Microsoft Patches Record 570Flaws Including Three Zero-Day Vulnerabilities

Share:

Microsoft released its largest ever security update on 14 July 2026, fixing 570 flaws across Windows
and its business software. Attackers are already using two of these flaws, in SharePoint and Active
Directory Federation Services (AD FS), to gain higher levels of access inside company networks. Apply
the July updates now, starting with SharePoint and identity servers.

1.Vulnerability Details

  • CVE-2026-56164 (CVSS 5.3): Microsoft describes missing authentication for a critical function in SharePoint Server, letting an unauthorised attacker elevate privileges over the network with no login.
  • CVE-2026-56155 (CVSS 7.8): Insufficient granularity of access control in AD FS lets an authorised attacker elevate privileges locally to administrator.
  • CVE-2026-50661 (CVSS 6.1): A BitLocker security feature bypass lets an attacker with physical access to a device read its encrypted data. No formal CWE identifiers were published in the sources reviewed for any of the three flaws.

2. Affected Products

  • Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition
  • Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations)
  • Windows 10 versions 1607, 1809, 21H2, and 22H2 (32-bit, x64, and ARM64)
  • Windows 11 versions 24H2, 25H2, and 26H1 (x64 and ARM64)

3. Observed Activity

Two of the three zero-days were exploited in the wild before a fix existed. Microsoft has released no detail on the attacks themselves.

  • CVE-2026-56164, SharePoint (exploited): Exploited over the network before the patch. CISA added it to the Known Exploited Vulnerabilities catalogue on 1 July 2026, 13 days before the fix, despite Microsoft’s original ‘Exploitation Less Likely’ rating. Credited to Mandiant Incident Response, Google Cloud, FLARE OTF, and an anonymous researcher. Enabling Antimalware Scan Interface (AMSI) with Request Body Scan set to Full mitigates it.
  • CVE-2026-56155, AD FS (exploited): Exploited in the wild to gain administrator privileges. Credited to Microsoft’s Detection and Response Team (DART), suggesting it was found while investigating active attacks.
  • CVE-2026-50661, BitLocker (publicly disclosed): Disclosed publicly with a working exploit before the patch; exploitation needs physical access and none has been observed. Tenable assesses it possibly corresponds to the GreatXML bypass published by the researcher Chaotic Eclipse on 10 June 2026; this link is unconfirmed.
  • Release context The 570-flaw total is nearly triple June’s record. Microsoft attributes the volume to AI-assisted vulnerability discovery and says future releases will stay larger. Elevation of privilege (254 flaws) and remote code execution (145 flaws) dominate the release.

4. Other Notable CVEs

  • CVE-2026-55944 (CVSS 9.8): Dynamics NAV and Dynamics 365 Business Central remote code execution; unauthenticated, no user interaction, rated Exploitation More Likely
  • CVE-2026-48561 (CVSS 9.6): Microsoft Copilot remote code execution; a malicious website can make Edge for Android send crafted prompts to Copilot
  • CVE-2026-50518 (CVSS 9.8): Windows DHCP Server remote code execution; rated Exploitation More Likely, one of nine DHCP flaws fixed this month
  • CVE-2026-49798 (CVSS 9.3): Windows Kernel elevation of privilege; rated Exploitation More Likely, one of 20 kernel elevation flaws fixed this month

5. Recommendations

  • Find unpatched Windows, AD FS, and SharePoint systems with your vulnerability scanner and apply the 14 July 2026 updates, prioritising internet-facing SharePoint and identity infrastructure.
  • On SharePoint servers that cannot patch immediately, enable Antimalware Scan Interface (AMSI) integration and set Request Body Scan mode to Full as an interim mitigation.
  • Review SharePoint and AD FS logs for unexpected privilege grants or unusual POST requests since 1 July 2026, and investigate any anomaly as potential compromise.
  • Apply the BitLocker update to laptops and portable devices, and enforce TPM with PIN pre-boot authentication where data sensitivity requires it.

6. Sources

  • https://msrc.microsoft.com/update-guide/en-us/releaseNote/2026-Jul
  • https://www.cisa.gov/news-events/alerts/2026/07/01/cisa-adds-one-known-exploited-vulnerabil
    ity-catalog
  • https://www.tenable.com/blog/microsofts-july-2026-patch-tuesday-addresses-569-cves-cve-2026-56155-cve-2026-56164
  • https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-mas
    sive-570-flaws-3-zero-days/
  • https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

×

7th August 2026

New Delhi, India

Know more
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert