Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164) — Threadlinqs Intelligence
As of 2026-07-14, Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-1331 · Severity: CRITICAL · CVSS: 7.8 · Status: ACTIVE · Category: VULNERABILITY
Microsoft's July 2026 Patch Tuesday shattered all prior records, addressing roughly 570-622 CVEs (source counts vary: 569, 570, 621, 622) including two zero-days confirmed under active exploitation
On July 14, 2026, Microsoft released its largest Patch Tuesday on record, addressing between 569 and 622 CVEs depending on the counting methodology used by different research teams (Trend Micro/ZDI cites 569-621; other outlets cite 570 or 622) — more than triple June 2026's prior record of 206. Security researchers including Dustin Childs of Trend Micro's Zero Day Initiative called it 'the mother of all releases' and 'the bug apocalypse,' while Satnam Narang of Tenable attributed the volume growth to AI-assisted vulnerability discovery tooling (referred to in coverage as MDASH) rather than a genuine spike in underlying risk. Microsoft is now projecting it will exceed 2,000-3,000 disclosed CVEs for calendar year 2026, well above 2020's prior full-year record of 1,245.
Two vulnerabilities in this release were confirmed as zero-days under active exploitation in the wild and were added to CISA's Known Exploited Vulnerabilities (KEV) catalog on the release date:
1. **CVE-2026-56155** — an elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control (CWE-1220). CVSS 3.1 base score 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) — a locally-authenticated, low-privileged attacker can escalate to administrator. Microsoft credits the discovery to Jeremy Kingston and Scott Clark of its own Detection and Response Team (DART), the incident-response unit that investigates active intrusions — a strong signal the bug was found via forensics on a real compromise rather than proactive research. Because AD FS underpins federated authentication trust across hybrid Azure AD / on-premises environments, ZDI analysts flagged it as a high-value pivot point for identity-infrastructure compromise, drawing comparisons to historical 'Golden SAML' token-forgery attack patterns against AD FS token-signing certificates. Affects Windows Server 2012 through Windows Server 2025 and Windows 10 hosts running the AD FS role. CISA set a remediation due date of July 28, 2026.
2. **CVE-2026-56164** — an elevation-of-privilege vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function (CWE-306). CVSS 3.1 base score 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) — despite the 'Moderate' label, it is unauthenticated, network-reachable, and requires no user interaction, letting a remote attacker elevate privileges over the network. Credited to Jayson Frost (Mandiant) and Genwei Jiang (Google Cloud) — both threat-intelligence firms with histories of tracking SharePoint on-prem exploitation by espionage actors. Affects SharePoint Enterprise Server 2016 (< 16.0.5561.1001), SharePoint Server 2019 (< 16.0.10417.20175), and SharePoint Server Subscription Edition (< 16.0.19725.20434). Microsoft's stated mitigation is enabling Antimalware Scan Interface (AMSI) integration with Request Body Scan mode set to Full, which can detect malicious POST requests exploiting the flaw. CISA set an accelerated remediation due date of July 17, 2026 (3 days), reflecting the low exploitation bar and SharePoint's history as a preferred on-prem target for state-linked intrusion sets (ToolShell/CVE-2025-53770 lineage).
A third notable zero-day, **CVE-2026-50661**, is a Windows BitLocker Device Encryption security-feature-bypass vulnerability that was publicly disclosed prior to patch availability, though not confirmed as actively exploited. It requires physical access to the target device and exploits weaknesses in BitLocker's recovery environment rather than the core encryption implementation — researchers drew a direct parallel to the earlier 2026 BitLocker recovery-environment bypass tracked as CVE-2026-45585.
Beyond the zero-days, the release included a large cluster of Critical-rated remote code execution flaws: CVE-2026-57092 (Windows VMSwitch EoP, CVSS 9.9, use-after-free enabling guest-to-host VM escape — the highest score of the cycle); a matched pair of SharePoint deserializat
Weaknesses (CWE)
CWE-1220, CWE-306, CWE-416, CWE-502, CWE-190, CWE-367
Target sectors: government administration, finance, health, technology, education, critical-infrastructure, professional-services
Target regions: North America, Europe, Asia Pacific, Global
Related threats
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)
- Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP)
- Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS (CVE-2026-56155), SharePoint (CVE-2026-56164) Exploited; BitLocker (CVE-2026-50661) Publicly Disclosed
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)
- Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155)
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-56155, CVE-2026-56164, CVE-2026-50661, CVE-2026-57092, CVE-2026-50522, CVE-2026-58644, CVE-2026-56190, CVE-2026-50518, CVE-2026-56159, CVE-2026-56188, T1068, T1548, T1190, T1606, T1528, T1211, T1556, T1203, T1505, T1210