Critical Microsoft Zero-Days Actively Exploited, CISA Issues Urgent Patching Directives
- CVE ID
- CVE-2026-58644, CVE-2026-56164, CVE-2026-56155
- Affected Products / Orgs
- Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, SharePoint Server 2016, SharePoint Enterprise Server 2016, Active Directory Federation Services (AD FS).
Overview
Microsoft’s July 2026 Patch Tuesday has delivered a record-breaking volume of security updates, addressing 622 vulnerabilities across its product line. Among these are three critical zero-day vulnerabilities (CVE-2026-58644, CVE-2026-56164, and CVE-2026-56155) that are confirmed to be actively exploited in the wild. The Cybersecurity and Infrastructure Security Agency (CISA) has issued urgent directives, adding CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog on July 17, 2026, mandating federal agencies to patch within three days. This release underscores the escalating threat posed by sophisticated attackers targeting widely used enterprise services.
Technical Details
The three actively exploited zero-days patched in July 2026 are:
-
CVE-2026-58644: Microsoft SharePoint Server Remote Code Execution (RCE) Vulnerability (CVSS 9.8) This critical vulnerability is a deserialization of untrusted data issue. In a network-based attack, an attacker authenticated as at least a Site Owner could inject and execute arbitrary code remotely on the SharePoint Server. While initially not marked as exploited, Microsoft later updated its advisory to reflect active exploitation, prompting CISA’s urgent KEV catalog addition. The flaw allows remote, authenticated attackers to execute arbitrary code on the server.
-
CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege (EoP) Vulnerability (CVSS 5.3) Despite its moderate CVSS score, this is an extremely dangerous unauthenticated, network-based privilege escalation vulnerability in SharePoint Server that requires no user interaction and is being actively exploited. It stems from a missing authentication for a critical function, allowing an unauthorized attacker to elevate privileges over a network. Affected versions include SharePoint Server 2016, 2019, and Subscription Edition. This vulnerability was discovered by Mandiant/Google FLARE incident responders, indicating its discovery during real-world attacks.
-
CVE-2026-56155: Active Directory Federation Services (AD FS) Elevation of Privilege (EoP) Vulnerability (CVSS 7.8) This important-severity vulnerability in AD FS is caused by insufficient granularity of access control. An attacker who has a low-privileged local account on the AD FS server can leverage this flaw to elevate their privileges to administrator level. While it requires local access, the compromise of AD FS is highly significant as it sits at the core of enterprise identity and trust, potentially enabling broader lateral movement and abuse across an organization’s infrastructure.
The sheer volume of 622 patches in this month’s release is partly attributed to Microsoft’s AI-powered vulnerability discovery system (MDASH), which is surfacing a greater number of bugs across the Windows codebase.
Real-World Impact
The active exploitation of these vulnerabilities poses an immediate and severe risk to organizations globally.
-
SharePoint Server Vulnerabilities (CVE-2026-58644, CVE-2026-56164): SharePoint is a cornerstone for collaboration and document management in many enterprises. Exploiting these flaws can lead to unauthorized remote code execution and privilege escalation, giving attackers deep access to highly sensitive data, intellectual property, and critical business operations. The unauthenticated nature of CVE-2026-56164 makes it particularly dangerous for internet-facing SharePoint deployments, as it can be exploited with low complexity and no user interaction. Compromise could result in extensive data theft, manipulation, or disruption of critical business processes.
-
AD FS Vulnerability (CVE-2026-56155): AD FS plays a crucial role in managing identity and access within federated environments. An attacker gaining administrator privileges on an AD FS server can potentially forge identities, gain unauthorized access to other linked applications and services, move laterally across the network, and even deploy ransomware or exfiltrate credentials on a massive scale. This represents a severe threat to an organization’s entire identity infrastructure.
CISA’s directive for CVE-2026-58644 underscores the high likelihood and severity of real-world attacks, placing federal agencies and, by extension, all organizations under immense pressure to patch immediately. The consequences for failing to patch promptly could include significant data breaches, operational downtime, financial losses, and severe reputational damage.
Threat Landscape
The July 2026 Patch Tuesday highlights several concerning trends in the current threat landscape. Firstly, the continued emergence and active exploitation of zero-day vulnerabilities in critical enterprise software, particularly those related to identity and collaboration, demonstrates the persistent focus of sophisticated threat actors on high-value targets. The fact that these flaws were discovered by incident responders during active attacks, rather than through proactive research, indicates their immediate and practical utility to adversaries.
Secondly, the CISA KEV catalog’s rapid inclusion of CVE-2026-58644 emphasizes the U.S. government’s recognition of the severe, widespread risk posed by these vulnerabilities. This puts pressure on both federal and private sector entities to adhere to strict patching timelines, moving away from a reactive, less urgent approach to vulnerability management.
Finally, the sheer volume of vulnerabilities addressed this month, partly due to AI-driven discovery, suggests that the pace of vulnerability disclosure may continue to accelerate. This requires organizations to bolster their vulnerability management programs, focusing not just on patching but also on robust threat intelligence to prioritize and respond to actively exploited flaws. The shift towards identity-based attacks also continues to be a major theme, as seen with the AD FS vulnerability.
Remediation
Organizations must prioritize the immediate application of Microsoft’s July 2026 security updates, especially focusing on the actively exploited vulnerabilities:
- Immediate Patching: Apply the latest Microsoft security updates for SharePoint Server (CVE-2026-58644, CVE-2026-56164) and Active Directory Federation Services (CVE-2026-56155) without delay. Given CISA’s directive, federal agencies have a three-day deadline for CVE-2026-58644, and all organizations should treat this as an urgent requirement.
- Verify Patch Deployment: After applying patches, ensure they have been successfully deployed and are effective across all affected systems.
- Strengthen SharePoint Security: For SharePoint Server, consider implementing Microsoft’s Antimalware Scan Interface (AMSI) integration, which can provide mitigation for CVE-2026-56164 by scanning for and detecting malicious POST requests. Review permissions for SharePoint Site Owners to ensure least privilege principles are applied.
- Enhance AD FS Security: For AD FS environments, ensure all administrative accounts are secured with strong, unique passwords and multi-factor authentication (MFA). Continuously monitor AD FS logs for any anomalous activity, such as unusual privilege escalation attempts or unauthorized access.
- Conduct Comprehensive Logging and Monitoring: Implement robust logging for SharePoint and AD FS environments and integrate these logs with security information and event management (SIEM) systems for continuous monitoring and rapid detection of suspicious activities.
- Regular Vulnerability Scanning and Penetration Testing: Regularly scan your environment for unpatched systems and conduct penetration tests to identify potential exploitation paths, especially for internet-facing services like SharePoint.
- Isolate Critical Systems: Where possible, segment and isolate critical systems like SharePoint and AD FS servers to limit potential lateral movement in the event of a compromise.
- Stay Informed: Keep abreast of the latest threat intelligence and CISA advisories to quickly respond to newly identified actively exploited vulnerabilities.
Proactive and swift action is paramount to protect against these critical, actively exploited zero-day threats and safeguard sensitive enterprise infrastructure.
Related content
Actively Exploited Zero-Days in Microsoft SharePoint and AD FS Demand Immediate Patching
Security NewsCISA Adds Four Actively Exploited Vulnerabilities, Including SonicWall and Microsoft…
Security NewsMicrosoft SharePoint Server Actively Exploited Zero-Day Vulnerability (CVE-2026-56164)
AdvisoryUrgent: Actively Exploited Microsoft ADFS Privilege Elevation Vulnerability…
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call