Microsoft released its largest Patch Tuesday update on record, fixing roughly 570 to 622 Microsoft CVEs across Windows, Office, SharePoint Server, Exchange Server, SQL Server, Edge, Azure, Defender, and developer tools. The release included three zero-days, with CVE-2026-56155 in Active Directory Federation Services (AD FS) and CVE-2026-56164 in on-premises Microsoft SharePoint Server confirmed as exploited in the wild, while CVE-2026-50661 patched a publicly disclosed BitLocker security feature bypass requiring physical access. Microsoft and multiple security outlets said the surge in findings was partly driven by AI-assisted vulnerability discovery, while the broader update also addressed dozens of critical remote code execution flaws in services such as DHCP, Hyper-V, Office, Exchange, SQL Server, Copilot, and SharePoint.
U.S. agencies and industry groups elevated the urgency around SharePoint after CISA warned that attackers were actively exploiting CVE-2026-56164 alongside CVE-2026-32201 and CVE-2026-45659 against internet-exposed on-premises servers, enabling unauthorized access, remote code execution, theft of IIS machine keys, persistence, and malware deployment. CISA added the exploited AD FS and SharePoint flaws to its Known Exploited Vulnerabilities catalog and urged immediate remediation, while Microsoft recommended SharePoint hardening measures including AMSI integration with full request body scanning and stronger Defender protections; exposed identity systems, SharePoint farms, and other internet-facing Microsoft services were identified as the highest-priority patch targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Microsoft released July 2026 security updates fixing five Important Windows Remote Desktop Protocol information disclosure vulnerabilities: CVE-2026-50445, CVE-2026-57982, CVE-2026-55003, CVE-2026-50497, and CVE-2026-57979. The flaws could expose sensitive process memory during remote sessions, and no public exploits or in-the-wild exploitation were reported at publication time.
The three exploited SharePoint vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 were added to CISA's Known Exploited Vulnerabilities Catalog. Federal agencies were ordered under BOD 26-04 to secure systems affected by CVE-2026-56164 by July 17 or discontinue them if mitigations could not be applied.
CISA warned that attackers were actively exploiting three vulnerabilities in Internet-exposed on-premises Microsoft SharePoint Server instances: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. The agency also highlighted CVE-2026-55040 and CVE-2026-58644 as attractive targets and urged immediate patching, AMSI and Defender protections, reduced Internet exposure, and reverse-proxy protections.
WaterISAC warned that multiple on-premises Microsoft SharePoint Server vulnerabilities were being actively exploited, citing CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. The notice said attackers could steal IIS machine keys, gain persistence, and deploy malware, and it highlighted risks to utilities that use SharePoint for sensitive internal records.
Microsoft disclosed and fixed CVE-2026-50479, an elevation-of-privilege vulnerability in the Windows USB Hub Driver classified as CWE-822 with a CVSS score of 7.8. The Security Update Guide credited Adrian Denkiewicz of Doyensec, in collaboration with Claude and Anthropic Research, for reporting the issue.
Microsoft disclosed and patched CVE-2026-50661, a publicly known BitLocker security feature bypass vulnerability requiring physical access to a target device. Microsoft said it had not observed active exploitation in the wild and delivered fixes through the July 14 cumulative updates.
Microsoft disclosed CVE-2026-56164, a SharePoint Server elevation-of-privilege vulnerability caused by missing authentication for a critical function. Microsoft said the flaw had been exploited in the wild, released a fix, and recommended enabling AMSI with full request body scanning and IIS worker process memory scanning as mitigation.
Microsoft disclosed CVE-2026-56155, an Important elevation-of-privilege vulnerability in Active Directory Federation Services caused by insufficient granularity of access control. Microsoft said exploitation had been detected in the wild, functional exploit code was available, and a fix was available.
Microsoft released its July 2026 Patch Tuesday security updates, the largest Patch Tuesday on record, addressing roughly 570 to 622 Microsoft CVEs across Windows, Office, SharePoint, Exchange, SQL Server, Azure, and other products. The release included three zero-days, with CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint confirmed as exploited in the wild, and CVE-2026-50661 in BitLocker publicly disclosed before patching.
The CVE record for CVE-2026-56164 was published, describing a SharePoint Server elevation-of-privilege flaw caused by missing authentication for a critical function and affecting SharePoint Server 2016, 2019, and Subscription Edition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecyberveille.ch
Open sourcecysecurity.news
Open sourcesocprime.com
Open sourcecwe.mitre.org
Open sourcerapid7.com
Open sourcelearn.microsoft.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.