News Room
16
Share
Microsoft Patches Record 622 Flaws, Including ADFS and SharePoint Zero-Days Under Active Attack
criticalZero-Day Exploits

Microsoft Patches Record 622 Flaws, Including ADFS and SharePoint Zero-Days Under Active Attack

Microsoft's latest security update addresses a record 622 vulnerabilities, including two critical zero-days in Active Directory Federation Services and SharePoint Server exploited in the wild.

30 August 2026Last updated 30 August 20265 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-68820
Source:
Microsoft MSTIC
Read Time:
5 min

Executive Summary

On August 29, 2026, Microsoft released its most extensive security update to date, remediating a staggering 622 vulnerabilities across its software ecosystem. This unprecedented patch cycle is headlined by the discovery and mitigation of two zero-day vulnerabilities—one affecting Active Directory Federation Services (ADFS) and the other targeting SharePoint Server—both of which have been confirmed by Microsoft MSTIC as being under active exploitation in the wild. The scale of this release underscores a significant escalation in the discovery of critical flaws within core enterprise identity and collaboration infrastructure.

Threat Analysis

The primary focus of this intelligence report centers on the exploitation of ADFS and SharePoint Server. ADFS serves as the gatekeeper for identity management in many hybrid-cloud environments, making any vulnerability in this service a 'tier-0' security risk. The exploited zero-day allows attackers to bypass certain authentication checks, potentially leading to full identity takeover. Simultaneously, the SharePoint Server vulnerability provides a pathway for Remote Code Execution (RCE), allowing attackers to gain a foothold within internal networks to exfiltrate sensitive documents or deploy ransomware. The simultaneous exploitation of these two services suggests a coordinated effort by threat actors to compromise the entire chain of trust within targeted organizations.

Technical Details

The ADFS vulnerability involves a flaw in how the service validates security tokens during the authentication handshake. By crafting a specific malicious request, an attacker can trick the server into issuing a valid session token without requiring the secondary authentication factors typically enforced by Multi-Factor Authentication (MFA). The SharePoint flaw is rooted in the improper handling of serialized data within the server's web components. Attackers can trigger this vulnerability by uploading a specially crafted file or sending a malicious request to the SharePoint API, resulting in the execution of arbitrary code with the privileges of the SharePoint service account. Additionally, this patch cycle addressed a publicly disclosed BitLocker security bypass that could allow an attacker with physical access to circumvent disk encryption.

Attribution Assessment

While formal attribution is still ongoing, the sophistication required to discover and weaponize these specific zero-days points toward a highly capable Advanced Persistent Threat (APT). Preliminary telemetry from Threat Radar and other intelligence partners suggests that the exploitation patterns align with known tactics used by state-sponsored groups, particularly those focused on long-term espionage and data exfiltration. There are indications that a group with a Chinese nexus may be involved, though the Lazarus Group has also been recently active in exploiting similar zero-days in the Windows kernel (CVE-2026-68820) earlier this month.

Implications

The sheer volume of 622 patches creates a massive operational burden for IT and security teams. The 'patch gap'—the time between the release of a fix and its deployment—is the most critical window for attackers. Given that these flaws are already being exploited, organizations that delay patching are at extreme risk. The compromise of ADFS, in particular, has long-term implications for identity integrity, as attackers may have already established persistence by creating backdoored accounts or stealing signing certificates that remain valid even after the software is patched.

Recommendations

Encrygma Intelligence recommends that all organizations prioritize the deployment of the August 29, 2026, cumulative updates immediately. Priority should be given to ADFS and SharePoint servers, followed by Exchange and SQL Server instances. Security teams should perform a retrospective hunt for Indicators of Compromise (IoCs) in ADFS logs, specifically looking for anomalous token issuance events. Furthermore, organizations should verify the integrity of their BitLocker configurations and ensure that all endpoints are updated to prevent physical bypass attacks.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo