CVE-2026-56164 and CVE-2026-56155 in Microsoft SharePoint and Active Directory Patches Released Amid Active Exploitation Concerns

Published:

On July 20, 2026, Microsoft released critical patches addressing two vulnerabilities, CVE-2026-56164 and CVE-2026-56155, affecting SharePoint Server and Active Directory Federation Services, respectively. These vulnerabilities are currently under active exploitation and could allow attackers to elevate privileges. Organizations using these products are urged to apply the patches immediately to mitigate potential risks. For further details, refer to the Check Point Research.

What the Advisory Covers

This advisory highlights the urgent need for organizations to address vulnerabilities in Microsoft products that are currently being exploited. The vulnerabilities in question could lead to unauthorized access and privilege escalation, making them particularly dangerous for enterprise environments.

Affected Products and Versions

  • Microsoft SharePoint Server: CVE-2026-56164
  • Active Directory Federation Services: CVE-2026-56155

Severity and Exploitation Status

Both vulnerabilities are under active exploitation, which means that attackers are currently leveraging these flaws to gain unauthorized access to systems. Organizations should prioritize patching these vulnerabilities to prevent potential breaches.

Available Patches or Fixed Versions

Microsoft has released patches for both vulnerabilities as part of its July Patch Tuesday updates. Organizations are encouraged to apply these patches as soon as possible to secure their systems.

Recommended Actions

  • Immediately apply the patches released by Microsoft for CVE-2026-56164 and CVE-2026-56155.
  • Review system configurations to ensure that no unauthorized access has occurred.
  • Monitor systems for any unusual activity that may indicate exploitation attempts.

Detection or Verification Guidance

Organizations should implement monitoring solutions to detect any attempts to exploit these vulnerabilities. Regular audits and security assessments can help identify any unauthorized changes or access.

In summary, the immediate application of the patches for CVE-2026-56164 and CVE-2026-56155 is crucial for organizations using Microsoft SharePoint and Active Directory Federation Services to mitigate the risks associated with these actively exploited vulnerabilities.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

ShinyHunters resumes exploitation of Oracle PeopleSoft vulnerability, warns Mandiant

A new campaign by the hacking group ShinyHunters is exploiting a vulnerability in Oracle's PeopleSoft, as reported by Mandiant. This vulnerability, identified as CVE-2026-35273,...

CrowdStrike recognized as leader in Forrester Wave for proactive security platforms

CrowdStrike has been recognized as a Leader in The Forrester Wave: Proactive Security Platforms, Q3 2026, achieving the highest score in the Strategy category...

Microsoft tracks Storm-2570’s consistent tactics across multiple ransomware deployments

Microsoft has identified Storm-2570, a ransomware affiliate, as a significant threat actor employing consistent tactics across various ransomware deployments, including Qilin, DragonForce, Anubis, and...

Citrix NetScaler ADC and Gateway products affected by multiple critical CVEs

Citrix has disclosed multiple critical vulnerabilities affecting its NetScaler ADC and Gateway products, with at least two of these vulnerabilities, CVE-2026-88771 and CVE-2026-88772, reportedly...