CyberzSOC

Publication detail
← Back to advisories & guidance

Microsoft Releases July 2026 Security Updates ↗ source

July 15, 2026 JPCERT/CC Alert

Summary

Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely without authentication, etc. According to Microsoft, among the vulnerabilities, the following vulnerabilities have been confirmed to be exploited in the wild. Please refer to the latest information provided by Microsoft and implement the measures described in "II. Solution." Microsoft SharePoint Server Elevation of Privilege Vulnerability Active Directory Federation Services Elevation of Privilege Vulnerability Microsoft has updated its advisory and stated that the remote code execution vulnerability in SharePoint (CVE-2026-58644), which was addressed in this month's security updates, has been exploited in the wild. Microsoft SharePoint Remote Code Execution Vulnerability In addition, another remote code execution vulnerability (CVE-2026-50522)has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.Information believed to include a proof-of-concept (PoC) exploit for this vulnerability has been published by a security researcher. Furthermore,watchTowr has reported observing attacks using the PoC exploit against its honeypots and published information indicating that machine keys were stolen from vulnerable SharePoint Server.

News Coverage

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-50522 9.8 Critical Microsoft SharePoint Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a net…
CVE-2026-58644 9.8 Critical Microsoft SharePoint Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2026-56155 7.8 High Microsoft Active Directory Federation Services Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacke…
CVE-2026-56164 5.3 Medium Microsoft SharePoint Server Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.