Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164) — Threadlinqs Intelligence
As of 2026-07-19, Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164) is a critical-severity vulnerability threat attributed to APT27 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-1336 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-19 · revalidated 1× · latest source
Attribution: APT27 · China · ESPIONAGE
Microsoft's July 2026 Patch Tuesday fixed a record 622 vulnerabilities (57 critical), including two flaws confirmed under active exploitation: CVE-2026-56155, a local privilege-escalation bug in
On July 14, 2026, Microsoft shipped its largest Patch Tuesday to date, addressing 622 CVEs (416 in Windows, 164 in Office products), 57 rated critical. Two vulnerabilities were confirmed exploited in the wild at release. CVE-2026-56155 is an Elevation of Privilege vulnerability in Active Directory Federation Services caused by insufficient granularity of access control (CWE-1220); an authorized local attacker with low privileges can escalate to administrator, which is particularly dangerous because AD FS underpins federated authentication trust across hybrid Azure AD/on-premises environments and is a favored pivot point once an attacker has an initial foothold, echoing prior AD FS golden-SAML style attacks. Microsoft credited Jeremy Kingston and Scott Clark of its own Detection and Response Team (DART) with the finding, suggesting it was surfaced during an active incident-response engagement. CVE-2026-56164 is a Missing Authentication for Critical Function vulnerability (CWE-306) in Microsoft SharePoint Server that lets an unauthorized, unauthenticated attacker elevate privileges over the network with no user interaction. Despite Microsoft's own 'Moderate' severity label, NVD scores it CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) because it is remotely reachable and trivially weaponizable. CISA added CVE-2026-56164 to the KEV catalog on July 14, 2026, and observed post-exploitation activity consistent with the 2025 'ToolShell' SharePoint attack chain: attackers deserialize untrusted data server-side to gain code execution as the IIS worker process (w3wp.exe), then steal ASP.NET machine keys (ValidationKey/DecryptionKey) to forge ViewState payloads for durable, re-exploitable remote code execution even after the initial vulnerability is patched, and drop lightweight .aspx web shells (e.g., spinstall0.aspx and the spinstallN.aspx family) under SharePoint LAYOUTS/wwwroot paths for persistence. Security reporting ties active exploitation of this vulnerability class to China-nexus threat actors Linen Typhoon, Violet Typhoon, and Storm-2603, the same clusters Microsoft previously linked to on-premises SharePoint ToolShell exploitation, with Storm-2603 historically pivoting stolen access into ransomware deployment. Eleven additional critical remote-code-execution bugs were flagged by Microsoft as 'more likely' to be exploited, including CVE-2026-50522 and CVE-2026-58644 (SharePoint deserialization RCE, CVSS 9.8, demonstrated at Pwn2Own Berlin), CVE-2026-50518 and CVE-2026-50370 (Windows DHCP Server heap-based buffer overflow RCE, CVSS 9.8, network-reachable), CVE-2026-54128 (Windows DHCP Client use-after-free), CVE-2026-57092 (Windows VMSwitch elevation of privilege via use-after-free, CVSS 9.9, the month's highest score, enabling a low-privileged guest to fully compromise the Hyper-V host across the VM boundary), CVE-2026-56190 (RDP RCE via uninitialized resource, CWE-908, CVSS 9.8), CVE-2026-56188 (Windows Server networking race condition), CVE-2026-55944 (Dynamics NAV/365 deserialization RCE), CVE-2026-55010 (Minecraft Bedrock heap overflow), CVE-2026-50327 (Windows Media heap overflow), CVE-2026-50655 (Media Foundation heap overflow), and CVE-2026-54992 (Message Queuing heap overflow). Also disclosed was CVE-2026-50661, a publicly-known BitLocker security-feature-bypass affecting physical-access scenarios, and CVE-2026-55008, a cross-site scripting flaw in Exchange Server. Given internet-exposed SharePoint and DHCP infrastructure, unauthenticated deserialization RCE, and confirmed nation-state exploitation, defenders should prioritize patching AD FS and on-premises SharePoint immediately, hunt for ToolShell-pattern web shells and machine-key theft, and rotate ASP.NET machine keys post-patch since key theft survives patching.
Weaknesses (CWE)
CWE-1220, CWE-306, CWE-502, CWE-122, CWE-416, CWE-908, CWE-362, CWE-79, CWE-284, CWE-787
Target sectors: government administration, finance, health, technology, education, critical-infrastructure, professional-services
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-56155, CVE-2026-56164, CVE-2026-50522, CVE-2026-58644, CVE-2026-50518, CVE-2026-50370, CVE-2026-54128, CVE-2026-57092, CVE-2026-56190, CVE-2026-56188, T1588, T1190, T1059, T1059, T1505, T1078, T1068, T1611, T1027, T1140