Active exploitation of two zero-day flaws drives massive Microsoft security update targeting 622 vulnerabilities
Microsoft has released a massive update addressing 622 vulnerabilities, including two zero-days currently being exploited in the wild. High-priority fixes target Active Directory Federation Services (AD FS) and SharePoint Server to prevent privilege escalation. Prioritize patching these identity and collaboration services immediately.
Summary
Microsoft's July 2026 Patch Tuesday addresses a record-breaking 622 vulnerabilities, pushing the company's year-to-date CVE count past previous annual totals. The update includes fixes for 416 Windows vulnerabilities and 164 Office suite flaws. Among the most critical findings are two zero-day vulnerabilities that have already been exploited in active environments.
Exploited Vulnerabilities
Two specific bugs are currently being exploited in the wild, requiring immediate attention from administrators:
- CVE-2026-56155: An Active Directory (AD) flaw affecting Federation Services (AD FS). This vulnerability allows an attacker to elevate their privileges locally to administrator status.
- CVE-2026-56164: A SharePoint Server flaw that enables privilege escalation. This can be exploited over the network without any prior authentication.
Additionally, Microsoft highlighted CVE-2026-50661, a BitLocker security feature bypass. This defect can be exploited by attackers with physical access and was publicly disclosed prior to this Patch Tuesday cycle. Researchers have suggested these vulnerabilities might be linked to a series of disclosures from the researcher known as Nightmare-Eclipse or Chaotic-Eclipse, though Microsoft has not officially confirmed this connection.
Technical Details
The July update addresses several high-impact flaws across various Windows components:
- Windows VMSwitch: A critical flaw tracked as CVE-2026-57092.
- SharePoint Server: Critical vulnerabilities tracked as CVE-2026-50522 and CVE-2026-50522.
- Remote Code Execution (RCE): Vulnerabilities identified in the Remote Desktop Protocol (CVE-2026-56190), Windows DHCP Server (CVE-2026-50518), and the Windows Server Network driver (CVE-2026-56188).
- Exchange Server: An XSS vulnerability tracked as CVE-2026-55008.
- Minecraft Bedrock Dedicated Server: A flaw tracked as CVE-2026-55010.
Microsoft executive VP Pavan Davuluri noted that the company is increasingly using a multi-model agentic scanning harness (MDASH) to accelerate vulnerability discovery across the Windows codebase through AI-driven processes.
Defender Guidance
Defenders should prioritize patching based on the following hierarchy:
- Identity and Collaboration: Apply patches for AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164) first, as these are actively being exploited to escalate privileges.
- Network Services: Address the RCE vulnerabilities in Remote Desktop Protocol, DHCP Server, and Windows Server Network drivers to prevent remote exploitation.
- Physical Security: Review BitLocker configurations following the disclosure of CVE-2026-50661.
The update also covers security weaknesses across Azure, Defender, Developer Tools, Edge, and SQL Server.
