Two actively exploited Microsoft zero-days added to CISA must-patch list
US federal agencies have until July 28 to patch two actively exploited zero-days in Microsoft $MSFT products, per CISA's Known Exploited Vulnerabilities catalog. CVE-2026-56155 hits Active Directory Federation Services; CVE-2026-56164 hits on-prem SharePoint Server only.
US federal civilian agencies have until July 28 to patch two actively exploited zero-day vulnerabilities in Microsoft products, according to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, which added both flaws on July 14. CVE-2026-56155 affects Active Directory Federation Services, an identity infrastructure component used to manage logins across an organization. It allows a local attacker to gain administrator privileges due to insufficient access control granularity. CVE-2026-56164 affects on-premises Microsoft $MSFT SharePoint Server, not the cloud-hosted SharePoint Online. It is a missing-authentication flaw that lets an unauthenticated attacker elevate privileges over the network without needing valid credentials first. Microsoft's own Detection and Response Team found it during active incident response, confirming the flaw was already being exploited before a patch existed. Because the SharePoint flaw is specific to on-premises deployments, organizations running only the cloud version of SharePoint are not exposed to this particular bug. Organizations running on-premises servers, however, are advised to treat this as an immediate priority given the confirmed active exploitation.