2026-55018, CVE-2026-55056, CVE-2026-55120, CVE-2026-55043, CVE-2026-55123), DirectX/GDI+ (CVE-2026-50382, CVE-2026-49796, CVE-2026-50380), the RMCAST reliable-multicast driver (CVE-2026-54995, CVE-2026-54982), Remote Desktop Client (CVE-2026-50474), and SQL Server (CVE-2026-54118, CVE-2026-54117). Windows components accounted for the largest single share of fixes (416 CVEs), followed by Office (82) and Microsoft Edge (46). Adobe separately released 88 CVEs across 12 bulletins the same day, moving to a bimonthly release cadence.
No public threat-actor attribution has been made for the exploitation of CVE-2026-56155 or CVE-2026-56164 as of this writing; ransomware use of either flaw is listed as 'Unknown' in the CISA KEV catalog. Given AD FS and SharePoint's long history as targets for state-linked espionage actors (Golden SAML abuse of AD FS by suspected Russian-nexus intrusion sets; the ToolShell SharePoint exploitation chain attributed to Chinese state-linked actors in 2025), defenders should treat both flaws as high-priority identity- and collaboration-infrastructure targeting until attribution is clarified.
MITRE ATT&CK techniques used in TL-2026-1331
Discovery
T1046 Network Service Discovery
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Stealth
Collection
T1213 Data from Information Repositories
Command and Control
Impact
Persistence
T1505 Server Software Component
Credential Access
T1528 Steal Application Access Token; T1606 Forge Web Credentials
defense-impairment
Affected products and versions in Microsoft July 2026 Patch Tuesday
- Microsoft — Active Directory Federation Services (AD FS)
Vulnerable versions: Windows Server 2012; Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows 10
Fixed in: July 2026 cumulative update applied - Microsoft — SharePoint Enterprise Server 2016
Vulnerable versions: < 16.0.5561.1001
Fixed in: 16.0.5561.1001 - Microsoft — SharePoint Server 2019
Vulnerable versions: < 16.0.10417.20175
Fixed in: 16.0.10417.20175 - Microsoft — SharePoint Server Subscription Edition
Vulnerable versions: < 16.0.19725.20434
Fixed in: 16.0.19725.20434 - Microsoft — Windows BitLocker Device Encryption
Vulnerable versions: Windows 10; Windows 11; Windows Server (BitLocker recovery environment)
Fixed in: July 2026 cumulative update applied - Microsoft — Windows (VMSwitch, DHCP Server, RDP, network drivers)
Vulnerable versions: Windows Server 2016-2025; Windows 10; Windows 11
Fixed in: July 2026 cumulative update applied - Microsoft — Exchange Server / Outlook Web Access
Vulnerable versions: Exchange Server (pre-July 2026 update)
Fixed in: July 2026 security update applied
Remediation for Microsoft July 2026 Patch Tuesday
Patches
- Microsoft July 2026 Patch Tuesday cumulative updates (all affected Windows, SharePoint, Office, Exchange, Defender, Edge, Dynamics, and SQL Server builds)
Immediate actions
- Apply the July 2026 cumulative updates for AD FS-hosting Windows Server versions (2012-2025) to remediate CVE-2026-56155 by CISA's July 28, 2026 due date
- Apply SharePoint Server security updates to remediate CVE-2026-56164 (versions below 16.0.5561.1001 / 16.0.10417.20175 / 16.0.19725.20434) by CISA's accelerated July 17, 2026 due date
- Enable AMSI integration on SharePoint Server and set Request Body Scan mode to Full to detect exploitation attempts against CVE-2026-56164 pending patch deployment
- Prioritize patching CVE-2026-57092 (VMSwitch, CVSS 9.9), the SharePoint RCE pair CVE-2026-50522/CVE-2026-58644 (CVSS 9.8, PoC demonstrated at Pwn2Own Berlin), CVE-2026-56190 (RDP RCE), and CVE-2026-50518 (DHCP Server RCE) given their unauthenticated, network-reachable exploitation profiles
- Audit AD FS token-signing certificate access and federation trust configuration for signs of privilege escalation or Golden SAML-style token forgery following CVE-2026-56155 patching
- Inventory internet- and intranet-facing SharePoint on-premises farms and treat them as top patching priority regardless of the 'Moderate' CVSS label on CVE-2026-56164
Workarounds
- For CVE-2026-56164: enable AMSI with Request Body Scan mode set to Full on SharePoint Server as an interim mitigation
- For CVE-2026-50661 (BitLocker bypass): restrict physical access to devices and review BitLocker recovery-environment configuration until patched
Longer-term hardening
- Move on-premises SharePoint Server and AD FS deployments toward supported, actively-patched configurations or cloud equivalents (SharePoint Online, Entra ID federation) given the recurring cadence of on-prem identity/collaboration zero-days
- Deploy EDR/behavioral monitoring on AD FS servers to detect anomalous local privilege escalation and token-signing certificate access
- Establish a scanning/patch-compliance program to track the growing annual CVE volume (Microsoft projects 2,000-3,000+ CVEs for 2026) against CISA KEV due dates
CVEs associated with Microsoft July 2026 Patch Tuesday
- CVE-2026-56155
- CVE-2026-56164
- CVE-2026-50661
- CVE-2026-57092
- CVE-2026-50522
- CVE-2026-58644
CVE-2026-56190CVE-2026-50518CVE-2026-56159CVE-2026-56188CVE-2026-55008CVE-2026-55944CVE-2026-48561CVE-2026-55011CVE-2026-55012CVE-2026-55010CVE-2026-45585
Weaknesses (CWE) in Microsoft July 2026 Patch Tuesday
CWE-1220, CWE-306, CWE-416, CWE-502, CWE-190, CWE-367
Timeline of Microsoft July 2026 Patch Tuesday
- Microsoft projects 2026 full-year CVE disclosures will exceed 2,000, and potentially surpass 3,000, well above 2020's previous full-year record of 1,245
- Microsoft's April 2026 Patch Tuesday previously fixed an actively exploited SharePoint zero-day (CVE-2026-32201), establishing a pattern of recurring on-prem SharePoint zero-day exploitation in 2026
- June 2026 Patch Tuesday sets prior single-month record at 206 CVEs, later tripled by July's release
- Trend Micro's Zero Day Initiative (Dustin Childs) calls the release 'the mother of all releases' and 'the bug apocalypse'; Tenable's Satnam Narang attributes the volume to AI-assisted vulnerability discovery tooling
- CISA adds CVE-2026-56155 (AD FS EoP) and CVE-2026-56164 (SharePoint Server EoP) to the Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation
- Microsoft releases July 2026 Patch Tuesday addressing between 569 and 622 CVEs (count varies by source methodology), including 56-63 Critical-rated flaws
- CISA-mandated remediation due date for CVE-2026-56164 (SharePoint Server), reflecting the unauthenticated, no-user-interaction exploitation bar
- CISA-mandated remediation due date for CVE-2026-56155 (AD FS elevation of privilege)
Sources cited for Microsoft July 2026 Patch Tuesday
- Microsoft Patch Tuesday July 2026 sets record with 622 CVEs, two zero-days under active exploitation
- Microsoft's July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
- The July 2026 Security Update Review
- Microsoft's July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
- Record-Breaking Microsoft Patch Tuesday Update: 570 Vulnerabilities Fixed, Including 3 Zero-Days
- Microsoft Patches a Record 570 Security Flaws
- NVD - CVE-2026-56155
- NVD - CVE-2026-56164
- CISA Known Exploited Vulnerabilities Catalog - CVE-2026-56155
- CISA Known Exploited Vulnerabilities Catalog - CVE-2026-56164
- MSRC Security Update Guide - CVE-2026-56155
- MSRC Security Update Guide - CVE-2026-56164
Threats related to Microsoft July 2026 Patch Tuesday
- Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS (CVE-2026-56155), SharePoint (CVE-2026-56164) Exploited; BitLocker (CVE-2026-50661) Publicly Disclosed
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)
- Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP)
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation
- July 2026 Patch Tuesday: Two Actively Exploited Microsoft Zero-Days (SharePoint EoP CVE-2026-56164, AD FS EoP CVE-2026-56155) Plus SharePoint JWT Auth Bypass CVE-2026-55040
Detection coverage for TL-2026-1331
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1331 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.