CVE-2026-56164 and CVE-2026-56155 in Microsoft SharePoint and Active Directory Patches Released Amid Active Exploitation Concerns

Published:

spot_img

On July 20, 2026, Microsoft released critical patches addressing two vulnerabilities, CVE-2026-56164 and CVE-2026-56155, affecting SharePoint Server and Active Directory Federation Services, respectively. These vulnerabilities are currently under active exploitation and could allow attackers to elevate privileges. Organizations using these products are urged to apply the patches immediately to mitigate potential risks. For further details, refer to the Check Point Research.

What the Advisory Covers

This advisory highlights the urgent need for organizations to address vulnerabilities in Microsoft products that are currently being exploited. The vulnerabilities in question could lead to unauthorized access and privilege escalation, making them particularly dangerous for enterprise environments.

Affected Products and Versions

  • Microsoft SharePoint Server: CVE-2026-56164
  • Active Directory Federation Services: CVE-2026-56155

Severity and Exploitation Status

Both vulnerabilities are under active exploitation, which means that attackers are currently leveraging these flaws to gain unauthorized access to systems. Organizations should prioritize patching these vulnerabilities to prevent potential breaches.

Available Patches or Fixed Versions

Microsoft has released patches for both vulnerabilities as part of its July Patch Tuesday updates. Organizations are encouraged to apply these patches as soon as possible to secure their systems.

Recommended Actions

  • Immediately apply the patches released by Microsoft for CVE-2026-56164 and CVE-2026-56155.
  • Review system configurations to ensure that no unauthorized access has occurred.
  • Monitor systems for any unusual activity that may indicate exploitation attempts.

Detection or Verification Guidance

Organizations should implement monitoring solutions to detect any attempts to exploit these vulnerabilities. Regular audits and security assessments can help identify any unauthorized changes or access.

In summary, the immediate application of the patches for CVE-2026-56164 and CVE-2026-56155 is crucial for organizations using Microsoft SharePoint and Active Directory Federation Services to mitigate the risks associated with these actively exploited vulnerabilities.

spot_img

Related articles

Recent articles

Project CAV3RN Expands Espionage Capabilities with Google Apps Script in Israel

Project CAV3RN, a modular espionage framework targeting entities in Israel, has recently expanded its capabilities by integrating Google Apps Script into its command and...

Red Hat releases important security update for gstreamer1-plugins-bad-free in RHEL 8.6

Red Hat has announced an important security update for the gstreamer1-plugins-bad-free package, applicable to Red Hat Enterprise Linux (RHEL) 8.6 Advanced Mission Critical Update...

Flaw in OpenAI, Anthropic, and Google APIs Allows Weaker AI Models to Decode Stronger Models’ Reasoning

A newly disclosed flaw in the APIs of OpenAI, Anthropic, and Google has raised significant security concerns, allowing researchers to recover internal reasoning and...

Cyberattacks Target North Carolina Ports and Ryde, Exposing Millions of Records

In a week marked by significant cyber incidents, the cybersecurity landscape has seen notable attacks targeting critical infrastructure and major companies. The latest Threat...