ZeroHour
The Recordpublished ()ingested

Microsoft smashes Patch Tuesday record for second successive month

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-50656
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

NVD description · AI analysis pending
7.011% PoC
  • microsoft malware protection engine
CVE-2026-50661
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

NVD description · AI analysis pending
4.6<1%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
CVE-2026-55040
Authentication Bypass in Microsoft SharePoint Server

Microsoft SharePoint Server is affected by a weak authentication vulnerability (CWE-1390) that allows an unauthorized attacker to bypass a security feature over a network. Per the CVSS vector, exploitation requires no privileges and no user interaction with low attack complexity, so any unauthenticated attacker with network access to a vulnerable server can trigger it remotely. Impact to confidentiality and integrity is rated high (CVSS 9.1, critical), meaning the bypass effectively grants the attacker access that authentication should have prevented, with no direct availability impact. All organizations running on-premises Microsoft SharePoint Server are potentially affected; the source data does not specify affected version ranges or fixed builds, so defenders should consult Microsoft's advisory for those details. The flaw is under active exploitation: a public proof-of-concept is available on GitHub, attackers began exploiting it after the PoC went public, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18 (EPSS ~40%, 99th percentile; ransomware association unknown).

Do: Apply Microsoft's security update for CVE-2026-55040 immediately, prioritizing internet-facing SharePoint servers, and comply with CISA BOD 26-04 and the agency's Forensics Triage Requirements, including checking for signs of prior compromise on SharePoint servers. Use the public GitHub proof-of-concept to validate patching and detection coverage, and restrict network exposure of SharePoint until all servers are updated.

9.151% KEV PoC ×2
  • Microsoft SharePoint Server
mass≈tens of thousands of internet-exposed SharePoint Server instances, within an installed base spanning hundreds of thousands of enterprise and government…
CVE-2026-56155
Local Privilege Escalation in Microsoft Active Directory Federation Services

CVE-2026-56155 is a high-severity (CVSS 3.1: 7.8) access-control flaw (CWE-1220) in Microsoft Active Directory Federation Services (AD FS), in which insufficient granularity of access control lets an authorized attacker elevate privileges locally. Exploitation requires only low local privileges and no user interaction, so any locally authenticated user or process on a system with the AD FS role can trigger it. Successful exploitation yields full local privilege escalation with high impact on confidentiality, integrity, and availability. It affects organizations running AD FS on Windows Server 2012, 2016, 2019, 2022, and 2025, and on Windows 10 versions 1607 and 1809, per CISA's affected-products list. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-07-14, confirming in-the-wild exploitation despite a modest EPSS of 0.3%; it was fixed as part of Microsoft's record-breaking July 2026 Patch Tuesday.

Do: Apply Microsoft's July 2026 security updates to all affected Windows 10 and Windows Server systems, prioritizing servers hosting the AD FS role, especially federation servers tied to Microsoft 365 or hybrid identity. Per CISA KEV and BOD 26-04, federal agencies must apply vendor mitigations promptly or discontinue use, and all defenders should inventory AD FS servers, restrict local logon to them, and triage for signs of local privilege-escalation activity. No public PoC or workaround beyond patching is currently known.

7.8<1% KEV
  • Microsoft Windows 10 (1607)
  • Microsoft Windows 10 (1809)
  • Microsoft Windows Server 2012
  • +4 more
largetens of thousands of internet-exposed AD FS servers; likely six figures of total AD FS deployments affected
CVE-2026-56164
Missing Authentication in Microsoft SharePoint Server Allows Privilege Escalation

Microsoft SharePoint Server contains a missing authentication for critical function vulnerability (CWE-306) that lets an unauthenticated attacker elevate privileges over a network without valid credentials. The flaw is triggered when the affected SharePoint function is accessed remotely without any authentication check, allowing an attacker to gain higher privileges than intended. Successful exploitation could enable an attacker to take elevated actions within the SharePoint environment, potentially leading to further compromise of the server and its data. All organizations running on-premises Microsoft SharePoint Server are potentially affected, though specific versions have not yet been enumerated by Microsoft or CISA. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-14, indicating it is being actively exploited, and its EPSS score of 26.6% (98th percentile) reflects a high near-term exploitation risk.

Do: Apply Microsoft's security updates for SharePoint Server as soon as they are available, and check Microsoft's advisory for the specific affected version ranges once published. In the meantime, restrict network access to SharePoint servers, especially for internet-facing instances, and verify whether your environment falls under CISA BOD 26-04 requirements given the KEV listing. Monitor for updated guidance from Microsoft and CISA, as exploitation is confirmed and patching urgency is high.

9.827% KEV
  • Microsoft SharePoint Server
masspotentially millions of users and well over 100,000 exposed installations worldwide
Full article827 words · extracted from therecord.media · click to collapse

Microsoft on Tuesday released fixes for more than 600 security vulnerabilities, making July the largest Patch Tuesday in the program's history and more than triple the size of the previous record set last month.

Vulnerability counts have been surging this year, and July’s mammoth release of 622 CVEs is larger than the three previous months combined.

In a break from normal procedure, Microsoft's Security Update Guide no longer lists the individual CVEs of these vulnerabilities, replacing the previously itemised batch with a summary table showing a count of bugs by product family alongside a “Notable CVEs” section. Individual advisories for each CVE remain available separately. Microsoft last year stopped listing Chromium fixes in the guide as browser-vulnerability volumes exploded.

“All of this only serves to illustrate the recent industry-wide trend of exploding vulnerability report counts,” wrote Rapid7’s Adam Barnett, “with an associated uptick in the publication of remediations as a trailing indicator.

The release day marks the start of a regular cycle for cybersecurity defenders. Once a patch is out, attackers pick it apart in an attempt to reverse-engineer the holes it plugs and then race to break into machines that haven't updated yet — a phenomenon often described as “Exploit Wednesday.” A less detailed advisory risks making that triage harder, as defenders and third-party trackers must now piece together the full picture from underlying advisory feeds themselves.

Microsoft and analysts have suggested AI-assisted tools are behind the trend of rapidly rising volumes of vulnerabilities being discovered, although Microsoft did not specifically say how many of this month’s CVEs were found by such tools.

In May, the company revealed it had been using a new internal AI system called MDASH to hunt for security flaws in its own software. At the time, Tom Gallagher, vice president of engineering at Microsoft’s Security Response Center, said the company expects releases to continue trending larger.

Britain's National Cyber Security Centre (NCSC) issued a similar caution in April, warning organizations to brace for a wave of urgent updates. But while that wave appears to have arrived, a corresponding surge in cyberattacks has not yet been observed.

Jerry Gamblin, an engineer at Cisco, noted in an analysis earlier this month that while the curve for the volume of vulnerabilities “has gone vertical,” the curve for exploited vulnerabilities has not.

He found that of the more than 35,000 CVEs published by all vendors in the first half of this year, only 85 — 0.24% — had made an appearance in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog, though Gamblin noted the figure will rise as exploitation is confirmed.

Two bugs already under attack

Microsoft said two of this month’s flaws are currently being exploited in the wild. The first, CVE-2026-56164, is an elevation-of-privilege flaw in on-premises SharePoint Server that allows an unauthenticated attacker to escalate privileges over the network. Microsoft rates it “Important,” with a CVSS score of 5.3.

The second, CVE-2026-56155, is an elevation-of-privilege flaw in Active Directory Federation Services that allows an authenticated attacker to escalate privileges locally. Microsoft credited its incident-response unit, DART, with discovering both. Neither was on CISA's KEV catalog as of Wednesday morning, though Microsoft marks both as exploited.

A third SharePoint fix drew separate attention. CVE-2026-55040, a security feature bypass discovered by Rapid7 researcher Stephen Fewer and disclosed in coordination with Microsoft, is the first half of an exploit chain that Rapid7 said leads to unauthenticated remote code execution against a vulnerable server.

The second vulnerability in the chain remains embargoed, with Microsoft expected to patch it in August. Rapid7 rates the bypass 5.3, while Trend Micro’s Zero Day Initiative rates it 9.1.

The release also patches CVE-2026-50661, a publicly disclosed BitLocker security feature bypass that allows a physical attacker to circumvent drive encryption. Rapid7 said the advisory is consistent with a vulnerability announced under the name GreatXML the day after June's Patch Tuesday by Nightmare Eclipse — the pseudonymous researcher locked in a months-long standoff with Microsoft — though Microsoft does not confirm this.

Nightmare Eclipse, who has been posting working exploit code for unpatched Windows flaws to GitHub since April, had threatened a fresh exploit release to coincide with this Patch Tuesday, although in the days before the researcher partially walked back that threat.

Instead, a new proof-of-concept, nicknamed LegacyHive, emerged on Tuesday from the same source, which appears to allow a non-privileged user to mount another user's registry hive.

Microsoft patched a separate Defender elevation-of-privilege vulnerability — CVE-2026-50656, known as RoguePlanet — in an out-of-band update on July 8 after Nightmare Eclipse posted proof-of-concept code following June's release. Nightmare Eclipse has since claimed the patch introduces a disk-exhaustion vector.

No previous article

No new articles

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-vulnerabilities-patch-tuesday-release