July 2026 Patch Tuesday: Two Actively Exploited Microsoft Zero-Days (SharePoint EoP CVE-2026-56164, AD FS EoP CVE-2026-56155) Plus SharePoint JWT Auth Bypass CVE-2026-55040
July 2026 Patch Tuesday (TL-2026-1339), also tracked as July 2026 Patch Tuesday, is a high-severity software vulnerability scored CVSS 9.1, first published 2026-07-14. It has no confirmed attribution, affects Microsoft SharePoint Enterprise Server 2016, references 6 CVEs (CVE-2026-56164, CVE-2026-56155, CVE-2026-55040), maps to 20 MITRE ATT&CK techniques (T1003, T1006, T1059), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-1339
- Threat ID
- TL-2026-1339
- Also known as
- July 2026 Patch Tuesday, SharePoint JWT Auth Bypass Chain
- Severity
- HIGH
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, education, manufacturing, critical-infrastructure
- Target regions
- Global, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in July 2026 Patch Tuesday
Malware and tooling: GreatXML
Microsoft's July 2026 Patch Tuesday addressed a record 622 vulnerabilities (416 Windows). Two SharePoint/AD FS elevation-of-privilege flaws (CVE-2026-56164, CVE-2026-56155) are confirmed actively exploited and listed on CISA's KEV catalog. A third, critical SharePoint JWT authentication bypass (CVE-2026-55040, CVSS 9.1) was coordinated-disclosed by Rapid7 as the first half of an unauthenticated RCE chain whose second component is embargoed for the August 2026 release.
How July 2026 Patch Tuesday works
On 14 July 2026, Microsoft shipped its largest Patch Tuesday on record: 622 CVEs, including 416 Windows-related fixes. Two of the disclosed flaws were already being exploited as zero-days in the wild and were immediately added to CISA's Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-56164, a missing-authentication elevation-of-privilege flaw in Microsoft SharePoint Server (CWE-306), and CVE-2026-56155, an insufficient-access-control-granularity elevation-of-privilege flaw in Active Directory Federation Services (AD FS) (CWE-1220).
CVE-2026-56164 is network-reachable and requires no authentication or user interaction — Microsoft notes an attacker 'does not require significant prior knowledge of the system, and can achieve repeatable success,' and CISA states active exploitation is enabling threat actors to gain unauthorized access to on-premises SharePoint Server instances, establish remote code execution, and conduct post-exploitation activity including theft of IIS machine keys — a technique consistent with prior SharePoint ToolShell-style campaigns where stolen ASP.NET machine keys are used to forge viewstate payloads for persistent, re-authenticatable RCE even after the initial vulnerability is patched.
CVE-2026-56155 affects AD FS, Microsoft's identity federation/SSO infrastructure, and requires local access with low privileges to trigger — consistent with a second-stage privilege-escalation vector used after an attacker has already obtained a foothold, allowing pivoting toward domain administrator control of federated identity trust.
A third vulnerability, CVE-2026-55040 (CWE-1390, Weak Authentication), is a critical SharePoint Server JWT-token-validation bypass with a CVSS v3.1 base score of 9.1 (Microsoft's own scoring lists 5.3). It was discovered and coordinated-disclosed by Stephen Fewer, Senior Principal Security Researcher at Rapid7, built originally for a Rapid7 Labs Pwn2Own Berlin entry. Multiple flaws in SharePoint's JWT validation pipeline let a remote, unauthenticated attacker impersonate any SharePoint site user — including administrators — provided the attacker knows the target's Active Directory Security Identifier (SID) or User Principal Name (UPN) in advance. Rapid7 Labs has privately chained CVE-2026-55040 with a second, still-embargoed remote-code-execution vulnerability to achieve full unauthenticated RCE; that second bug is scheduled for disclosure/patch in Microsoft's August 2026 Patch Tuesday. CVE-2026-55040 itself is not currently listed as exploited in the wild, but public availability of exploitation research for the auth-bypass half creates meaningful risk ahead of the RCE half's disclosure.
The July release also included several other notable items referenced for context and completeness: CVE-2026-57092, a CVSS 9.9 use-after-free elevation-of-privilege flaw in the Windows Hyper-V VMSwitch component enabling guest-to-host VM escape; CVE-2026-50661, a Windows BitLocker security-feature-bypass (CVSS 6.1) believed to correspond to the publicly disclosed 'GreatXML' technique released in June 2026 by the pseudonymous researcher Nightmare Eclipse (aka Chaotic Eclipse), which abuses the WinRE (Windows Recovery Environment) trust boundary and a Defender Offline Scan artifact to plant attacker-controlled recovery-partition XML and obtain a SYSTEM-privileged command prompt with physical access, bypassing full-disk encryption; and CVE-2026-50663, a remote-code-execution flaw in Age of Empires II: Definitive Edition triggered by opening a malicious game scenario file that places files in unexpected filesystem locations.
The report underscores a broader industry trend of 'uncoordinated' disclosure: pseudonymous researchers such as Nightmare Eclipse are publishing zero-day exploit code and technical writeups (including public GitHub-style repositories) ahead of, or without, vendor coordination, compressing defenders' patch windows and increasing the operational tempo threat actors can exploit. All identified CVEs affect widely deployed enterprise infrastructure (SharePoint Server, AD FS, Windows Server, Hyper-V, BitLocker) and should be prioritized per CISA Binding Operational Directive 26-04 guidance, with the two KEV-listed flaws remediated ahead of their federal due dates (2026-07-17 for CVE-2026-56164, 2026-07-28 for CVE-2026-56155).
MITRE ATT&CK techniques used in TL-2026-1339
Credential Access
T1003 OS Credential Dumping; T1528 Steal Application Access Token; T1606 Forge Web Credentials
Defense Evasion
T1006 Direct Volume Access; T1070 Indicator Removal; T1211 Exploitation for Stealth
Execution
T1059 Command and Scripting Interpreter; T1059.001 PowerShell
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts; T1611 Escape to Host
Discovery
Initial Access
T1091 Replication Through Removable Media; T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services; T1550 Use Alternate Authentication Material
Persistence
T1505 Server Software Component; T1505.003 Web Shell; T1543 Create or Modify System Process
defense-impairment
Affected products and versions in July 2026 Patch Tuesday
- Microsoft — SharePoint Enterprise Server 2016
Vulnerable versions: < 16.0.5561.1001
Fixed in: 16.0.5561.1001 and later (July 2026 CU) - Microsoft — SharePoint Server 2019
Vulnerable versions: < 16.0.10417.20175
Fixed in: 16.0.10417.20175 and later (July 2026 CU) - Microsoft — SharePoint Server Subscription Edition
Vulnerable versions: < 16.0.19725.20434
Fixed in: 16.0.19725.20434 and later (July 2026 CU) - Microsoft — Active Directory Federation Services (AD FS)
Vulnerable versions: Windows 10 1607 < 10.0.14393.9339; Windows 10 1809 < 10.0.17763.9020; Windows Server 2012/R2 (all); Windows Server 2016 < 10.0.14393.9339; Windows Server 2019 < 10.0.17763.9020; Windows Server 2022 < 10.0.20348.5386; Windows Server 2025 < 10.0.26100.33158
Fixed in: July 2026 cumulative updates per build - Microsoft — Windows Hyper-V (VMSwitch)
Vulnerable versions: Pre-July 2026 CU builds
Fixed in: July 2026 CU - Microsoft — Windows BitLocker
Vulnerable versions: Builds with WinRE Defender Offline Scan artifact pre-July 2026
Fixed in: July 2026 CU - Microsoft — Age of Empires II: Definitive Edition
Vulnerable versions: Pre-July 2026 patch
Fixed in: July 2026 patch
Remediation for July 2026 Patch Tuesday
Patches
- Microsoft July 2026 Patch Tuesday cumulative update for SharePoint Enterprise Server 2016 (< 16.0.5561.1001)
- Microsoft July 2026 cumulative update for SharePoint Server 2019 (< 16.0.10417.20175)
- Microsoft July 2026 cumulative update for SharePoint Server Subscription Edition (< 16.0.19725.20434)
- Microsoft July 2026 cumulative update for AD FS on Windows Server 2012 R2 through Windows Server 2025
- Microsoft July 2026 cumulative update addressing CVE-2026-50661 BitLocker bypass (GreatXML/WinRE trust-boundary abuse)
- Microsoft July 2026 update for Age of Empires II: Definitive Edition (CVE-2026-50663)
Immediate actions
- Apply Microsoft's July 2026 cumulative security updates to all on-premises SharePoint Server 2016, 2019, and Subscription Edition farms immediately
- Apply AD FS security updates to all Windows Server hosts running Active Directory Federation Services
- Rotate ASP.NET machine keys on all SharePoint farms per Microsoft's ToolShell-era guidance, since stolen machine keys survive patching and enable forged-viewstate RCE persistence
- Review IIS logs and SharePoint ULS logs for signs of unauthenticated privilege-escalation attempts or unexpected machine-key export/config access consistent with CVE-2026-56164 exploitation
- Audit AD FS trust relationships and federation server configs for unauthorized local privilege escalation consistent with CVE-2026-56155
- Comply with CISA BOD 26-04 remediation deadlines: 2026-07-17 for CVE-2026-56164 and 2026-07-28 for CVE-2026-56155
Workarounds
- Where patching SharePoint is delayed, restrict SharePoint Server access to trusted internal networks and disable anonymous/unauthenticated access paths
- Disable or restrict WinRE offline scan / recovery-partition write access where BitLocker-protected devices face physical-access risk, pending the BitLocker patch
- Enforce AD FS access from trusted management hosts only until the AD FS update is deployed
Longer-term hardening
- Restrict network exposure of on-premises SharePoint Server to only required internal segments; avoid direct internet exposure
- Implement conditional access and hardened MFA on AD FS federation endpoints
- Deploy EDR/behavioral monitoring on SharePoint and AD FS servers for anomalous w3wp.exe process trees and PowerShell/command execution
- Establish a faster internal patch-testing SLA given the trend of pseudonymous zero-day disclosure that compresses defender response windows
- Track Rapid7's embargoed CVE-2026-55040 RCE-chain companion vulnerability ahead of its expected August 2026 disclosure and pre-stage patch deployment
CVEs associated with July 2026 Patch Tuesday
CVE-2026-56164, CVE-2026-56155, CVE-2026-55040, CVE-2026-50663, CVE-2026-50661, CVE-2026-57092
Weaknesses (CWE) in July 2026 Patch Tuesday
CWE-306, CWE-1220, CWE-1390, CWE-416
Timeline of July 2026 Patch Tuesday
- Pseudonymous researcher Nightmare Eclipse (Chaotic Eclipse) publicly discloses the 'GreatXML' BitLocker bypass, exploiting the WinRE trust boundary and a Defender Offline Scan artifact, without vendor coordination.
- GreatXML proof-of-concept code and technical writeups circulate publicly on independent git hosting, ahead of any Microsoft patch.
- Rapid7, Zero Day Initiative, Tenable, and Talos publish independent technical analyses of the July 2026 Patch Tuesday release.
- Rapid7's Stephen Fewer publicly discloses CVE-2026-55040, the SharePoint JWT authentication-bypass half of an unauthenticated RCE chain originally built for a Pwn2Own Berlin entry.
- CISA publishes an alert urging SharePoint hardening, noting active exploitation is enabling unauthorized access, RCE establishment, and IIS machine-key theft on on-premises SharePoint Server instances.
- CISA adds CVE-2026-56164 (SharePoint EoP) and CVE-2026-56155 (AD FS EoP) to the Known Exploited Vulnerabilities catalog, confirming active exploitation.
- Microsoft ships its July 2026 Patch Tuesday, a record 622 CVEs (416 Windows), including CVE-2026-56164, CVE-2026-56155, CVE-2026-55040, CVE-2026-50663, CVE-2026-50661, and CVE-2026-57092.
- CISA BOD 26-04 remediation deadline for CVE-2026-56164 (SharePoint EoP) for federal agencies.
- CISA BOD 26-04 remediation deadline for CVE-2026-56155 (AD FS EoP) for federal agencies.
- Expected disclosure/patch date for the embargoed RCE vulnerability that Rapid7 has privately chained with CVE-2026-55040 for full unauthenticated remote code execution, per Rapid7's August 2026 Patch Tuesday cycle.
Sources cited for July 2026 Patch Tuesday
- Patch Tuesday - July 2026 (Rapid7)
- CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
- Microsoft Security Response Center - CVE-2026-56164
- Microsoft Security Response Center - CVE-2026-56155
- Microsoft Security Response Center - CVE-2026-55040
- CISA Known Exploited Vulnerabilities Catalog
- CISA Urges SharePoint Hardening After New Exploitations
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
- Zero Day Initiative - The July 2026 Security Update Review
- Microsoft's July 2026 Patch Tuesday Addresses 569 CVEs (Tenable)
- Microsoft's July 2026 Patch Tuesday Addresses 569 CVEs (Security Boulevard)
- Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days (SecurityWeek)
- Record-Breaking Microsoft Patch Tuesday Update: 570 Vulnerabilities Fixed, Including 3 Zero-Days
- Microsoft Patch Tuesday for July 2026 - Snort rules and prominent vulnerabilities (Talos)
- Nightmare Eclipse drops claimed BitLocker bypass for Microsoft Windows
Threats related to July 2026 Patch Tuesday
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog
- Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164)
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)
Detection coverage for TL-2026-1339
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1339 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.