July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass) — Threadlinqs Intelligence
As of 2026-07-15, July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1372 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Microsoft's July 2026 Patch Tuesday addressed a record 622 CVEs (59 Critical), including three zero-days. CVE-2026-56155 (AD FS elevation of privilege) and CVE-2026-56164 (SharePoint Server elevation
Microsoft's July 2026 Patch Tuesday release is the largest in the company's 20-year vulnerability-disclosure history, fixing 622 CVEs (roughly triple June 2026's count of 206) including 59 vulnerabilities rated Critical. Three zero-day vulnerabilities were disclosed alongside the fix, two of which were confirmed under active exploitation at time of release and added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
CVE-2026-56155 is an elevation-of-privilege flaw in Active Directory Federation Services (AD FS) stemming from insufficient granularity of access control (CWE-1220). It requires an attacker to already hold authenticated, low-privileged local access to the AD FS host, from which they can escalate to administrator-level control. Because AD FS signs trusted security tokens used enterprise-wide for single sign-on and federated authentication, compromise of an AD FS host has outsized blast radius: an attacker with administrative control can alter federation trust settings, extract token-signing certificates, disable security controls, forge SAML/WS-Federation tokens for lateral movement into every service that trusts the federation, and use the host as a pivot point for further intrusion — a technique with strong overlap to historical Golden SAML abuse against ADFS infrastructure. Microsoft's DART (Detection and Response Team) identified the vulnerability while investigating live incident-response engagements, indicating it was discovered via observed attacker activity rather than proactive research. Microsoft assigned it Important severity with a CVSS 3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2026-56164 is a missing-authentication-for-critical-function flaw (CWE-306) in Microsoft SharePoint Server (on-premises) that allows an unauthenticated, network-based attacker to elevate privileges without any user interaction. NVD independently scored the flaw 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) while Microsoft's own CNA scoring rated it 5.3 Moderate (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) — a significant scoring divergence that understated real-world risk and is cited industry-wide as a case study in why CVSS base scores alone should not drive patch triage when active exploitation is confirmed. The flaw was reported by Mandiant (Jayson Frost) and Google Cloud/FLARE (Genwei Jiang), plus an anonymous researcher, and affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Critically, SharePoint Server 2016 and 2019 reached end of extended support on the same day (July 14, 2026) the patch was released, and no paid Extended Security Updates (ESU) program exists for on-prem SharePoint, creating acute remediation pressure for organizations still running those versions. Microsoft's interim mitigation is enabling Antimalware Scan Interface (AMSI) integration with SharePoint's Request Body Scan mode set to Full, pending patch deployment. This disclosure lands amid an active exploitation wave against separate, previously-patched SharePoint flaws (CVE-2026-32201, CVE-2026-45659) referenced in the same CISA guidance, and alongside newly disclosed critical SharePoint RCE pairs CVE-2026-50522/CVE-2026-58644 (untrusted-data deserialization, CVSS 9.8 each, no auth/user interaction required, CVE-2026-50522 publicly demonstrated at Pwn2Own Berlin) and CVE-2026-55040 (a security-feature bypass discovered by Rapid7's Stephen Fewer that chains with a separate embargoed vulnerability to achieve unauthenticated RCE) — collectively making SharePoint the highest-density target surface in this release.
CVE-2026-50661 is a protection-mechanism-failure security-feature bypass in Windows BitLocker Device Encryption. An attacker with physical, hands-on access to a target device can defeat BitLocker's disk-encryption guarantees and access data on the system drive without the encryption key or user credentials, undermining the primary defense against data
Weaknesses (CWE)
CWE-1220, CWE-306, CWE-693
Target sectors: government administration, finance, health, technology, education, manufacturing, critical-infrastructure, professional-services
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-50661, CVE-2026-56155, CVE-2026-56164, T1190, T1068, T1134, T1611, T1211, T1685, T1606, T1528, T1552, T1069