Back to Blog
CVE-2026-56164, CVE-2026-56155: Microsoft SharePoint & AD FS — Active Exploitation, Privilege Escalation (July 2026)
vulnerabilities

CVE-2026-56164, CVE-2026-56155: Microsoft SharePoint & AD FS — Active Exploitation, Privilege Escalation (July 2026)

breachwire TeamJul 15, 20262 min read

CVE-2026-56164, CVE-2026-56155 — Microsoft SharePoint & AD FS

Microsoft has released critical patches for CVE-2026-56164 (SharePoint Server) and CVE-2026-56155 (Active Directory Federation Services), both rated critical and confirmed as zero-day vulnerabilities under active exploitation. These flaws permit attackers to escalate privileges—remotely in SharePoint and locally in AD FS—potentially granting full control over affected systems. No CVSS scores are published, but Microsoft classifies both as critical with immediate exploitation in the wild.

Attack Vector

CVE-2026-56164 targets on-premises SharePoint Server, allowing remote attackers to exploit insufficient privilege validation and gain elevated access. CVE-2026-56155 impacts AD FS, where local attackers can bypass authentication controls to escalate privileges. Both require access to exposed or misconfigured services; exploitation is confirmed in the wild. The update also addresses CVE-2026-50661, a BitLocker bypass, and several critical remote code execution bugs, further expanding the attack surface if unpatched.

Who Is at Risk

All organizations running on-premises Microsoft SharePoint Server (2016, 2019, and later) and Active Directory Federation Services are at risk. The July 2026 update marks the end of support for SharePoint Server 2016 and 2019, increasing urgency for those deployments. Enterprises relying on AD FS for authentication are especially vulnerable to lateral movement and privilege escalation attacks.

Patch & Mitigate

  • Patch: Apply the July 14, 2026 Patch Tuesday updates for all affected Microsoft products without delay. Prioritize SharePoint Server and AD FS systems.
  • Workaround: No official workarounds are available; patching is the only effective mitigation.
  • Detect: Monitor for anomalous privilege escalation events in SharePoint and AD FS logs. Look for unexpected account privilege changes, new administrative sessions, and suspicious authentication attempts.

MITRE ATT&CK

  • TA0004 — Privilege Escalation: Attackers leverage these flaws to gain elevated access on SharePoint and AD FS.
  • TA0003 — Persistence: Exploited systems may be used to maintain long-term access.
  • TA0001 — Initial Access: Remote exploitation of SharePoint can provide a foothold for broader compromise.

Source: https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: