Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164)

Microsoft July 2026 Patch Tuesday (TL-2026-1331), also tracked as July 2026 Patch Tuesday, is a critical-severity software vulnerability scored CVSS 7.8, first published 2026-07-14. It has no confirmed attribution, affects Microsoft Active Directory Federation Services (AD FS), references 17 CVEs (CVE-2026-56155, CVE-2026-56164, CVE-2026-50661), maps to 15 MITRE ATT&CK techniques (T1046, T1068, T1078), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-1331

Threat ID
TL-2026-1331
Also known as
July 2026 Patch Tuesday, MSRC July 2026 Release, Microsoft Bug Apocalypse July 2026
Severity
CRITICAL
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-14
Last reviewed
2026-07-14
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, education, critical-infrastructure, professional-services
Target regions
North America, Europe, Asia Pacific, Global
Detection rules
9
Indicators of compromise
17

Microsoft's July 2026 Patch Tuesday shattered all prior records, addressing roughly 570-622 CVEs (source counts vary: 569, 570, 621, 622) including two zero-days confirmed under active exploitation and added to the CISA KEV catalog: CVE-2026-56155, an Active Directory Federation Services (AD FS) elevation-of-privilege flaw (CVSS 7.8), and CVE-2026-56164, a SharePoint Server missing-authentication elevation-of-privilege flaw (CVSS 5.3). A third zero-day, CVE-2026-50661 (Windows BitLocker security-feature bypass), was publicly disclosed but not confirmed exploited. 56-63 of the CVEs fixed this cycle were rated Critical, including several CVSS 9.8-9.9 remote code execution flaws.

How Microsoft July 2026 Patch Tuesday works

On July 14, 2026, Microsoft released its largest Patch Tuesday on record, addressing between 569 and 622 CVEs depending on the counting methodology used by different research teams (Trend Micro/ZDI cites 569-621; other outlets cite 570 or 622) — more than triple June 2026's prior record of 206. Security researchers including Dustin Childs of Trend Micro's Zero Day Initiative called it 'the mother of all releases' and 'the bug apocalypse,' while Satnam Narang of Tenable attributed the volume growth to AI-assisted vulnerability discovery tooling (referred to in coverage as MDASH) rather than a genuine spike in underlying risk. Microsoft is now projecting it will exceed 2,000-3,000 disclosed CVEs for calendar year 2026, well above 2020's prior full-year record of 1,245.

Two vulnerabilities in this release were confirmed as zero-days under active exploitation in the wild and were added to CISA's Known Exploited Vulnerabilities (KEV) catalog on the release date:

1. **CVE-2026-56155** — an elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control (CWE-1220). CVSS 3.1 base score 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) — a locally-authenticated, low-privileged attacker can escalate to administrator. Microsoft credits the discovery to Jeremy Kingston and Scott Clark of its own Detection and Response Team (DART), the incident-response unit that investigates active intrusions — a strong signal the bug was found via forensics on a real compromise rather than proactive research. Because AD FS underpins federated authentication trust across hybrid Azure AD / on-premises environments, ZDI analysts flagged it as a high-value pivot point for identity-infrastructure compromise, drawing comparisons to historical 'Golden SAML' token-forgery attack patterns against AD FS token-signing certificates. Affects Windows Server 2012 through Windows Server 2025 and Windows 10 hosts running the AD FS role. CISA set a remediation due date of July 28, 2026.

2. **CVE-2026-56164** — an elevation-of-privilege vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function (CWE-306). CVSS 3.1 base score 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) — despite the 'Moderate' label, it is unauthenticated, network-reachable, and requires no user interaction, letting a remote attacker elevate privileges over the network. Credited to Jayson Frost (Mandiant) and Genwei Jiang (Google Cloud) — both threat-intelligence firms with histories of tracking SharePoint on-prem exploitation by espionage actors. Affects SharePoint Enterprise Server 2016 (< 16.0.5561.1001), SharePoint Server 2019 (< 16.0.10417.20175), and SharePoint Server Subscription Edition (< 16.0.19725.20434). Microsoft's stated mitigation is enabling Antimalware Scan Interface (AMSI) integration with Request Body Scan mode set to Full, which can detect malicious POST requests exploiting the flaw. CISA set an accelerated remediation due date of July 17, 2026 (3 days), reflecting the low exploitation bar and SharePoint's history as a preferred on-prem target for state-linked intrusion sets (ToolShell/CVE-2025-53770 lineage).

A third notable zero-day, **CVE-2026-50661**, is a Windows BitLocker Device Encryption security-feature-bypass vulnerability that was publicly disclosed prior to patch availability, though not confirmed as actively exploited. It requires physical access to the target device and exploits weaknesses in BitLocker's recovery environment rather than the core encryption implementation — researchers drew a direct parallel to the earlier 2026 BitLocker recovery-environment bypass tracked as CVE-2026-45585.

Beyond the zero-days, the release included a large cluster of Critical-rated remote code execution flaws: CVE-2026-57092 (Windows VMSwitch EoP, CVSS 9.9, use-after-free enabling guest-to-host VM escape — the highest score of the cycle); a matched pair of SharePoint deserialization RCEs, CVE-2026-50522 and CVE-2026-58644 (CVSS 9.8 each, unauthenticated, no user interaction — CVE-2026-50522 was previously demonstrated live at Pwn2Own Berlin); CVE-2026-56190 (RDP client/server RCE, CVSS 9.8, use-of-uninitialized-resource); CVE-2026-50518 (Windows DHCP Server RCE, CVSS 9.8, heap-based buffer overflow, unauthenticated network-reachable); CVE-2026-56188 (Windows Server network driver RCE, CVSS 9.8, TOCTOU race condition, assessed as potentially wormable); CVE-2026-55008 (Exchange/Outlook Web Access stored XSS, CVSS 9.6, triggered simply by opening a crafted email); and CVE-2026-55944 and CVE-2026-56159 (Dynamics NAV/365 Business Central and DHCP Server, CVSS 9.8 each). Additional Critical RCE flaws spanned Microsoft Copilot (CVE-2026-48561), Microsoft Defender (CVE-2026-55011, CVE-2026-55012), Microsoft Office (CVE-2026-55129, CVE-2026-55049, CVE-2026-55045, CVE-2026-50314, CVE-2026-50467, CVE-2026-55022, CVE-2026-55018, CVE-2026-55056, CVE-2026-55120, CVE-2026-55043, CVE-2026-55123), DirectX/GDI+ (CVE-2026-50382, CVE-2026-49796, CVE-2026-50380), the RMCAST reliable-multicast driver (CVE-2026-54995, CVE-2026-54982), Remote Desktop Client (CVE-2026-50474), and SQL Server (CVE-2026-54118, CVE-2026-54117). Windows components accounted for the largest single share of fixes (416 CVEs), followed by Office (82) and Microsoft Edge (46). Adobe separately released 88 CVEs across 12 bulletins the same day, moving to a bimonthly release cadence.

No public threat-actor attribution has been made for the exploitation of CVE-2026-56155 or CVE-2026-56164 as of this writing; ransomware use of either flaw is listed as 'Unknown' in the CISA KEV catalog. Given AD FS and SharePoint's long history as targets for state-linked espionage actors (Golden SAML abuse of AD FS by suspected Russian-nexus intrusion sets; the ToolShell SharePoint exploitation chain attributed to Chinese state-linked actors in 2025), defenders should treat both flaws as high-priority identity- and collaboration-infrastructure targeting until attribution is clarified.

MITRE ATT&CK techniques used in TL-2026-1331

Discovery

T1046 Network Service Discovery

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution

Lateral Movement

T1210 Exploitation of Remote Services

Defense Evasion

T1211 Exploitation for Stealth

Collection

T1213 Data from Information Repositories

Command and Control

T1219 Remote Access Tools

Impact

T1489 Service Stop

Persistence

T1505 Server Software Component

Credential Access

T1528 Steal Application Access Token; T1606 Forge Web Credentials

defense-impairment

T1556 Modify Authentication Process

Affected products and versions in Microsoft July 2026 Patch Tuesday

  • Microsoft — Active Directory Federation Services (AD FS)
    Vulnerable versions: Windows Server 2012; Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows 10
    Fixed in: July 2026 cumulative update applied
  • Microsoft — SharePoint Enterprise Server 2016
    Vulnerable versions: < 16.0.5561.1001
    Fixed in: 16.0.5561.1001
  • Microsoft — SharePoint Server 2019
    Vulnerable versions: < 16.0.10417.20175
    Fixed in: 16.0.10417.20175
  • Microsoft — SharePoint Server Subscription Edition
    Vulnerable versions: < 16.0.19725.20434
    Fixed in: 16.0.19725.20434
  • Microsoft — Windows BitLocker Device Encryption
    Vulnerable versions: Windows 10; Windows 11; Windows Server (BitLocker recovery environment)
    Fixed in: July 2026 cumulative update applied
  • Microsoft — Windows (VMSwitch, DHCP Server, RDP, network drivers)
    Vulnerable versions: Windows Server 2016-2025; Windows 10; Windows 11
    Fixed in: July 2026 cumulative update applied
  • Microsoft — Exchange Server / Outlook Web Access
    Vulnerable versions: Exchange Server (pre-July 2026 update)
    Fixed in: July 2026 security update applied

Remediation for Microsoft July 2026 Patch Tuesday

Patches

  • Microsoft July 2026 Patch Tuesday cumulative updates (all affected Windows, SharePoint, Office, Exchange, Defender, Edge, Dynamics, and SQL Server builds)

Immediate actions

  • Apply the July 2026 cumulative updates for AD FS-hosting Windows Server versions (2012-2025) to remediate CVE-2026-56155 by CISA's July 28, 2026 due date
  • Apply SharePoint Server security updates to remediate CVE-2026-56164 (versions below 16.0.5561.1001 / 16.0.10417.20175 / 16.0.19725.20434) by CISA's accelerated July 17, 2026 due date
  • Enable AMSI integration on SharePoint Server and set Request Body Scan mode to Full to detect exploitation attempts against CVE-2026-56164 pending patch deployment
  • Prioritize patching CVE-2026-57092 (VMSwitch, CVSS 9.9), the SharePoint RCE pair CVE-2026-50522/CVE-2026-58644 (CVSS 9.8, PoC demonstrated at Pwn2Own Berlin), CVE-2026-56190 (RDP RCE), and CVE-2026-50518 (DHCP Server RCE) given their unauthenticated, network-reachable exploitation profiles
  • Audit AD FS token-signing certificate access and federation trust configuration for signs of privilege escalation or Golden SAML-style token forgery following CVE-2026-56155 patching
  • Inventory internet- and intranet-facing SharePoint on-premises farms and treat them as top patching priority regardless of the 'Moderate' CVSS label on CVE-2026-56164

Workarounds

  • For CVE-2026-56164: enable AMSI with Request Body Scan mode set to Full on SharePoint Server as an interim mitigation
  • For CVE-2026-50661 (BitLocker bypass): restrict physical access to devices and review BitLocker recovery-environment configuration until patched

Longer-term hardening

  • Move on-premises SharePoint Server and AD FS deployments toward supported, actively-patched configurations or cloud equivalents (SharePoint Online, Entra ID federation) given the recurring cadence of on-prem identity/collaboration zero-days
  • Deploy EDR/behavioral monitoring on AD FS servers to detect anomalous local privilege escalation and token-signing certificate access
  • Establish a scanning/patch-compliance program to track the growing annual CVE volume (Microsoft projects 2,000-3,000+ CVEs for 2026) against CISA KEV due dates

CVEs associated with Microsoft July 2026 Patch Tuesday

Weaknesses (CWE) in Microsoft July 2026 Patch Tuesday

CWE-1220, CWE-306, CWE-416, CWE-502, CWE-190, CWE-367

Timeline of Microsoft July 2026 Patch Tuesday

  • Microsoft projects 2026 full-year CVE disclosures will exceed 2,000, and potentially surpass 3,000, well above 2020's previous full-year record of 1,245
  • Microsoft's April 2026 Patch Tuesday previously fixed an actively exploited SharePoint zero-day (CVE-2026-32201), establishing a pattern of recurring on-prem SharePoint zero-day exploitation in 2026
  • June 2026 Patch Tuesday sets prior single-month record at 206 CVEs, later tripled by July's release
  • Trend Micro's Zero Day Initiative (Dustin Childs) calls the release 'the mother of all releases' and 'the bug apocalypse'; Tenable's Satnam Narang attributes the volume to AI-assisted vulnerability discovery tooling
  • CISA adds CVE-2026-56155 (AD FS EoP) and CVE-2026-56164 (SharePoint Server EoP) to the Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation
  • Microsoft releases July 2026 Patch Tuesday addressing between 569 and 622 CVEs (count varies by source methodology), including 56-63 Critical-rated flaws
  • CISA-mandated remediation due date for CVE-2026-56164 (SharePoint Server), reflecting the unauthenticated, no-user-interaction exploitation bar
  • CISA-mandated remediation due date for CVE-2026-56155 (AD FS elevation of privilege)

Sources cited for Microsoft July 2026 Patch Tuesday

Threats related to Microsoft July 2026 Patch Tuesday

Detection coverage for TL-2026-1331

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1331 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats