Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164)

Microsoft July 2026 Patch Tuesday (TL-2026-1336), also tracked as ToolShell (SharePoint attack chain), is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-14 and last reviewed 2026-07-19. It is attributed to APT27 (China) with medium confidence, affects Microsoft Active Directory Federation Services (AD FS), references 22 CVEs (CVE-2026-56155, CVE-2026-56164, CVE-2026-50522), maps to 19 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 32 indicators of compromise.

Key facts for TL-2026-1336

Threat ID
TL-2026-1336
Also known as
ToolShell (SharePoint attack chain), July 2026 Patch Tuesday zero-days
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-14
Last reviewed
2026-07-19
Attribution
APT27
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, finance, health, technology, education, critical-infrastructure, professional-services
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
32
Updates
2026-07-19 · revalidated 1× · latest source

Malware and tooling in Microsoft July 2026 Patch Tuesday

Malware and tooling: ToolShell

Microsoft's July 2026 Patch Tuesday fixed a record 622 vulnerabilities (57 critical), including two flaws confirmed under active exploitation: CVE-2026-56155, a local privilege-escalation bug in Active Directory Federation Services (AD FS), and CVE-2026-56164, a critical missing-authentication/spoofing flaw in on-premises SharePoint Server tied to a ToolShell-style attack chain. CISA added CVE-2026-56164 to its Known Exploited Vulnerabilities catalog the same day and ordered federal agencies to mitigate within days.

How Microsoft July 2026 Patch Tuesday works

On July 14, 2026, Microsoft shipped its largest Patch Tuesday to date, addressing 622 CVEs (416 in Windows, 164 in Office products), 57 rated critical. Two vulnerabilities were confirmed exploited in the wild at release. CVE-2026-56155 is an Elevation of Privilege vulnerability in Active Directory Federation Services caused by insufficient granularity of access control (CWE-1220); an authorized local attacker with low privileges can escalate to administrator, which is particularly dangerous because AD FS underpins federated authentication trust across hybrid Azure AD/on-premises environments and is a favored pivot point once an attacker has an initial foothold, echoing prior AD FS golden-SAML style attacks. Microsoft credited Jeremy Kingston and Scott Clark of its own Detection and Response Team (DART) with the finding, suggesting it was surfaced during an active incident-response engagement. CVE-2026-56164 is a Missing Authentication for Critical Function vulnerability (CWE-306) in Microsoft SharePoint Server that lets an unauthorized, unauthenticated attacker elevate privileges over the network with no user interaction. Despite Microsoft's own 'Moderate' severity label, NVD scores it CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) because it is remotely reachable and trivially weaponizable. CISA added CVE-2026-56164 to the KEV catalog on July 14, 2026, and observed post-exploitation activity consistent with the 2025 'ToolShell' SharePoint attack chain: attackers deserialize untrusted data server-side to gain code execution as the IIS worker process (w3wp.exe), then steal ASP.NET machine keys (ValidationKey/DecryptionKey) to forge ViewState payloads for durable, re-exploitable remote code execution even after the initial vulnerability is patched, and drop lightweight .aspx web shells (e.g., spinstall0.aspx and the spinstallN.aspx family) under SharePoint LAYOUTS/wwwroot paths for persistence. Security reporting ties active exploitation of this vulnerability class to China-nexus threat actors Linen Typhoon, Violet Typhoon, and Storm-2603, the same clusters Microsoft previously linked to on-premises SharePoint ToolShell exploitation, with Storm-2603 historically pivoting stolen access into ransomware deployment. Eleven additional critical remote-code-execution bugs were flagged by Microsoft as 'more likely' to be exploited, including CVE-2026-50522 and CVE-2026-58644 (SharePoint deserialization RCE, CVSS 9.8, demonstrated at Pwn2Own Berlin), CVE-2026-50518 and CVE-2026-50370 (Windows DHCP Server heap-based buffer overflow RCE, CVSS 9.8, network-reachable), CVE-2026-54128 (Windows DHCP Client use-after-free), CVE-2026-57092 (Windows VMSwitch elevation of privilege via use-after-free, CVSS 9.9, the month's highest score, enabling a low-privileged guest to fully compromise the Hyper-V host across the VM boundary), CVE-2026-56190 (RDP RCE via uninitialized resource, CWE-908, CVSS 9.8), CVE-2026-56188 (Windows Server networking race condition), CVE-2026-55944 (Dynamics NAV/365 deserialization RCE), CVE-2026-55010 (Minecraft Bedrock heap overflow), CVE-2026-50327 (Windows Media heap overflow), CVE-2026-50655 (Media Foundation heap overflow), and CVE-2026-54992 (Message Queuing heap overflow). Also disclosed was CVE-2026-50661, a publicly-known BitLocker security-feature-bypass affecting physical-access scenarios, and CVE-2026-55008, a cross-site scripting flaw in Exchange Server. Given internet-exposed SharePoint and DHCP infrastructure, unauthenticated deserialization RCE, and confirmed nation-state exploitation, defenders should prioritize patching AD FS and on-premises SharePoint immediately, hunt for ToolShell-pattern web shells and machine-key theft, and rotate ASP.NET machine keys post-patch since key theft survives patching.

MITRE ATT&CK techniques used in TL-2026-1336

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services; T1210 Exploitation of Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Stealth

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1611 Escape to Host

Command and Control

T1071 Application Layer Protocol

Persistence

T1078 Valid Accounts; T1505 Server Software Component

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1486 Data Encrypted for Impact

Credential Access

T1552 Unsecured Credentials; T1606 Forge Web Credentials

Resource Development

T1588 Obtain Capabilities

Affected products and versions in Microsoft July 2026 Patch Tuesday

  • Microsoft — Active Directory Federation Services (AD FS)
    Vulnerable versions: Windows 10 Version 1607 (before 10.0.14393.9339); Windows 10 Version 1809 (before 10.0.17763.9020); Windows Server 2012; Windows Server 2012 R2; Windows Server 2016 (before 10.0.14393.9339); Windows Server 2019 (before 10.0.17763.9020); Windows Server 2022 (before 10.0.20348.5386); Windows Server 2025 (before 10.0.26100.33158)
    Fixed in: Windows Server 2016 10.0.14393.9339+; Windows Server 2019 10.0.17763.9020+; Windows Server 2022 10.0.20348.5386+; Windows Server 2025 10.0.26100.33158+
  • Microsoft — SharePoint Server
    Vulnerable versions: SharePoint Enterprise Server 2016 (before 16.0.5561.1001); SharePoint Server 2019 (before 16.0.10417.20175); SharePoint Server Subscription Edition (before 16.0.19725.20434)
    Fixed in: SharePoint Enterprise Server 2016 16.0.5561.1001+; SharePoint Server 2019 16.0.10417.20175+; SharePoint Server Subscription Edition 16.0.19725.20434+
  • Microsoft — Windows DHCP Server / Client
    Vulnerable versions: Windows Server (DHCP role, all currently supported builds); Windows 10/11 (DHCP client)
    Fixed in: July 2026 cumulative update
  • Microsoft — Windows Hyper-V (VMSwitch)
    Vulnerable versions: Windows Server with Hyper-V role enabled, all currently supported builds
    Fixed in: July 2026 cumulative update

Remediation for Microsoft July 2026 Patch Tuesday

Patches

  • Microsoft July 2026 Patch Tuesday cumulative updates for CVE-2026-56155 (AD FS) and CVE-2026-56164 (SharePoint Server)
  • Windows Server / Windows 10 builds: 10.0.14393.9339, 10.0.17763.9020, 10.0.20348.5386, 10.0.26100.33158 or later resolve CVE-2026-56155
  • SharePoint Enterprise Server 2016 16.0.5561.1001+, SharePoint Server 2019 16.0.10417.20175+, SharePoint Server Subscription Edition 16.0.19725.20434+ resolve CVE-2026-56164

Immediate actions

  • Apply the July 2026 cumulative update for AD FS hosts (CVE-2026-56155) on all affected Windows Server builds before 2026-07-28 per CISA KEV deadline
  • Apply the SharePoint Server security update addressing CVE-2026-56164 on all on-premises farms (Subscription Edition, 2019, 2016) before 2026-07-17 per CISA KEV deadline
  • Enable Antimalware Scan Interface (AMSI) integration on SharePoint Server and set Request Body Scan mode to Full
  • Rotate ASP.NET machine keys (ValidationKey/DecryptionKey) on all SharePoint farms regardless of patch status, since stolen keys remain valid post-patch
  • Hunt for web shells matching spinstall0.aspx / spinstall\d+.aspx and generic cmd.aspx/webshell.aspx under LAYOUTS, wwwroot, inetpub, and Microsoft Shared paths
  • Alert on w3wp.exe spawning cmd.exe or powershell.exe as a high-fidelity SharePoint post-exploitation indicator

Workarounds

  • If patching is delayed, disable or restrict external network access to on-premises SharePoint Server front-end URLs
  • Restrict AD FS server console/RDP access to a dedicated jump host with MFA until patched

Longer-term hardening

  • Restrict AD FS server local logon and administrative access to a minimal, monitored admin tier to reduce local-EoP blast radius
  • Segment on-premises SharePoint Server from the internet where feasible and place it behind an authenticating reverse proxy/WAF
  • Deploy EDR with behavioral detection tuned to deserialization-triggered process trees and IIS worker process anomalies
  • Establish periodic machine-key rotation as standard SharePoint operational hygiene, independent of incident response

CVEs associated with Microsoft July 2026 Patch Tuesday

Weaknesses (CWE) in Microsoft July 2026 Patch Tuesday

CWE-1220, CWE-306, CWE-502, CWE-122, CWE-416, CWE-908, CWE-362, CWE-79, CWE-284, CWE-787

Timeline of Microsoft July 2026 Patch Tuesday

  • "GreatXML" BitLocker bypass research is publicly disclosed, likely the basis for the later CVE-2026-50661 security-feature-bypass disclosure.
  • CVE-2026-50522 and CVE-2026-58644 (SharePoint deserialization RCE, both CVSS 9.8) are noted as having been demonstrated at Pwn2Own Berlin, raising the likelihood of near-term public exploitation.
  • Security researchers link active exploitation of the SharePoint deserialization/ToolShell attack chain to China-nexus actors Linen Typhoon, Violet Typhoon, and Storm-2603.
  • CISA publishes an alert urging organizations to harden on-premises SharePoint Server deployments in response to new exploitation.
  • CISA adds CVE-2026-56164 to the Known Exploited Vulnerabilities (KEV) catalog on the day of disclosure.
  • Microsoft credits DART researchers Jeremy Kingston and Scott Clark for finding CVE-2026-56155, indicating the flaw was surfaced during active incident-response investigation.
  • Microsoft releases July 2026 Patch Tuesday: 622 CVEs fixed (57 critical), including confirmed active exploitation of CVE-2026-56155 (AD FS) and CVE-2026-56164 (SharePoint Server).
  • Vendor research (CyCognito) publishes exploit-chain analysis for CVE-2026-56164 detailing IIS machine-key theft and deserialization-based persistence, recommending AMSI Full Request Body Scan mitigation.
  • Security media (BleepingComputer, Krebs on Security, Forbes, The Record) report on the record-scale patch release and the two actively exploited zero-days.
  • HKCERT publishes High Threat Security Alert A26-07-21 summarizing the July 2026 Microsoft release and confirming active exploitation of CVE-2026-56155 and CVE-2026-56164.
  • CISA federal mitigation deadline for CVE-2026-56164 (SharePoint Server), per KEV catalog binding operational directive timelines.
  • CISA action deadline for CVE-2026-56155 (AD FS elevation of privilege).

Update history for TL-2026-1336

Sources cited for Microsoft July 2026 Patch Tuesday

Threats related to Microsoft July 2026 Patch Tuesday

Detection coverage for TL-2026-1336

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1336 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats