
Microsoft's July Patch Tuesday fixes 570 bugs. Two zero-days in AD FS and SharePoint are already under active attack. Security teams are urged to patch these first.
Microsoft released the July Patch Tuesday update Tuesday, fixing 570 vulnerabilities. The company warned that two zero-day bugs, CVE-2026-56155 and CVE-2026-56164, are already exploited in the wild. Users of Active Directory Federation Services and SharePoint Server need to prioritize these updates.
CVE-2026-56155 is an elevation of privilege flaw in Active Directory Federation Services. CVE-2026-56164 is the same type of bug in Microsoft SharePoint Server. Microsoft has not disclosed how or when the attacks occurred. Microsoft confirmed both are active.
Jack Bicer, director of vulnerability research at Action1, said a successful exploit of CVE-2026-56155 can grant administrator privileges. “In environments using AD FS for authentication and identity services, administrator-level compromise can lead to unauthorized access to sensitive business resources, disruption of critical services, deployment of ransomware, theft of credentials, and broader compromise of enterprise infrastructure,” Bicer said.
Adam Barnett, principal software engineer at Rapid7, said the SharePoint zero-day is low complexity. “Successful exploitation allows an attacker to elevate privileges over a network, with no existing privileges required, and low attack complexity since an attacker does not require significant prior knowledge of the system, and can achieve repeatable success,” Barnett said.
Enterprise security teams should prioritize these two bugs. Jon Levenson, a director at Automox, said to patch CVE-2026-56155 first, ahead of higher-scoring bugs. Active exploitation outranks a bigger number, he said. He added that teams should treat ADFS as tier-zero identity infrastructure. After the initial box is patched, they should walk the rest of their identity path. A privilege escalation like this one is the second step in a chain. It is not the whole attack.
Levenson gave the same priority advice for the SharePoint bug. He said teams should audit site-owner and elevated-permission grants after patching. The access gained here might already have been used to create one.
Microsoft shares fell 1.55% to $384.93. The stock carries an Alpha Score of 58, labeled Moderate. The broader software sector has been under pressure from margin concerns tied to AI infrastructure spending, as OpenAI's ChatGPT Work Pressures Software Margins details. The Patch Tuesday news itself had a muted impact on the stock.
The two zero-days bring the total number of in-the-wild exploits Microsoft has addressed this year to a dozen. Microsoft has not said whether the attacks were targeted or widespread. Bicer and Barnett said organizations should assume exploitation attempts will increase once the patches are public. Reverse engineering the fixes is straightforward, they said.
The AD FS bug is a foothold for lateral movement, Levenson said. “If they got in here, they might have already set up a backdoor,” he said. “Don’t assume the patch is the end of the incident.”
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.