TLP:CLEAR
Microsoft July 2026 Threat & Deployment BriefActive Exploitation, Chain Cuts, End-of-Support Risks

Patch SharePoint first — exploited at 5.3, and the last fix ever for Server 2016 and 2019. Then the Windows cumulative, where an AD FS zero-day is under active attack.

Deploy first
SharePoint Server July 2026 PU
Act units
4
Hunt required
2 unit(s) — exploited pre-fix
Release
Microsoft 2026-07-14
CVEs
569–622 (by counter)
KEV read
2026-07-15
Report
ITS-EXV-2026-0715

SharePoint ships first, then the Windows package. The exploited SharePoint flaw scores 5.3 and is rated Moderate. It will sort near the bottom of a severity-ordered queue. It is unauthenticated, network-reachable, needs no user interaction, and is being exploited now.

The highest-scored flaw in the release is not why anything ships first. CVE-2026-57092 (VMSwitch, 9.9) rides the Windows package and is deployed as a passenger, not a reason.

What patching will not fix. SharePoint and AD FS were both attacked before their fixes existed. Deployment closes the door; it tells you nothing about whether someone already came through it. Two units carry a separate compromise-assessment obligation.

The deadline that is not a patch deadline. SharePoint Server 2016 and 2019 reached extended end of support on 14 July with no ESU. On those farms this is reportedly the last update they will ever receive — including the half of a known RCE chain Microsoft is due to fix in August.

The worklist

1

SharePoint Server July 2026 PU

Per-product servicing — see table
ACT · under attack
emergency change, ≤72h

Why now. CVE-2026-56164 is KEV-listed and Microsoft attests exploitation. It is unauthenticated, network-reachable and needs no user interaction — Microsoft's own advisory language is that an attacker does not require significant prior knowledge of the system and can achieve repeatable success. It scores 5.3 and is rated Moderate, which means an automated severity-ordered queue will bury it beneath dozens of Critical items you are not being attacked through. This is the severity inversion of the cycle, and it is the reason this unit ships first rather than tenth.

This unit cannot slip. Assessed to cut 2 of the identified chains — see the cut section, where this is labelled as a judgement rather than a finding.

ProductPackageCarries
SharePoint Server Subscription EditionKB5002882CVE-2026-56164, CVE-2026-55040, CVE-2026-50522
SharePoint Server 2019 (language independent)KB5002883CVE-2026-56164, CVE-2026-55040, CVE-2026-50522
SharePoint Server 2019 (language dependent)KB5002885
SharePoint Server 2016 (language independent)KB5002891CVE-2026-56164, CVE-2026-55040, CVE-2026-50522
SharePoint Server 2016 (language dependent)KB5002892
Office Online ServerKB5002884

Also inside: The same package carries CVE-2026-55040, the first half of an unauthenticated-RCE chain Rapid7 disclosed in coordination with Microsoft; the second half is embargoed and due for an August fix. It also carries the CVE-2026-50522 and CVE-2026-58644 pair, both scored 9.8 and both unauthenticated. CVE-2026-50522 was demonstrated at Pwn2Own Berlin, so a working exploit is in Microsoft's hands — but it is not public, so the PoC escalator does not fire and we have not treated it as one.

Patching is not remediation. CVE-2026-56164 was exploited before its fix existed, so deployment and compromise assessment are two obligations and this unit discharges only the first. CISA reports active exploitation of CVE-2026-56164 alongside two previously patched SharePoint flaws, with post-exploitation activity including theft of IIS machine keys and deserialization for persistence. That matters for scoping: a stolen machine key survives the patch. Review SharePoint and IIS logs for unexplained POST requests, new accounts and configuration changes predating install, and treat machine-key rotation as in scope rather than optional.

Then. Installing the Windows update does not patch a SharePoint farm. SharePoint servicing is its own path and needs its own change, its own validation, and a Configuration Wizard run. Where a farm cannot be patched immediately, Microsoft names AMSI integration with Request Body Scan set to Full as a mitigation for CVE-2026-56164 — treat that as a holding action, not the remediation. Farms at September 2025 CU level need a permissions correction first or the fixes fail to install.

The soft call in this unit

This unit ships first — an internet-facing portal under confirmed attack, unauthenticated and network-reachable. The chain-cut count below is a judgement, not a vendor-attested fact.

2

Windows client and server monthly security update

Per-product servicing — see table
ACT · under attack
emergency change, ≤72h

Why now. CVE-2026-56155 is KEV-listed and Microsoft credits its own incident-response team with finding it, which means it was found inside live attacks. AD FS is the box that signs the tokens the rest of the estate trusts, so a flaw labelled local on that host is worth more than the label suggests. The package is also the only route to five DHCP fixes, an unauthenticated RDP server RCE, and a wormable server network driver RCE — all in services that everything else in the estate depends on and none of which have a separate installer.

ProductPackageCarries
Windows Server 2025KB5099536CVE-2026-56155, CVE-2026-50661
Windows Server 2022KB5099540CVE-2026-56155, CVE-2026-50661
Windows Server 2019 / Windows 10 1809KB5099538CVE-2026-56155, CVE-2026-50661
Windows Server 2016 / Windows 10 1607KB5099535CVE-2026-56155, CVE-2026-50661
Windows Server 2012 R2 (ESU)KB5099444CVE-2026-56155
Windows Server 2012 (ESU)KB5099445CVE-2026-56155
Windows 11 25H2 / 24H2KB5101650CVE-2026-50661
Windows 11 26H1KB5101649CVE-2026-50661
Windows 11 23H2KB5099414
Windows 10 21H2 / 22H2 (ESU)KB5099539CVE-2026-50661

Also inside: CVE-2026-57092, the VMSwitch use-after-free, carries the highest CVSS in the release at 9.9 and rides this package. It is a passenger, not a reason: as a non-Tier-0 elevation of privilege it fails the impact gate and would sit at Prioritise on its own. Because it ships inside a package that is already Act, the cost of that call is close to zero — which is the honest way to describe it rather than pretending the gate caught it.

Patching is not remediation. CVE-2026-56155 was exploited before the fix existed. Microsoft has not published how. Alongside the update Microsoft is staging a hardening change to the AD FS Distributed Key Manager container ACL under KB5121391: after the July update the service enters Audit mode, checks the ACL at startup and every 24 hours, and raises Event ID 1132 where permissions need attention without changing them. Automatic remediation is planned to begin on 13 October 2026 unless opted out. Two things follow. Hunt for token-signing and DKM access predating install rather than assuming the patch closed the story. And treat Event 1132 as a finding to work now, because the audit phase is a grace period, not a fix.

Then. Two changes in this package have nothing to do with security and will generate tickets. Microsoft is blocking the Windows 11 updates on some Dell devices that shut down or lose performance after installing. And a security hardening change now enforces TDI transport registration, so applications using sockets over unregistered third-party TDI transports may stop working — that is a class of legacy networking and endpoint agent software, and it will not announce itself in advance.

The soft call in this unit

We rank this second, below SharePoint. That rests on the judgement that CVE-2026-56155 needs an attacker already on the AD FS host, while the SharePoint flaw needs nothing. If your AD FS estate is more exposed than your SharePoint estate — or if you run no on-premises SharePoint — invert ranks 1 and 2. Nothing else in the worklist moves.

3

Exchange Server Subscription Edition SU8

Per-product servicing — see table
ACT · structural
≤5 days

Why now. An attacker sends a mail. The victim opens it in OWA. JavaScript runs in their authenticated session — no attachment, no macro prompt, no click beyond reading the message. The scope-changed CVSS means it breaks out of the web app context. Under EXVORA S10.3 this is scored at the chained outcome, not at the first link's label, which is why a flaw Microsoft titles Spoofing outranks most of this month's Critical remote code execution. Microsoft rates it Exploitation More Likely and nothing yet says it is being used.

ProductPackageCarries
Exchange Server Subscription Edition RTMKB5103212CVE-2026-55008, CVE-2026-55009
Exchange Server 2019 (Period 2 ESU only, distributed privately)not establishedresolve via vendor advisory before deployment
Exchange Server 2016 (Period 2 ESU only, distributed privately)not establishedresolve via vendor advisory before deployment

Also inside: The same update ships CVE-2026-55009 and further Exchange fixes. Exchange 2016 and 2019 are out of support: only organisations enrolled in Period 2 ESU, valid May to October 2026, receive them, and Microsoft distributes those privately rather than through a public download. If you run 2016 or 2019 without Period 2 ESU, this unit has no deployable artifact for you and the mitigation lane is the only lane you have.

Then. The July update is the build Microsoft blesses for removing the CVE-2026-42897 mitigations. Do not remove them early: the Exchange Emergency Mitigation service change that stops re-applying M2.1.0 was rolling out with a stated completion of 16 July, so until it lands the service re-applies what you removed. Block M2.1.0 then remove its IIS rules, or roll back via the EOMT script if you deployed it that way.

The soft call in this unit

Act rather than Prioritise rests entirely on classifying OWA session XSS as a gate-passing impact. That class exists in the model because CVE-2026-42897 — the same shape, same product, same component — was exploited and KEV-listed on 15 May. That is one vendor-attested sighting of the capability, not two, so the EXVORA S2.3 Rule of 2 does NOT fire and we are not claiming it does. If you reject the class, this unit drops to Prioritise and a 14-day clock.

4

Dynamics 365 Business Central and Dynamics NAV on-premises

Per-product servicing — see table
ACT · structural
≤5 days

Why now. Same deserialization shape as the SharePoint pair, same 9.8, same unauthenticated and network-reachable profile — and it is easy to miss precisely because it is not SharePoint. The trigger is a crafted login request, so authentication is not a barrier: it is the attack surface. Microsoft rates it Exploitation More Likely. This unit reaches Act structurally, with no exploitation signal, which is the one call in this brief the evidence does not yet back.

ProductPackageCarries
Microsoft Dynamics 365 Business Central (on-premises) and Dynamics NAVnot establishedresolve via vendor advisory before deployment

Then. The package is not established here — resolve it against the Security Update Guide for your Business Central or NAV build before scheduling, and do not assume the Windows update reaches it. Where the on-premises server is published to the internet, the deployment order argument is over: it is a listed exposed technology with an unauthenticated 9.8.

The soft call in this unit

CVE-2026-55010 is grouped here for reporting convenience because it shares the vendor and the release, not because it shares a package or a tier — Minecraft Bedrock Dedicated Server is neither exposed technology nor core infrastructure in the frozen lists, so on its own it is Track. If it appeared in your Act queue on the strength of its 9.8, that is the queue mis-sorting, not the flaw being urgent.

The cut — why the top unit cannot slip

Confidence: moderate — analytic judgement, not vendor-attested

SharePoint Server July 2026 PU cuts 2 chains and cannot slip. CVE-2026-55040 breaks the Rapid7-disclosed pair before its remote-code-execution half exists, and CVE-2026-56164 breaks the entry link on a farm where the post-exploitation machinery is already documented.

Basis. Stage 2 composition pass. Both chains co-locate on the SharePoint farm asset class. Rapid7 states the second half of its chain is embargoed and due in August, so cutting the July link removes the chain before the other end is public. CISA states the post-exploitation activity on exploited SharePoint flaws includes IIS machine key theft and deserialization for persistence, which is what the entry link buys. No advisory attests either chain; this is inferred from architecture and disclosure timing.

What would lower this. A farm that is not reachable from an untrusted network cuts both chains before the patch does, and the leverage drops to near zero. Machine keys already stolen in an earlier compromise also survive the cut, which makes the number optimistic on an estate that skipped the April or July KEV work on CVE-2026-32201 and CVE-2026-45659. If Microsoft publishes the August RCE half early, chain A re-forms against unpatched farms and the cut has to be re-run.

Confidence: moderate — analytic judgement, not vendor-attested

On SharePoint Server 2016 and 2019 the July PU is the last chance to cut the Rapid7 chain, because those versions reportedly reached extended end of support on 14 July with no ESU and will not receive the August fix for the other half.

Basis. Rapid7 states both the end-of-support date and the August timing for the embargoed half; the two facts are separately reported but the inference that joins them is ours. If both hold, a 2016 or 2019 farm that skips this PU has no future opportunity to break the chain through servicing.

What would lower this. The end-of-support date traces to a single research source rather than to Microsoft Lifecycle, so confirm it there before acting on the finality. Microsoft has previously introduced ESU programmes for products already past their extended end date — Exchange 2016 and 2019 Period 2 is the example sitting in this very release — and were it to do the same for SharePoint, the inference collapses.

Confidence: moderate — analytic judgement, not vendor-attested

No unit in this worklist becomes conditional on another shipping. The cut is self-contained within the SharePoint farm.

Basis. The escalation links in this release — CVE-2026-56155 on AD FS and CVE-2026-57092 on a Hyper-V host — do not co-locate on the same asset class as any of this month's entry links, so no Track-tier unit is being held up by another unit's deployment. We are declining to claim a cross-estate chain the architecture does not support.

What would lower this. An estate that runs SharePoint, AD FS or Hyper-V management on shared hosts, or that lets one service account span them, collapses the asset-class separation this rests on and re-creates the cross-unit chains. A single flat administrative tier would invalidate it outright.

Confidence: moderate-high — analytic judgement, not vendor-attested

The severity inversion this month is structural, not incidental: the two flaws being exploited score 5.3 and 7.8, while the highest-scored flaw at 9.9 has no exploitation signal.

Basis. Direct comparison of vendor-attested exploitation status against the vendor's and ZDI's own scores. The scores and the KEV listings are facts; the claim that this is structural rather than a one-off is the judgement, resting on the same pattern in the model's 2026 corpus.

What would lower this. One month is one data point and the corpus behind this model is thin and selected on months where something interesting happened. If the next two cycles see the top-scored flaw exploited first, the pattern claim weakens and the structural-first ordering loses its main argument.

What is not urgent — and why

1

Microsoft Office (Click-to-Run and MSI)

Per-product servicing — see table
TRACK
normal cycle

Why now. It is not now. Office is the largest single block of Critical-rated items in this release and none of it is exposed technology or core infrastructure, so the tree never reaches the impact gate and the answer is Track on the normal cycle. ZDI flags a Preview Pane attack vector within the Office set, which is a real caveat and is called out in the caveats below as a place the model is thin.

ProductPackageCarries
Microsoft Office (July 2026 updates)KB5105810CVE-2026-50314, CVE-2026-55041

Then. Patch Office and reboot on the normal cycle. Do not let the Critical label pull it ahead of the four Act units — it is Critical because a user opening a file can lose their session, not because anyone can reach it unbidden.

Method, sources, caveats

Sources

SourceAdmiraltyUsed for
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2026-JulA1Vendor release note; primary for every Microsoft CVE in this brief
https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploiA1KEV additions of 14 July 2026: CVE-2026-15409, CVE-2026-15410, CVE-2026-56155, CVE-2026-56164
https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardeA1SharePoint exploitation and post-exploitation activity; machine key theft; KEV dates for CVE-2026-32201 and CVE-2026-45659
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202A1KEV record for the May Exchange OWA XSS; basis for the session_xss_mail_edge impact class
https://support.microsoft.com/en-us/servicing/os/windows-server/2026/07/july-1A1Windows Server 2025 package and build; TDI transport hardening change
https://support.microsoft.com/en-us/servicing/os/windows-server/2026/07/july-1A1Windows Server 2022 package and build; TDI transport hardening change
https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5103A1Exchange Server SE RTM SU8 package; CVE list
https://techcommunity.microsoft.com/blog/exchange/released-july-2026-exchange-A1Exchange servicing guidance; Period 2 ESU scope; CVE-2026-42897 mitigation rollback and EM service timing
https://blog.stefan-gossner.com/2026/07/14/sharepoint-security-fixes-released-B2SharePoint per-product package numbers and the per-version CVE applicability table; Microsoft SharePoint escalation engineering, personal blog
https://www.tenable.com/blog/microsofts-july-2026-patch-tuesday-addresses-569-B2Release counts and severity split; zero-day detail; DHCP and kernel CVE tables; Dynamics NAV detail
https://www.thezdi.com/blog/2026/7/14/the-july-2026-security-update-reviewB2Counts; full CVE table with scores; VMSwitch, Exchange OWA XSS, RDP and DHCP analysis
https://www.rapid7.com/blog/post/em-patch-tuesday-july-2026/B2Counts; the CVE-2026-55040 chain and its embargoed half; SharePoint 2016/2019 end of support; LegacyHive
https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesB2Release counts and severity split by a different methodology
https://www.bleepingcomputer.com/news/microsoft/microsoft-some-dell-devices-shB2Change-management risk: update block on some Dell devices
https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5101650-and-kb509B2Windows 11 package numbers and builds
https://www.darkreading.com/vulnerabilities-threats/records-broken-patch-tuesdB2Per-product-family counts; conflicting CVSS for CVE-2026-56155; CVE-2026-58644 as SharePoint RCE
https://www.helpnetsecurity.com/2026/07/15/microsoft-patch-tuesday-sharepoint-B2AD FS DKM ACL hardening; LegacyHive PoC; CISA SharePoint hardening context