
Microsoft Issues Record 570 Patches as AD FS and SharePoint Zero-Days Face Active In-The-Wild Exploitation
Microsoft's July 2026 Patch Tuesday fixes a record 570 vulnerabilities, including two critical zero-days in AD FS and SharePoint being actively leveraged by sophisticated threat actors.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-56155, CVE-2026-56164, CVE-2026-50661
- Source:
- Microsoft MSTIC
- Read Time:
- 5 min
Executive Summary
On July 15, 2026, Microsoft released a historic security update addressing 570 vulnerabilities, the largest single-month patch volume in the company's history. This release is dominated by the disclosure of two zero-day vulnerabilities, CVE-2026-56155 and CVE-2026-56164, which are currently being exploited in the wild. These flaws affect Active Directory Federation Services (AD FS) and Microsoft SharePoint Server, respectively. The Cybersecurity and Infrastructure Security Agency (CISA) has added both to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches by July 17, 2026. Simultaneously, a third zero-day affecting BitLocker was publicly disclosed, and an independent researcher known as 'Nightmare Eclipse' released a proof-of-concept (PoC) for an unpatched privilege escalation bug named 'LegacyHive'.
Threat Analysis
The primary threats involve elevation of privilege (EoP) and remote code execution (RCE). CVE-2026-56155 (AD FS) allows an authenticated attacker to escalate privileges to administrator levels on the federation server, potentially compromising the entire identity infrastructure. CVE-2026-56164 (SharePoint) involves missing authentication for critical functions, allowing unauthenticated network-based attackers to elevate privileges. These exploits are particularly dangerous because they target the 'Tier-0' identity layer and core collaboration platforms, providing attackers with a durable foothold for lateral movement or ransomware deployment.
Technical Details
- CVE-2026-56155 (CVSS 7.8): A flaw in the granularity of access controls within AD FS. Attackers with low-level credentials can abuse the gap in the Windows User Profile Service to gain System-level access.
- CVE-2026-56164 (CVSS 5.3): While rated 'Moderate', its active exploitation stems from an logic error in SharePoint's authentication pipeline. Attackers can bypass identity checks by sending specially crafted network requests to reach restricted management functions.
- LegacyHive (Zero-Day): Released by researcher 'Nightmare Eclipse', this exploit targets the ProfSvc (User Profile Service). It allows the mounting of arbitrary user hives (including Administrators) into the current user's registry space. While the public PoC is 'stripped' of its most malicious components, it remains functional on fully patched July 2026 systems.
Attribution Assessment
Initial intelligence from Microsoft's Threat Intelligence Center (MSTIC) suggests that the exploitation of the AD FS and SharePoint zero-days is currently limited to highly targeted campaigns. The tactics, techniques, and procedures (TTPs) align with sophisticated nation-state actors (APTs) focused on espionage and long-term persistence within Western enterprise networks. No specific group has been named, but the focus on identity infrastructure is a hallmark of strategic intelligence-gathering operations.
Implications
The unprecedented volume of patches—nearly triple the previous record—signals an escalation in the 'arms race' between AI-driven vulnerability discovery tools and defensive patching. Organizations relying on AD FS for single sign-on (SSO) face an immediate risk of credential theft and full forest compromise. The public disclosure of 'LegacyHive' by a disgruntled researcher underscores a growing trend of 'leak-first' disclosures that bypass traditional responsible disclosure channels, leaving defenders with zero lead time.
Recommendations
- Immediate Patching: Prioritize the deployment of the July 2026 Cumulative Updates for Windows Server, specifically focusing on AD FS and SharePoint instances.
- Enable AMSI for SharePoint: For environments unable to patch immediately, Microsoft recommends enabling the Antimalware Scan Interface (AMSI) and setting 'Request Body Scan' to 'Full'.
- Audit Identity Logs: Review AD FS and Entra ID logs for unusual service provider registrations or unauthorized modifications to federation settings.
- Restrict Physical Access: To mitigate the publicly disclosed BitLocker bypass (CVE-2026-50661), ensure physical security of mobile endpoints until the patch is verified.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
