All stories

Three zero-day vulnerabilities exploited in the wild require immediate Microsoft security updates

Microsoft's July 2026 Patch Tuesday addresses a record 570 flaws, including three zero-day vulnerabilities. Two of these are currently being exploited in the wild: one targeting Active Directory Federation Services (AD FS) and another targeting Microsoft SharePoint Server. Immediate patching is required to prevent unauthorized privilege escalation.

Summary

Microsoft has released security updates for 570 vulnerabilities, a significant increase driven by the company's new AI-powered vulnerability discovery system. The update includes 59 critical flaws, with 145 categorized as remote code execution and 254 as elevation of privilege. Among these are three zero-day vulnerabilities: two that are actively being exploited in attacks and one that was publicly disclosed prior to the patch release.

Active Exploitation of AD FS and SharePoint

Two high-priority vulnerabilities have been confirmed as actively exploited in current attacks.

CVE-2026-56155 (AD FS Elevation of Privilege) This flaw exists in Active Directory Federation Services (AD FS). Insufficient granularity in access control allows an authorized attacker to elevate their privileges locally. The vulnerability was discovered by Microsoft's Detection and Response Team (DART) during investigations into active attacks.

CVE-2026-56164 (SharePoint Server Elevation of Privilege) This flaw affects Microsoft Office SharePoint Server. An unauthorized attacker can gain elevated privileges over a network due to missing authentication for a critical function. This vulnerability was identified by researchers from Mandiant, Google Cloud, and FLARE OTF.

BitLocker Security Bypass

The third zero-day addressed in this cycle is CVE-2026-50661, a Windows BitLocker security feature bypass. Unlike the previous two flaws, this vulnerability was publicly disclosed before a fix was available.

An attacker with physical access to a target system's storage device can exploit this flaw to bypass BitLocker Device Encryption and gain access to encrypted data. This vulnerability was attributed to an anonymous researcher.

Defender guidance

To mitigate the risks associated with these vulnerabilities, implement the following actions:

  • For SharePoint Server (CVE-2026-56164): Enable the Antimalware Scan Interface (AMSI) on the server and configure the Request Body Scan mode to "Full" to help mitigate the risk of unauthorized privilege escalation.
  • For AD FS (CVE-2026-56155): Apply the Microsoft security update immediately to address the insufficient access control granularity.
  • For BitLocker (CVE-2026-50661): Deploy the latest Windows updates to prevent attackers with physical access from bypassing device encryption.

What remains unclear

While Microsoft has confirmed that the AD FS and SharePoint vulnerabilities are being exploited in active attacks, specific details regarding the methods of exploitation or the specific threat actors involved have not been disclosed.

Sources

  1. https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/
  2. https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-56155
  3. https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-56164
  4. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -