News Room
16
Share
Microsoft Issues Record 570 Patches as AD FS and SharePoint Zero-Days Face Active In-The-Wild Exploitation
criticalZero-Day Exploits

Microsoft Issues Record 570 Patches as AD FS and SharePoint Zero-Days Face Active In-The-Wild Exploitation

Microsoft's July 2026 Patch Tuesday fixes a record 570 vulnerabilities, including two critical zero-days in AD FS and SharePoint being actively leveraged by sophisticated threat actors.

16 July 2026Last updated 20 August 20265 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-56155, CVE-2026-56164, CVE-2026-50661
Source:
Microsoft MSTIC
Read Time:
5 min

Executive Summary

On July 15, 2026, Microsoft released a historic security update addressing 570 vulnerabilities, the largest single-month patch volume in the company's history. This release is dominated by the disclosure of two zero-day vulnerabilities, CVE-2026-56155 and CVE-2026-56164, which are currently being exploited in the wild. These flaws affect Active Directory Federation Services (AD FS) and Microsoft SharePoint Server, respectively. The Cybersecurity and Infrastructure Security Agency (CISA) has added both to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches by July 17, 2026. Simultaneously, a third zero-day affecting BitLocker was publicly disclosed, and an independent researcher known as 'Nightmare Eclipse' released a proof-of-concept (PoC) for an unpatched privilege escalation bug named 'LegacyHive'.

Threat Analysis

The primary threats involve elevation of privilege (EoP) and remote code execution (RCE). CVE-2026-56155 (AD FS) allows an authenticated attacker to escalate privileges to administrator levels on the federation server, potentially compromising the entire identity infrastructure. CVE-2026-56164 (SharePoint) involves missing authentication for critical functions, allowing unauthenticated network-based attackers to elevate privileges. These exploits are particularly dangerous because they target the 'Tier-0' identity layer and core collaboration platforms, providing attackers with a durable foothold for lateral movement or ransomware deployment.

Technical Details

  • CVE-2026-56155 (CVSS 7.8): A flaw in the granularity of access controls within AD FS. Attackers with low-level credentials can abuse the gap in the Windows User Profile Service to gain System-level access.
  • CVE-2026-56164 (CVSS 5.3): While rated 'Moderate', its active exploitation stems from an logic error in SharePoint's authentication pipeline. Attackers can bypass identity checks by sending specially crafted network requests to reach restricted management functions.
  • LegacyHive (Zero-Day): Released by researcher 'Nightmare Eclipse', this exploit targets the ProfSvc (User Profile Service). It allows the mounting of arbitrary user hives (including Administrators) into the current user's registry space. While the public PoC is 'stripped' of its most malicious components, it remains functional on fully patched July 2026 systems.

Attribution Assessment

Initial intelligence from Microsoft's Threat Intelligence Center (MSTIC) suggests that the exploitation of the AD FS and SharePoint zero-days is currently limited to highly targeted campaigns. The tactics, techniques, and procedures (TTPs) align with sophisticated nation-state actors (APTs) focused on espionage and long-term persistence within Western enterprise networks. No specific group has been named, but the focus on identity infrastructure is a hallmark of strategic intelligence-gathering operations.

Implications

The unprecedented volume of patches—nearly triple the previous record—signals an escalation in the 'arms race' between AI-driven vulnerability discovery tools and defensive patching. Organizations relying on AD FS for single sign-on (SSO) face an immediate risk of credential theft and full forest compromise. The public disclosure of 'LegacyHive' by a disgruntled researcher underscores a growing trend of 'leak-first' disclosures that bypass traditional responsible disclosure channels, leaving defenders with zero lead time.

Recommendations

  1. Immediate Patching: Prioritize the deployment of the July 2026 Cumulative Updates for Windows Server, specifically focusing on AD FS and SharePoint instances.
  2. Enable AMSI for SharePoint: For environments unable to patch immediately, Microsoft recommends enabling the Antimalware Scan Interface (AMSI) and setting 'Request Body Scan' to 'Full'.
  3. Audit Identity Logs: Review AD FS and Entra ID logs for unusual service provider registrations or unauthorized modifications to federation settings.
  4. Restrict Physical Access: To mitigate the publicly disclosed BitLocker bypass (CVE-2026-50661), ensure physical security of mobile endpoints until the patch is verified.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo