July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days — Threadlinqs Intelligence
As of 2026-07-17, July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days is a critical-severity vulnerability threat attributed to Storm-2603 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1437 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Storm-2603 · China · ESPIONAGE
Microsoft's July 2026 Patch Tuesday (622 CVEs, its largest on record) shipped fixes for multiple zero-days under active exploitation: CVE-2026-58644, a network-reachable, unauthenticated SharePoint
On July 14, 2026, Microsoft released its July Patch Tuesday update covering 622 CVEs — the largest single release in Patch Tuesday history — including at least four vulnerabilities of immediate operational concern to defenders.
CVE-2026-58644 is a CVSS 9.8 deserialization-of-untrusted-data (CWE-502) remote code execution vulnerability in Microsoft Office SharePoint Server (Enterprise Server 2016 builds before 16.0.5556.1005, Server 2019 builds before 16.0.10417.20153, and Subscription Edition builds before 16.0.19725.20384). The flaw is network-reachable, requires no authentication and no user interaction, and allows an attacker to send a crafted serialized payload that SharePoint deserializes without adequate validation, resulting in arbitrary code execution in the context of the SharePoint application pool. Microsoft's exploitation-status field was updated from 'Exploitation More Likely' to 'Detected' on July 15, 2026, one day after release, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. It shares an identical root cause and CVSS score with the same-day CVE-2026-50522, which Zero Day Initiative researchers publicly demonstrated at Pwn2Own Berlin — Microsoft nonetheless listed CVE-2026-50522 as 'Exploit Maturity Unknown' at release, drawing criticism from the ZDI team, which noted it had handed Microsoft a working exploit.
CVE-2026-56164 is a CWE-306 (Missing Authentication for Critical Function) elevation-of-privilege flaw in on-premises SharePoint Server (2016, 2019, Subscription Edition) that lets an unauthenticated attacker reach a critical function over the network with no user interaction and no valid SharePoint credentials. Microsoft's CNA scored it 5.3 (low integrity impact only), but NVD's independent CVSS assessment rated it 9.8, reflecting a significant severity disagreement driven by differing assumptions about downstream impact once the missing-authentication gap is used as a pivot. CISA's KEV entry (effective July 14, 2026) and its accompanying alert describe active campaigns chaining CVE-2026-56164 together with older, previously disclosed SharePoint weaknesses (the 2025 ToolShell-class bugs CVE-2025-49704/CVE-2025-49706/CVE-2025-53770/CVE-2025-53771, plus 2026 SharePoint RCEs CVE-2026-32201 and CVE-2026-45659) to steal ASP.NET/IIS machine keys, forge __VIEWSTATE deserialization payloads for persistence, and deploy malware. The July 2025 ToolShell campaign that established this playbook was attributed to Chinese nation-state actors Linen Typhoon and Violet Typhoon, plus the ransomware affiliate Storm-2603, which deployed Warlock ransomware against victims across finance, healthcare, government, and energy sectors — CISA explicitly cites this precedent as the operational template for the July 2026 wave. This ToolShell-class exploitation chain is separately catalogued by MITRE ATT&CK as Campaign C0058.
CVE-2026-56155 is a CWE-1220 (Insufficient Granularity of Access Control) local elevation-of-privilege vulnerability (CVSS 7.8, vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) in Active Directory Federation Services (AD FS). The flaw exists in insufficiently restrictive permissions on the AD FS Distributed Key Manager (DKM) Active Directory container, which stores the symmetric key material that protects AD FS token-signing and token-decryption certificate private keys. A low-privileged local attacker — commonly an attacker who has already obtained a foothold via another vector — can abuse the loose ACL to read or tamper with DKM key material, enabling forgery of SAML/WS-Fed tokens and full compromise of the federation trust boundary, which in hybrid-identity environments cascades into Entra ID / Microsoft 365 access. Microsoft lists exploitation as 'Detected'; CISA added it to KEV on July 14, 2026 with a federal remediation deadline of July 28, 2026 under BOD 22-01. Microsoft's remediation is phased: from the July 14, 2026 update onward, the AD FS service audits the DKM con
Weaknesses (CWE)
CWE-502, CWE-1220, CWE-306, CWE-693
Target sectors: government administration, finance, health, energy, technology, education
Target regions: North America, Europe, Asia Pacific
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-58644, CVE-2026-56155, CVE-2026-56164, CVE-2026-50661, CVE-2026-50522, CVE-2026-45659, CVE-2026-32201, CVE-2026-55040, T1190, T1055, T1505.003, T1505, T1078, T1068, T1548, T1562.001, T1070, T1528