logo

Microsoft’s Largest Patch Tuesday Fixes 622 Vulnerabilities, Two Under Active Attack

ID: 0e733f30-c18d-5464-b199-84e980dd93a7

STIX ID: report--0e733f30-c18d-5464-b199-84e980dd93a7

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Ashish Khaitan

...
...

Microsoft's July 2026 Patch Tuesday addressed 622 CVEs across Windows, Office, Edge and other products and highlights two actively exploited zero-days—CVE-2026-56164 (unauthenticated remote elevation in on-premises SharePoint Server) and CVE-2026-56155 (authenticated local elevation in AD FS)—urging prioritized remediation and noting mitigations (AMSI Full Mode) and the increased risk due to SharePoint Server 2016/2019 reaching end of extended support.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.