Actively exploited zero-days in SharePoint, AD FS and Cisco firewall management
Every organization running SharePoint Server or Cisco's firewall manager is exposed right now, before the patch is applied. Microsoft $MSFT fixed 570 flaws in July, including an actively exploited SharePoint bug that hands attackers elevated privileges, plus an AD FS access-contr
The gap between a security patch being released and being installed is exactly where attackers are working right now. Microsoft's July 2026 Patch Tuesday addressed 570 flaws, including zero-days already under active exploitation. The most consequential is CVE-2026-56164 in SharePoint Server, where a missing authentication check on a critical function lets a remote attacker elevate their privileges. A second, CVE-2026-56155, targets Active Directory Federation Services, the system many organizations use for single sign-on, through insufficient access controls. Cisco faced its own problem. The company patched CVE-2026-20316 in its Secure Firewall Management Center, a static credential issue, and confirmed it was already being exploited in July. A firewall manager is a high-value target because it sits at the center of an organization's network defenses. Microsoft also disclosed CVE-2026-50661, a flaw in Windows BitLocker, though there is no confirmed exploitation of that one so far. The practical takeaway for any organization running these systems is simple: the window to patch is not open indefinitely. Microsoft $MSFT and Cisco $CSCO have released fixes, and the attacks are already underway. Sources: BleepingComputer / The Hacker News / SecurityWeek