
Microsoft Patches Record 622 Flaws, Including ADFS and SharePoint Zero-Days Under Active Attack
Microsoft's latest security update addresses a record 622 vulnerabilities, including two critical zero-days in Active Directory Federation Services and SharePoint Server exploited in the wild.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-68820
- Source:
- Microsoft MSTIC
- Read Time:
- 5 min
Executive Summary
On August 29, 2026, Microsoft released its most extensive security update to date, remediating a staggering 622 vulnerabilities across its software ecosystem. This unprecedented patch cycle is headlined by the discovery and mitigation of two zero-day vulnerabilities—one affecting Active Directory Federation Services (ADFS) and the other targeting SharePoint Server—both of which have been confirmed by Microsoft MSTIC as being under active exploitation in the wild. The scale of this release underscores a significant escalation in the discovery of critical flaws within core enterprise identity and collaboration infrastructure.
Threat Analysis
The primary focus of this intelligence report centers on the exploitation of ADFS and SharePoint Server. ADFS serves as the gatekeeper for identity management in many hybrid-cloud environments, making any vulnerability in this service a 'tier-0' security risk. The exploited zero-day allows attackers to bypass certain authentication checks, potentially leading to full identity takeover. Simultaneously, the SharePoint Server vulnerability provides a pathway for Remote Code Execution (RCE), allowing attackers to gain a foothold within internal networks to exfiltrate sensitive documents or deploy ransomware. The simultaneous exploitation of these two services suggests a coordinated effort by threat actors to compromise the entire chain of trust within targeted organizations.
Technical Details
The ADFS vulnerability involves a flaw in how the service validates security tokens during the authentication handshake. By crafting a specific malicious request, an attacker can trick the server into issuing a valid session token without requiring the secondary authentication factors typically enforced by Multi-Factor Authentication (MFA). The SharePoint flaw is rooted in the improper handling of serialized data within the server's web components. Attackers can trigger this vulnerability by uploading a specially crafted file or sending a malicious request to the SharePoint API, resulting in the execution of arbitrary code with the privileges of the SharePoint service account. Additionally, this patch cycle addressed a publicly disclosed BitLocker security bypass that could allow an attacker with physical access to circumvent disk encryption.
Attribution Assessment
While formal attribution is still ongoing, the sophistication required to discover and weaponize these specific zero-days points toward a highly capable Advanced Persistent Threat (APT). Preliminary telemetry from Threat Radar and other intelligence partners suggests that the exploitation patterns align with known tactics used by state-sponsored groups, particularly those focused on long-term espionage and data exfiltration. There are indications that a group with a Chinese nexus may be involved, though the Lazarus Group has also been recently active in exploiting similar zero-days in the Windows kernel (CVE-2026-68820) earlier this month.
Implications
The sheer volume of 622 patches creates a massive operational burden for IT and security teams. The 'patch gap'—the time between the release of a fix and its deployment—is the most critical window for attackers. Given that these flaws are already being exploited, organizations that delay patching are at extreme risk. The compromise of ADFS, in particular, has long-term implications for identity integrity, as attackers may have already established persistence by creating backdoored accounts or stealing signing certificates that remain valid even after the software is patched.
Recommendations
Encrygma Intelligence recommends that all organizations prioritize the deployment of the August 29, 2026, cumulative updates immediately. Priority should be given to ADFS and SharePoint servers, followed by Exchange and SQL Server instances. Security teams should perform a retrospective hunt for Indicators of Compromise (IoCs) in ADFS logs, specifically looking for anomalous token issuance events. Furthermore, organizations should verify the integrity of their BitLocker configurations and ensure that all endpoints are updated to prevent physical bypass attacks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day CVE-2026-82078 Hits PaperCut NG/MF; Active Exploitation Confirmed in Enterprise Environments

PaperCut Issues Emergency Patch for Actively Exploited Zero-Day Vulnerability in NG/MF Print Management Software

