Microsoft July 2026 Patch Tuesday fixes 570 flaws, including exploited AD FS and SharePoint zero-days

Microsoft released its July 2026 Patch Tuesday updates to fix 570 security flaws, including two zero-days already being used in attacks and one publicly disclosed flaw. The exploited bugs are CVE-2026-56155 in Active Directory Federation Services (AD FS), a local privilege-escalation issue, and CVE-2026-56164 in Microsoft SharePoint Server, a network-reachable elevation-of-privilege flaw caused by missing authentication for a critical function; Microsoft also fixed the publicly disclosed BitLocker bypass CVE-2026-50661.
Why it matters: Organizations running affected Microsoft products should treat this as urgent because attackers were already exploiting two of the flaws before patches were available. Admins should prioritize patching AD FS and SharePoint servers immediately and apply Microsoft's SharePoint mitigations such as enabling Antimalware Scan Interface request-body scanning where applicable.

Sources

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
Ionut Arghire 2026.07.15 72% relevant
This article adds post-Patch-Tuesday operational guidance and KEV action for SharePoint, specifically highlighting CVE-2026-56164 as actively exploited and reminding defenders that CVE-2026-55040 and CVE-2026-58644 were also fixed in the same July release.
Microsoft cancels Patch Tuesday for some Dell users over surprise shutdowns, overheating devices
2026.07.15 84% relevant
This article adds operational impact to the July 2026 Patch Tuesday story: Microsoft has paused distribution of that month's Windows security update for some Dell devices with Intel processors because Dell-reported incompatibilities can cause shutdowns, overheating, poor performance, and battery drain.
Microsoft smashes Patch Tuesday record for second successive month
2026.07.15 97% relevant
This article is a direct follow-up on the same July 2026 Patch Tuesday event, adding updated scale (622 CVEs), naming the exploited flaws CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services, and noting a notable SharePoint exploit chain involving CVE-2026-55040.
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
info@thehackernews.com (The Hacker News) 2026.07.15 76% relevant
This appears to add follow-on reporting that a researcher published proof-of-concept exploit code for a new Windows zero-day within hours of Microsoft's July 2026 Patch Tuesday, increasing urgency around one of the flaws addressed in that release.
Patchpocalypse Now: Microsoft tops last month's record with 622 Patch Tuesday CVEs
2026.07.14 99% relevant
This article is a report on the same July 2026 Microsoft Patch Tuesday event and adds detail on the scale of the release, including 622 Microsoft CVEs plus 428 Chromium CVEs in Edge, and specifics on exploited CVEs CVE-2026-56155 (AD FS) and CVE-2026-56164 (SharePoint), as well as publicly disclosed CVE-2026-50661 and other critical issues.
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
info@thehackernews.com (The Hacker News) 2026.07.14 97% relevant
This appears to be another report on the same July 2026 Microsoft Patch Tuesday event, describing the same underlying release cycle and highlighting two zero-days under active attack, while differing mainly in flaw-count framing.
Microsoft Patches a Record 570 Security Flaws
BrianKrebs 2026.07.14 99% relevant
This is a direct report on the same July 2026 Microsoft Patch Tuesday event, adding detail on the total flaw count, the three zero-days addressed, the publicly disclosed BitLocker issue CVE-2026-50661, and notable high-severity bugs such as Copilot RCE CVE-2026-48561.
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
Ionut Arghire 2026.07.14 98% relevant
This article covers the same July 2026 Microsoft Patch Tuesday event and adds that Microsoft says it fixed a record 622 vulnerabilities, highlights the exploited zero-days CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint Server, and notes public disclosure of BitLocker bypass CVE-2026-50661 plus several other critical flaws.
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Lawrence Abrams 2026.07.14 100% relevant
This article establishes a distinct July 2026 Microsoft Patch Tuesday event centered on newly fixed zero-days, separate from the already tracked June 2026 Patch Tuesday story.
← Back to all stories