logo

CVE-2026-56164 and CVE-2026-56155: Two Exploited Microsoft Zero-Days Put SharePoint and AD FS at Risk

ID: 1d7e0183-bb83-5c0e-a3cb-dc609f0022bd

STIX ID: report--1d7e0183-bb83-5c0e-a3cb-dc609f0022bd

Feed Name: SOC Prime Blog

Threat Score
85/100

Date Published: 2026-07-16

Date Updated: 2026-07-23

Author: SOC Prime Team

...
...

Microsoft's July 2026 Patch Tuesday fixes two actively exploited zero-day elevation-of-privilege vulnerabilities: CVE-2026-56164 in on‑premises SharePoint Server (remote, no credentials or user interaction required) and CVE-2026-56155 in Active Directory Federation Services (local low‑privilege escalation). The advisory emphasizes immediate patching, enabling AMSI Full Mode for SharePoint as an added control, inventorying and prioritizing internet-facing servers, and hardening identity infrastructure because exploitation of these flaws can enable broad post-compromise abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.