Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155) — Threadlinqs Intelligence
As of 2026-07-22, Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 36 indicators of compromise.
Threat ID: TL-2026-1334 · Severity: CRITICAL · CVSS: 9.9 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-22 · revalidated 1× · latest source
Microsoft's July 2026 Patch Tuesday fixed a record 622 CVEs (independent counts range 569-622), more than tripling June's prior high. Two flaws are under active exploitation as zero-days: an
Microsoft's July 2026 Patch Tuesday is the largest security update in the company's history, addressing 622 CVEs by Microsoft's own count (ZDI counted 621; several trade outlets reported an intermediate 569-570 figure before final numbers settled), more than triple June 2026's prior record of roughly 200. The scale is attributed in reporting to Microsoft's internal MDASH AI-assisted vulnerability-discovery system, which alone reportedly surfaced 16 bugs in May 2026, alongside an industry-wide rise in automated patch-diffing that shortens the window between disclosure and working exploit code.
Two vulnerabilities are confirmed under active exploitation as zero-days, both elevation-of-privilege bugs rather than the more commonly weaponized RCE class, illustrating that CVSS severity alone is an unreliable prioritization signal this cycle. CVE-2026-56164 is a missing-authentication-for-critical-function flaw in on-premises Microsoft SharePoint Server (2016, 2019, Enterprise Server 2016, and Subscription Edition) that lets an unauthenticated attacker escalate privileges over the network with no user interaction, discovered by Mandiant incident responders and Google's FLARE team. It follows the well-documented 'ToolShell' SharePoint exploit-chain lineage (CVE-2025-49704/49706/53770/53771) that Storm-2603, a suspected China-based ransomware actor, and espionage actors Threat Group-3390 and ZIRCONIUM weaponized in mid-2025 to drop web shells (spinstall0.aspx and renamed variants such as spinstall1.aspx/spinstall2.aspx) that exfiltrate ASP.NET MachineKey material, enabling persistent unauthenticated code execution even after patching unless keys are rotated. Storm-2603's campaign went on to deploy Warlock (aka X2anylock) and LockBit ransomware via w3wp.exe-spawned command execution and Defender-disabling registry edits through services.exe, compromising 300+ organizations. A related follow-on SharePoint KEV entry, CVE-2026-45659, continued this Warlock-ransomware pattern into 2026, underscoring that unauthenticated SharePoint EoP/RCE chains remain an active, repeatable playbook for the same actor cluster. Microsoft's AMSI-in-Full-Mode integration is the primary in-product mitigation for CVE-2026-56164 by scanning malicious POST requests to affected ASPX endpoints.
CVE-2026-56155 is an elevation-of-privilege flaw in Active Directory Federation Services caused by insufficient granularity of access control, requiring local access and low privileges to trigger but granting administrator-level privileges on the token-signing infrastructure that underpins hybrid Azure AD/on-premises authentication trust. Microsoft DART (Detection and Response Team) is credited with discovery; Microsoft has not disclosed the specific privilege grant or exploitation methodology. Because AD FS issues SAML tokens, compromise of this component mirrors the risk profile of 'Golden SAML' attacks, in which a stolen token-signing certificate lets an adversary forge arbitrary SAML assertions and impersonate any federated identity indefinitely, bypassing MFA and conditional access entirely.
A third, publicly disclosed but not-yet-exploited zero-day, CVE-2026-50661, is a BitLocker security-feature bypass requiring physical device access; public PoCs already exist. It continues 2026's BitLocker-bypass trend alongside CVE-2026-45585 ('YellowKey', which targeted the Windows Recovery Environment rather than BitLocker's core encryption) and an unconfirmed possible link to a researcher-disclosed flaw referred to in reporting as 'GreatXML'/'Nightmare-Eclipse'/'Chaotic-Eclipse' (no official Microsoft confirmation).
Beyond the zero-days, the release's highest CVSS score (9.9) belongs to CVE-2026-57092, a use-after-free elevation-of-privilege in Windows VMSwitch that lets a low-privileged attacker escalate across the VM boundary to full Hyper-V host compromise — an urgent patch for any virtualization host. CVE-2026-50522 (paired with CVE-2026-58644), both CVSS 9.8, are unauthe
Weaknesses (CWE)
CWE-306, CWE-284, CWE-1259, CWE-416, CWE-502, CWE-345, CWE-79, CWE-94
Target sectors: government administration, finance, health, software, telecoms, business-services, consumer-goods
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 36 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-56164, CVE-2026-56155, CVE-2026-50661, CVE-2026-57092, CVE-2026-50522, CVE-2026-58644, CVE-2026-55040, CVE-2026-54117, CVE-2026-54118, CVE-2026-55008, T1190, T1566, T1059, T1203, T1505, T1068, T1078, T1562, T1211, T1112