CVE-2026-56164 & CVE-2026-56155: Microsoft's SharePoint and AD FS Zero-Days in the July 622-CVE Patch Tuesday
Deep dive into Microsoft's record 622-CVE Patch Tuesday featuring active SharePoint and Active Directory Federation Services zero-days.
CVE-2026-56164 / 56155
Severity: CVSS 9.8
Status: Active zero-days in July Patch Tuesday
Target Component: SharePoint Server & AD FS
What's Affected
Microsoft's July release covered 622 CVEs, the largest single Patch Tuesday on record. Two flaws in that release are confirmed under active exploitation: an on-premises SharePoint Server flaw and an Active Directory Federation Services (AD FS) flaw. Affected products are on-premises SharePoint Server deployments and AD FS servers running supported Windows Server versions that had not yet applied this month's cumulative update. SharePoint Online (Microsoft 365) is not affected by the on-prem SharePoint flaw.
The Vulnerabilities
CVE-2026-56164, CVSS 5.3: a SharePoint Server flaw that lets an unauthenticated attacker escalate privileges over the network. Despite the moderate CVSS score, Microsoft confirmed active exploitation, which is why it is treated as high priority regardless of the numeric score.
CVE-2026-56155, CVSS 7.8: an AD FS flaw that lets an already-authenticated attacker elevate privileges locally through weak access controls on federation configuration.
Separately, CVE-2026-45659, a SharePoint Server RCE from an earlier disclosure, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog this week after confirmed in-the-wild exploitation, and is being chained with the newer flaws in some observed attacks against on-prem SharePoint farms.
Exploitation Pattern
Attackers are targeting internet-facing SharePoint Server farms that have not applied this month's cumulative update. The general pattern observed: initial access through the unauthenticated SharePoint privilege escalation path, followed by lateral movement toward AD FS infrastructure where the local privilege escalation flaw is used to gain a stronger foothold in the identity layer. Because AD FS underpins federated authentication for many downstream applications, compromising it can cascade into broader single-sign-on trust abuse well beyond the SharePoint farm itself.
Remediation
Apply this month's cumulative Windows Server and SharePoint Server updates as an emergency priority for any internet-facing SharePoint Server deployment, given the confirmed active exploitation and KEV listing. For AD FS servers, apply the update and separately audit federation trust configurations and access control policies for the weakness described in CVE-2026-56155. Review SharePoint and AD FS authentication and admin-action logs for the two weeks prior to patching for unexpected privilege changes, new service accounts, or federation trust modifications. Treat any SharePoint farm that was internet-facing and unpatched during this window as a candidate for a deeper compromise assessment, not just a patch-and-move-on.
Related
This post is part of this week's Security Roundup: SonicWall Zero-Days, Microsoft's Record Patch Tuesday, and the Klue Breach Fallout (Week of July 13, 2026), at colibrisec.org/security-roundup-sonicwall-microsoft-klue-july-13-2026/.