On July 20, 2026, Microsoft released critical patches addressing two vulnerabilities, CVE-2026-56164 and CVE-2026-56155, affecting SharePoint Server and Active Directory Federation Services, respectively. These vulnerabilities are currently under active exploitation and could allow attackers to elevate privileges. Organizations using these products are urged to apply the patches immediately to mitigate potential risks. For further details, refer to the Check Point Research.
What the Advisory Covers
This advisory highlights the urgent need for organizations to address vulnerabilities in Microsoft products that are currently being exploited. The vulnerabilities in question could lead to unauthorized access and privilege escalation, making them particularly dangerous for enterprise environments.
Affected Products and Versions
- Microsoft SharePoint Server: CVE-2026-56164
- Active Directory Federation Services: CVE-2026-56155
Severity and Exploitation Status
Both vulnerabilities are under active exploitation, which means that attackers are currently leveraging these flaws to gain unauthorized access to systems. Organizations should prioritize patching these vulnerabilities to prevent potential breaches.
Available Patches or Fixed Versions
Microsoft has released patches for both vulnerabilities as part of its July Patch Tuesday updates. Organizations are encouraged to apply these patches as soon as possible to secure their systems.
Recommended Actions
- Immediately apply the patches released by Microsoft for CVE-2026-56164 and CVE-2026-56155.
- Review system configurations to ensure that no unauthorized access has occurred.
- Monitor systems for any unusual activity that may indicate exploitation attempts.
Detection or Verification Guidance
Organizations should implement monitoring solutions to detect any attempts to exploit these vulnerabilities. Regular audits and security assessments can help identify any unauthorized changes or access.
In summary, the immediate application of the patches for CVE-2026-56164 and CVE-2026-56155 is crucial for organizations using Microsoft SharePoint and Active Directory Federation Services to mitigate the risks associated with these actively exploited vulnerabilities.


