Overview
Microsoft has released security updates addressing 570 vulnerabilities as part of the July 2026 Patch Tuesday. This includes 59 vulnerabilities marked as critical severity as well as three zero-day vulnerabilities, two of which are being actively exploited and one that was publicly disclosed before an update was available.
CVE-2026-56164 – Microsoft SharePoint Server Elevation of Privilege (CVSSv3 9.8)
An actively exploited vulnerability affecting Microsoft SharePoint Server. This vulnerability is cause by missing authentication for a critical function and could allow an unauthorised attacker to gain elevated privileges remotely over a network. No user interaction or prior authentication is required.
Affected Versions:
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
CVE-2026-56155 – Active Directory Federation Services Elevation of Privilege (CVSSv3 7.8)
An actively exploited vulnerability affecting Active Directory Federation Services (AD FS). And attacker who already has authorised local access could exploit this vulnerability to gain higher-level privileges and access sensitive information used to protect token signing and token encryption certificates.
Affected Versions: See Microsoft’s security releases below
CVE-2026-50661 – Windows BitLocker Security Feature Bypass (CVSSv3 6.1)
A publicly disclosed vulnerability affecting Windows BitLocker. And attacker with physical access to an affected device could exploit a failure in BitLocker’s protection mechanism to bypass device encryption and gain access to encrypted data stored on the system drive. Microsoft has not confirmed active exploitation of this vulnerability.
Affected Versions: See Microsoft’s security releases below
Recommended Action
Organisations are encouraged to review the appropriate security advisory pages and apply the updates:
Microsoft – Security Releases (July 2026)
If you have any concerns, or have been affected by a cyber-related issue, report it to us by submitting a Cyber Concerns Online Reporting Form.