CVE Tools
Back to feed
Exploited in the wild SharePoint Server zero-day Active Directory Federation Services Microsoft privilege-escalation

В июле Microsoft исправила рекордные 622 уязвимости в своих продуктах

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Microsoft released its July update addressing a record-breaking 622 vulnerabilities across multiple products, including three zero-days already exploited in real-world attacks. Among them, CVE-2026-56164 affects SharePoint Server and allows privilege escalation without authentication. Another exploited flaw, CVE-2026-56155, impacts Active Directory Federation Services (AD FS), enabling local privilege elevation. A third zero-day, CVE-2026-50661, bypasses BitLocker encryption but requires physical access for exploitation. Microsoft also patched high-severity issues like CVE-2026-57092 in Windows VMSwitch and CVE-2026-50522 in SharePoint. Administrators are urged to apply patches immediately due to active exploitation of some flaws.