Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661) — Threadlinqs Intelligence
As of 2026-07-15, Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1350 · Severity: CRITICAL · CVSS: 7.8 · Status: ACTIVE · Category: VULNERABILITY
Microsoft's July 2026 Patch Tuesday shipped a record 622 CVEs (57-62 Critical), including two zero-days with confirmed in-the-wild exploitation: an AD FS elevation-of-privilege flaw (CVE-2026-56155)
On July 14, 2026, Microsoft released its largest Patch Tuesday to date: 622 unique CVEs (some trackers report 569-570 due to differing de-duplication), including 57-62 rated Critical, 48 critical Remote Code Execution flaws, 7 critical Elevation of Privilege issues, 1 critical spoofing vulnerability, and 1 critical security-feature-bypass. Windows accounted for 416 CVEs, Office for 82, and Microsoft Edge for 46 (21 Microsoft-original, the rest inherited Chromium). Microsoft attributes the record volume in part to AI-assisted vulnerability discovery via its internal MDASH scanning system.
Two vulnerabilities carry confirmed active exploitation. CVE-2026-56155 is an insufficient-access-control-granularity flaw (CWE-1220) in Active Directory Federation Services (AD FS) discovered by Microsoft's own Detection and Response Team (DART) — credited to Jeremy Kingston and Scott Clark — while responding to real-world incidents, strongly suggesting it was already being abused in live intrusions before disclosure. It requires local access and low privileges (CVSS 3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, base 7.8) but grants full administrative elevation once triggered; because AD FS tokens establish trust across hybrid Azure AD/on-premises environments, exploitation enables attackers to forge or manipulate federated authentication trust in a manner reminiscent of Golden SAML attack patterns, giving durable enterprise-wide identity compromise.
CVE-2026-56164 is a missing-authentication-for-critical-function flaw (CWE-306) in on-premises Microsoft SharePoint Server (2016, 2019, and Subscription Edition), discovered by Mandiant incident responders and Google's FLARE team. It is remotely exploitable over the network by a fully unauthenticated attacker with no user interaction (CVSS 3.1 AV:N/AC:L/PR:N/UI:N, base 5.3 — rated only Moderate despite trivial reachability). Microsoft and third-party analysts (Talos, ZDI) stress the CVSS score understates real-world risk: 'when something this reachable is being actively abused, patch it now and worry about the score later.' The disclosure lands the same day SharePoint Server 2016 and 2019 reach end of extended support, complicating remediation for organizations that have not migrated. Pre-patch mitigation is enabling AMSI (Anti-Malware Scan Interface) integration on SharePoint/IIS worker processes with Request Body Scan mode set to Full so malicious POST payloads are detected before code execution.
A third vulnerability, CVE-2026-50661, is a protection-mechanism-failure flaw (CWE-693) in Windows BitLocker Device Encryption allowing an unauthenticated attacker with physical access to bypass full-disk encryption and read data directly off the storage device (CVSS 3.1 AV:P/AC:L/PR:N/UI:N, base 6.1). It was publicly disclosed with proof-of-concept code prior to patch release but has no confirmed in-the-wild exploitation; it continues a pattern of BitLocker physical-access bypasses disclosed through 2026 (e.g., the earlier 'YellowKey' CVE-2026-45585) and researchers note a possible but unconfirmed link to the 'GreatXML' bypass technique attributed to the Nightmare-Eclipse persona. It received an official Microsoft patch in this release, distinguishing it from YellowKey which initially shipped with mitigation-only guidance.
Separately, roughly 30 minutes after Microsoft's official Patch Tuesday disclosures, researcher MSNightmare (associated with the Nightmare-Eclipse persona, whose prior releases have been confirmed exploited in the wild) published proof-of-concept code for an unpatched, not-yet-CVE-assigned flaw in the Windows User Profile Service (profsvc), publicly nicknamed 'LegacyHive.' The bug allows a standard user to abuse the service's hive-loading mechanism to mount arbitrary registry hives with elevated privileges, enabling registry-based persistence, credential theft, and security-product tampering. The public PoC as released requires secondary user-account credentials, though the author c
Weaknesses (CWE)
CWE-1220, CWE-306, CWE-693, CWE-416, CWE-502, CWE-190, CWE-122
Target sectors: government administration, finance, health, technology, manufacturing, education, criticalinfrastructure
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-56155, CVE-2026-56164, CVE-2026-50661, CVE-2026-57092, CVE-2026-50522, CVE-2026-58644, CVE-2026-56190, CVE-2026-50518, CVE-2026-55040, T1190, T1068, T1548, T1134, T1606, T1649, T1556, T1003, T1562, T1211