Microsoft released the largest Patch Tuesday in its history on July 14, 2026, addressing 570 vulnerabilities. At least two zero-days are under active exploitation: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server. A third zero-day, CVE-2026-50661 in BitLocker, has been publicly disclosed per Microsoft's definition, though not confirmed as exploited. Both actively exploited flaws were discovered during active breach investigations, not routine research.
- Microsoft patched 570 CVEs on July 14, 2026, the highest single-month total; the figure excludes 468 Edge/Chromium fixes counted separately by other vendors.
- Two zero-days are actively exploited: CVE-2026-56155 in AD FS (CVSS 7.8, local privilege escalation) and CVE-2026-56164 in SharePoint Server (CVSS 5.3 per Microsoft CNA, network-based privilege escalation without authentication).
- A third zero-day, CVE-2026-50661 (BitLocker), is publicly disclosed but not confirmed as exploited; Microsoft counts it among the month's zero-days, bringing the total to three for some sources.
- CISA added both actively exploited vulnerabilities to the KEV catalog under BOD 26-04: deadline July 28 for CVE-2026-56155, July 17 for CVE-2026-56164 per NVD records.
- Both active flaws were discovered by incident response teams (Microsoft DART and Mandiant/Google Cloud FLARE OTF) during active breach investigations, indicating operational use.
The SharePoint CVSS Discrepancy: 5.3 vs 9.8
CVE-2026-56164 presents a rare and problematic scoring divergence. Microsoft, as CNA, assigned CVSS 5.3 MEDIUM, classifying the missing authentication in SharePoint Server as limited integrity impact with no effect on confidentiality or availability. NVD calculated CVSS 9.8 CRITICAL, likely weighting network exposure and ease of exploitation.
The official Microsoft description, cited in the NVD record, reads: "Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network." The discrepancy has operational implications: teams that automatically filter for CVSS ≥ 7.0 risk excluding an actively exploited vulnerability. Affected versions are SharePoint Server 2016, 2019, and Subscription Edition; SharePoint Online is not affected.
Why Attackers Chose CVSS 7.8 and 5.3
In the same release, two DHCP Server RCE bugs (CVE-2026-50518 and CVE-2026-56159) score CVSS 9.8 CRITICAL with unauthenticated remote exploit, yet no source in the dossier reports active exploitation. The zero-days instead operate on more targeted vectors: AD FS requires local access with low privileges, SharePoint is network-exposed but with formally contained CVSS impact.
According to the dossier, CVE-2026-56155 exploits "insufficient granularity of access control" for local privilege escalation (CWE-1220), while CVE-2026-56164 bypasses authentication on critical functions (CWE-306). The attackers' choice may reflect a posture logic: targeting identity and collaboration infrastructure already inside the perimeter, where persistence and access to corporate data justify a more targeted exploit effort compared to mass RCE attacks on network services. This reading is interpretive: the dossier does not attribute specific motives to the attackers.
Record Volume and AI-Driven Acceleration
The July 2026 volume triples June's and quintuples May's, per CrowdStrike data cited by KrebsOnSecurity. Pavan Davuluri, Microsoft Executive Vice President, stated: "The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code." Trey Ford of Bugcrowd summarized: "AI has collapsed the cost of finding vulnerabilities, and this increase in volume is a new floor, not the ceiling."
Microsoft explicitly attributes the 570-CVE record to the AI-enhanced vulnerability discovery system announced in early 2026. The qualitative takeaway is that the increase is not isolated: enterprise security teams must adapt to volumes that exceed the capacity of traditional manual analysis.
"This isn't your typical Patch Tuesday. The volume alone changes the triage calculus" — Dark Reading, cited by Decryption Digest
What to Do Now
For organizations running AD FS and SharePoint Server on-premises, actions are bound by CISA KEV deadlines and the nature of the flaws:
- Prioritize CVE-2026-56164: the NVD record indicates a July 17, 2026 KEV catalog deadline; federal agencies must comply with BOD 26-04.
- Schedule CVE-2026-56155 with a July 28, 2026 deadline: the CVSS 7.8 HIGH score may tempt deferral if filtered by severity, but confirmed active exploitation and discovery by Microsoft DART demand immediate treatment.
- Assess CVE-2026-50661 (BitLocker): publicly disclosed but not confirmed as exploited; dossier sources do not specify a verified CVSS score.
- Verify that triage processes do not exclude KEV vulnerabilities solely due to low CNA CVSS: the SharePoint 5.3/9.8 discrepancy exposes the limits of automatic threshold filtering.
The Dossier Limits: What Remains Outside
The dossier does not identify threat actor groups or specific exploit campaigns for CVE-2026-56155 or CVE-2026-56164. The scope of compromises discovered by Microsoft DART and Mandiant prior to patch release is not documented. The exact nature of compromised data or infrastructure is not recorded. For CVE-2026-50661 (BitLocker), no dossier source confirms in-the-wild exploitation.
Information is based primarily on Tech Insider, with convergence from secondary sources. The brief does not specify whether CrowdStrike's monthly volume data refers exclusively to Microsoft CVEs or a broader scope.
Information has been verified against cited sources and is current as of publication.
Sources
- https://tech-insider.org/microsoft-patch-tuesday-july-2026-zero-days/
- https://securityonline.info/july-2026-patch-tuesday/
- https://www.decryptiondigest.com/blog/microsoft-patch-tuesday-july-2026-zero-days
- https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/
- https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/
- https://www.infosecurity-magazine.com/news/microsoft-570-cves-patch-tuesday/
- https://nvd.nist.gov/vuln/detail/CVE-2026-56155
- https://nvd.nist.gov/vuln/detail/CVE-2026-56164
- https://msrc.microsoft.com/update-guide/vulnerability/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog