ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

AI-driven bug hunting fuels record Microsoft Patch Tuesday

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-32201
Improper Input Validation Spoofing Vulnerability in Microsoft SharePoint Server

Microsoft SharePoint Server contains an improper input validation flaw (CWE-20) that can be triggered by an unauthenticated, network-based attacker submitting crafted input to the server. Successful exploitation allows the attacker to perform spoofing over the network, impersonating a trusted user or source within SharePoint; detailed impact mechanics have not been published and no CVSS score or public proof-of-concept is available. Any organization running on-premises Microsoft SharePoint Server is potentially affected, and the available data does not specify affected version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-14, indicating evidence of active exploitation, and EPSS assigns a 42.8% probability of exploitation within 30 days (99th percentile). Ransomware association is currently unknown.

Do: Apply Microsoft's security updates for SharePoint Server per the vendor advisory as soon as possible, and identify your SharePoint Server versions and builds since specific affected ranges are not provided here. Given the KEV listing, federal agencies must apply the vendor mitigations, follow applicable BOD 22-01 cloud guidance, or discontinue use by the established deadline. Until patched, limit network exposure of SharePoint servers and review authentication and access logs for signs of impersonation or spoofing activity.

6.543% KEV
  • Microsoft SharePoint Server
masslikely on the order of 100,000+ on-premises SharePoint Server installations, of which tens of thousands are directly internet-exposed
CVE-2026-45659
Authenticated Deserialization RCE in Microsoft SharePoint Server (Actively Exploited)

CVE-2026-45659 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Microsoft SharePoint Server in which an authorized (authenticated, low-privilege) attacker can submit crafted serialized data over the network, with no user interaction required, to execute code on the server. Successful exploitation carries high impact on confidentiality, integrity, and availability within the SharePoint service context, giving attackers a foothold for follow-on activity, and CISA notes that ransomware use is known. Organizations running on-premises Microsoft SharePoint Server are affected; the source data lists no specific version ranges, and the CPE scope (sharepoint server) points to the on-premises product rather than the Microsoft-managed SharePoint Online service. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-01 after active exploitation, and its EPSS score of 76.1% (100th percentile) indicates a high probability of near-term exploitation. The CVE record lists no public proof-of-concept, though related reporting describes exploitation activity following a public PoC release for a SharePoint authentication bypass.

Do: Apply Microsoft's current security updates for SharePoint Server following vendor instructions, prioritizing internet-facing servers, and comply with CISA BOD 26-04, which requires applying mitigations per vendor guidance (including the cited Forensics Triage Requirements) or discontinuing use of the product if mitigations are unavailable. Because in-the-wild exploitation and ransomware use are confirmed, triage exposed servers for compromise: review IIS/SharePoint logs for unexpected authenticated requests, look for webshells or newly modified files in SharePoint web roots, and check for unusual child processes spawned by the SharePoint application pool. Given related reporting on an authentication-bypass PoC, also verify that any related SharePoint authentication-bypass patches are…

8.876% KEV ransomware
  • Microsoft SharePoint Server
mass≈100,000 internet-exposed SharePoint Server deployments (order-of-magnitude estimate), with total users across on-premises deployments likely in the millions
CVE-2026-50522
+2 in the same advisory: …58644 …55040
Unauthenticated Deserialization RCE in Microsoft SharePoint Server

CVE-2026-50522 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server that allows an unauthenticated attacker to send maliciously crafted serialized data over the network and execute code on the server, reflected in its 9.8 critical CVSS score with no privileges or user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability, giving attackers a foothold for follow-on actions such as data theft, lateral movement, or ransomware. Any organization running on-premises SharePoint Server is in scope, particularly deployments reachable from untrusted networks; the required action notes stakeholders must evaluate each asset's internet exposure under CISA BOD 26-04. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-22 and security news headlines describe it as a critical RCE exploited in the wild, with some reports referencing exploitation after a public proof-of-concept release and an authentication bypass. The structured record lists no public PoC as confirmed, but an EPSS of 84.6% (100th percentile) underscores a very high near-term exploitation likelihood.

Do: Apply Microsoft's security updates for SharePoint Server immediately per the vendor advisory, as required under CISA's KEV listing and BOD 26-04, and prioritize any SharePoint deployments that are internet-facing (federal/critical-infrastructure operators must follow BOD 26-04 timelines or discontinue unmitigated use). Until patched, restrict public access to SharePoint endpoints (VPN, firewall rules, or reverse proxy) and review IIS/application logs and running processes for signs of unauthenticated deserialization abuse. Because some reports reference an authentication bypass being chained, also verify authentication paths and monitor for follow-on attacker activity after patching.

9.8
group max
85% KEV
  • Microsoft SharePoint Server (on-premises)
massorder of 100,000+ on-prem SharePoint Server deployments worldwide, with tens of thousands plausibly internet-exposed
CVE-2026-50661
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

NVD description · AI analysis pending
4.6<1%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
CVE-2026-56155
Local Privilege Escalation in Microsoft Active Directory Federation Services

CVE-2026-56155 is a high-severity (CVSS 3.1: 7.8) access-control flaw (CWE-1220) in Microsoft Active Directory Federation Services (AD FS), in which insufficient granularity of access control lets an authorized attacker elevate privileges locally. Exploitation requires only low local privileges and no user interaction, so any locally authenticated user or process on a system with the AD FS role can trigger it. Successful exploitation yields full local privilege escalation with high impact on confidentiality, integrity, and availability. It affects organizations running AD FS on Windows Server 2012, 2016, 2019, 2022, and 2025, and on Windows 10 versions 1607 and 1809, per CISA's affected-products list. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-07-14, confirming in-the-wild exploitation despite a modest EPSS of 0.3%; it was fixed as part of Microsoft's record-breaking July 2026 Patch Tuesday.

Do: Apply Microsoft's July 2026 security updates to all affected Windows 10 and Windows Server systems, prioritizing servers hosting the AD FS role, especially federation servers tied to Microsoft 365 or hybrid identity. Per CISA KEV and BOD 26-04, federal agencies must apply vendor mitigations promptly or discontinue use, and all defenders should inventory AD FS servers, restrict local logon to them, and triage for signs of local privilege-escalation activity. No public PoC or workaround beyond patching is currently known.

7.8<1% KEV
  • Microsoft Windows 10 (1607)
  • Microsoft Windows 10 (1809)
  • Microsoft Windows Server 2012
  • +4 more
largetens of thousands of internet-exposed AD FS servers; likely six figures of total AD FS deployments affected
CVE-2026-56164
Missing Authentication in Microsoft SharePoint Server Allows Privilege Escalation

Microsoft SharePoint Server contains a missing authentication for critical function vulnerability (CWE-306) that lets an unauthenticated attacker elevate privileges over a network without valid credentials. The flaw is triggered when the affected SharePoint function is accessed remotely without any authentication check, allowing an attacker to gain higher privileges than intended. Successful exploitation could enable an attacker to take elevated actions within the SharePoint environment, potentially leading to further compromise of the server and its data. All organizations running on-premises Microsoft SharePoint Server are potentially affected, though specific versions have not yet been enumerated by Microsoft or CISA. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-14, indicating it is being actively exploited, and its EPSS score of 26.6% (98th percentile) reflects a high near-term exploitation risk.

Do: Apply Microsoft's security updates for SharePoint Server as soon as they are available, and check Microsoft's advisory for the specific affected version ranges once published. In the meantime, restrict network access to SharePoint servers, especially for internet-facing instances, and verify whether your environment falls under CISA BOD 26-04 requirements given the KEV listing. Monitor for updated guidance from Microsoft and CISA, as exploitation is confirmed and patching urgency is high.

9.827% KEV
  • Microsoft SharePoint Server
masspotentially millions of users and well over 100,000 exposed installations worldwide
Full article839 words · extracted from helpnetsecurity.com · click to collapse

Microsoft has released patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged by attackers (CVE-2026-56155 and CVE-2026-56164), and one that was previouly disclosed (CVE-2026-50661).

The release was once again followed by Nightmare Eclipse publishing a stripped down proof-of-concept exploit for an unpatched Windows elevation of privilege (EoP) vulnerability, which the researcher dubbed LegacyHive.

Vulnerabilities of note

CVE-2026-56155 is an EoP flaw affecting Active Directory Federation Services (ADFS), and has been spotted being exploited in the wild by Microsoft’s incident responders.

Fixes for it have been bundled into Windows and Windows servers updates, and Microsoft also announced it’s started hardening the Access Control List (ACL) on the AD FS Distributed Key Manager container.

“[This vulnerability] stems from insufficient access-control granularity and does require local access and low privileges to start, but AD FS is exactly the kind of identity infrastructure attackers love to pivot through once they’re in. It can also be paired with an RCE as we often see in ransomware. Test and deploy this patch quickly,” commented Dustin Childs, head of threat awareness at TrendAI’s Zero Day Initiative.

CVE-2026-56164 is an EoP flaw found in Microsoft SharePoint Server that has been reported by Google’s incident responders and an anonymous researcher. It’s remotely exploitable in low-complexity attacks, and attackers are already taking advantage of it.

While enabling the Antimalware Scan Interface (AMSI) feature on SharePoint servers is noted as a possible mitigation, implementing security updates is still a must, especially because they fix additional SharePoint remote code execution vulnerabilities (CVE-2026-50522 and CVE-2026-58644) and a critical security feature bypass flaw (CVE-2026-55040).

“Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer, and published (…) in coordination with Microsoft, [CVE-2026-55040] is the first in a pair of exploits which, when chained together, can lead to unauthenticated remote code execution against a vulnerable SharePoint server,” commented Adam Barnett, Principal Software Engineer at Rapid7.

The second vulnerability in the full RCE chain remains embargoed for now, and Microsoft is expected to publish patches for it in August 2026, he added.

In other developments, the US Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations running SharePoint servers to apply additional hardening measures, in light of the fact that attackers are also exploiting two recently patched vulnerabilities (CVE-2026-32201 and CVE-2026-45659).

CVE-2026-50661 is a Windows BitLocker security feature bypass vulnerability that has been disclosed but not (yet) actively exploited.

“While not confirmed at this time, this CVE may be the patch for GreatXML, a BitLocker bypass exploit released by the Nightmare-Eclipse persona,” Crowdstrike noted.

Security patching in the age of AI-assisted vulnerability discovery

The flood of new vulnerabilities was expected and pre-announced, as Microsoft recently confirmed it’s been using AI to speed up internal discovery of software vulnerabilities.

The company also noted that other security researchers and attackers have been doing the same.

“If you’re not delivering critical quality updates with security fixes until a couple of weeks after they’ve been issued, that’s ample time for attackers using AI to find and exploit known security gaps,” Microsoft said.

“To address this, we’ve updated our recommendations for deploying Windows updates to less than three days as the deferral period for quality updates, setting deadlines for those updates to zero or one day, and the update grace period to a maximum of two days.”

Satnam Narang, senior staff research engineer at Tenable, also pointed out that the state of the Exploitability Index (how likely a vulnerability is to be exploited) must shift with the machine speed of discovery.

“For example, Microsoft originally tagged CVE-2026-45659, a SharePoint vulnerability, as exploitation less likely. However, the vulnerability was added to the CISA KEV on July 1,” he noted.

“Anthropic’s Red Team’s own findings for known vulnerabilities (n-days) revealed how fragile this system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated ‘Exploitation Less Likely’ or ‘Exploitation Unlikely.’ What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.”

Cybersecurity agencies of Five Eyes countries have recently advised organizations to integrate AI tools into their security operations so they can “detect vulnerabilities earlier, improve software quality, monitor unusual behaviour, and respond faster to incidents.”

They’ve also urged them to:

  • Reduce their attack surface by limiting access to them
  • Accelerated the patching process and prioritise security updates according to risk
  • Address legacy systems (i.e., decommission themm if possible)
  • Strengthen identity and access controls
  • Prepare for incidents before they happen.

UPDATE (July 16, 2026, 02:20 a.m. ET):

Microsoft has updated the security advisory for CVE-2026-58644, one of the SharePoint RCE vulnerabilities it fixed in June but for which the advisory was released only this Tuesday, to say that it is being exploited by attackers.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/07/15/microsoft-patch-tuesday-sharepoint-cve-2026-56164/