SharePoint ships first, then the Windows package. The exploited SharePoint flaw scores 5.3 and is rated Moderate. It will sort near the bottom of a severity-ordered queue. It is unauthenticated, network-reachable, needs no user interaction, and is being exploited now.
The highest-scored flaw in the release is not why anything ships first. CVE-2026-57092 (VMSwitch, 9.9) rides the Windows package and is deployed as a passenger, not a reason.
What patching will not fix. SharePoint and AD FS were both attacked before their fixes existed. Deployment closes the door; it tells you nothing about whether someone already came through it. Two units carry a separate compromise-assessment obligation.
The deadline that is not a patch deadline. SharePoint Server 2016 and 2019 reached extended end of support on 14 July with no ESU. On those farms this is reportedly the last update they will ever receive — including the half of a known RCE chain Microsoft is due to fix in August.
Why now. CVE-2026-56164 is KEV-listed and Microsoft attests exploitation. It is unauthenticated, network-reachable and needs no user interaction — Microsoft's own advisory language is that an attacker does not require significant prior knowledge of the system and can achieve repeatable success. It scores 5.3 and is rated Moderate, which means an automated severity-ordered queue will bury it beneath dozens of Critical items you are not being attacked through. This is the severity inversion of the cycle, and it is the reason this unit ships first rather than tenth.
This unit cannot slip. Assessed to cut 2 of the identified chains — see the cut section, where this is labelled as a judgement rather than a finding.
| Product | Package | Carries |
|---|---|---|
| SharePoint Server Subscription Edition | KB5002882 | CVE-2026-56164, CVE-2026-55040, CVE-2026-50522 |
| SharePoint Server 2019 (language independent) | KB5002883 | CVE-2026-56164, CVE-2026-55040, CVE-2026-50522 |
| SharePoint Server 2019 (language dependent) | KB5002885 | — |
| SharePoint Server 2016 (language independent) | KB5002891 | CVE-2026-56164, CVE-2026-55040, CVE-2026-50522 |
| SharePoint Server 2016 (language dependent) | KB5002892 | — |
| Office Online Server | KB5002884 | — |
Also inside: The same package carries CVE-2026-55040, the first half of an unauthenticated-RCE chain Rapid7 disclosed in coordination with Microsoft; the second half is embargoed and due for an August fix. It also carries the CVE-2026-50522 and CVE-2026-58644 pair, both scored 9.8 and both unauthenticated. CVE-2026-50522 was demonstrated at Pwn2Own Berlin, so a working exploit is in Microsoft's hands — but it is not public, so the PoC escalator does not fire and we have not treated it as one.
Patching is not remediation. CVE-2026-56164 was exploited before its fix existed, so deployment and compromise assessment are two obligations and this unit discharges only the first. CISA reports active exploitation of CVE-2026-56164 alongside two previously patched SharePoint flaws, with post-exploitation activity including theft of IIS machine keys and deserialization for persistence. That matters for scoping: a stolen machine key survives the patch. Review SharePoint and IIS logs for unexplained POST requests, new accounts and configuration changes predating install, and treat machine-key rotation as in scope rather than optional.
Then. Installing the Windows update does not patch a SharePoint farm. SharePoint servicing is its own path and needs its own change, its own validation, and a Configuration Wizard run. Where a farm cannot be patched immediately, Microsoft names AMSI integration with Request Body Scan set to Full as a mitigation for CVE-2026-56164 — treat that as a holding action, not the remediation. Farms at September 2025 CU level need a permissions correction first or the fixes fail to install.
This unit ships first — an internet-facing portal under confirmed attack, unauthenticated and network-reachable. The chain-cut count below is a judgement, not a vendor-attested fact.
Why now. CVE-2026-56155 is KEV-listed and Microsoft credits its own incident-response team with finding it, which means it was found inside live attacks. AD FS is the box that signs the tokens the rest of the estate trusts, so a flaw labelled local on that host is worth more than the label suggests. The package is also the only route to five DHCP fixes, an unauthenticated RDP server RCE, and a wormable server network driver RCE — all in services that everything else in the estate depends on and none of which have a separate installer.
| Product | Package | Carries |
|---|---|---|
| Windows Server 2025 | KB5099536 | CVE-2026-56155, CVE-2026-50661 |
| Windows Server 2022 | KB5099540 | CVE-2026-56155, CVE-2026-50661 |
| Windows Server 2019 / Windows 10 1809 | KB5099538 | CVE-2026-56155, CVE-2026-50661 |
| Windows Server 2016 / Windows 10 1607 | KB5099535 | CVE-2026-56155, CVE-2026-50661 |
| Windows Server 2012 R2 (ESU) | KB5099444 | CVE-2026-56155 |
| Windows Server 2012 (ESU) | KB5099445 | CVE-2026-56155 |
| Windows 11 25H2 / 24H2 | KB5101650 | CVE-2026-50661 |
| Windows 11 26H1 | KB5101649 | CVE-2026-50661 |
| Windows 11 23H2 | KB5099414 | — |
| Windows 10 21H2 / 22H2 (ESU) | KB5099539 | CVE-2026-50661 |
Also inside: CVE-2026-57092, the VMSwitch use-after-free, carries the highest CVSS in the release at 9.9 and rides this package. It is a passenger, not a reason: as a non-Tier-0 elevation of privilege it fails the impact gate and would sit at Prioritise on its own. Because it ships inside a package that is already Act, the cost of that call is close to zero — which is the honest way to describe it rather than pretending the gate caught it.
Patching is not remediation. CVE-2026-56155 was exploited before the fix existed. Microsoft has not published how. Alongside the update Microsoft is staging a hardening change to the AD FS Distributed Key Manager container ACL under KB5121391: after the July update the service enters Audit mode, checks the ACL at startup and every 24 hours, and raises Event ID 1132 where permissions need attention without changing them. Automatic remediation is planned to begin on 13 October 2026 unless opted out. Two things follow. Hunt for token-signing and DKM access predating install rather than assuming the patch closed the story. And treat Event 1132 as a finding to work now, because the audit phase is a grace period, not a fix.
Then. Two changes in this package have nothing to do with security and will generate tickets. Microsoft is blocking the Windows 11 updates on some Dell devices that shut down or lose performance after installing. And a security hardening change now enforces TDI transport registration, so applications using sockets over unregistered third-party TDI transports may stop working — that is a class of legacy networking and endpoint agent software, and it will not announce itself in advance.
We rank this second, below SharePoint. That rests on the judgement that CVE-2026-56155 needs an attacker already on the AD FS host, while the SharePoint flaw needs nothing. If your AD FS estate is more exposed than your SharePoint estate — or if you run no on-premises SharePoint — invert ranks 1 and 2. Nothing else in the worklist moves.
Why now. An attacker sends a mail. The victim opens it in OWA. JavaScript runs in their authenticated session — no attachment, no macro prompt, no click beyond reading the message. The scope-changed CVSS means it breaks out of the web app context. Under EXVORA S10.3 this is scored at the chained outcome, not at the first link's label, which is why a flaw Microsoft titles Spoofing outranks most of this month's Critical remote code execution. Microsoft rates it Exploitation More Likely and nothing yet says it is being used.
| Product | Package | Carries |
|---|---|---|
| Exchange Server Subscription Edition RTM | KB5103212 | CVE-2026-55008, CVE-2026-55009 |
| Exchange Server 2019 (Period 2 ESU only, distributed privately) | not established | resolve via vendor advisory before deployment |
| Exchange Server 2016 (Period 2 ESU only, distributed privately) | not established | resolve via vendor advisory before deployment |
Also inside: The same update ships CVE-2026-55009 and further Exchange fixes. Exchange 2016 and 2019 are out of support: only organisations enrolled in Period 2 ESU, valid May to October 2026, receive them, and Microsoft distributes those privately rather than through a public download. If you run 2016 or 2019 without Period 2 ESU, this unit has no deployable artifact for you and the mitigation lane is the only lane you have.
Then. The July update is the build Microsoft blesses for removing the CVE-2026-42897 mitigations. Do not remove them early: the Exchange Emergency Mitigation service change that stops re-applying M2.1.0 was rolling out with a stated completion of 16 July, so until it lands the service re-applies what you removed. Block M2.1.0 then remove its IIS rules, or roll back via the EOMT script if you deployed it that way.
Act rather than Prioritise rests entirely on classifying OWA session XSS as a gate-passing impact. That class exists in the model because CVE-2026-42897 — the same shape, same product, same component — was exploited and KEV-listed on 15 May. That is one vendor-attested sighting of the capability, not two, so the EXVORA S2.3 Rule of 2 does NOT fire and we are not claiming it does. If you reject the class, this unit drops to Prioritise and a 14-day clock.
Why now. Same deserialization shape as the SharePoint pair, same 9.8, same unauthenticated and network-reachable profile — and it is easy to miss precisely because it is not SharePoint. The trigger is a crafted login request, so authentication is not a barrier: it is the attack surface. Microsoft rates it Exploitation More Likely. This unit reaches Act structurally, with no exploitation signal, which is the one call in this brief the evidence does not yet back.
| Product | Package | Carries |
|---|---|---|
| Microsoft Dynamics 365 Business Central (on-premises) and Dynamics NAV | not established | resolve via vendor advisory before deployment |
Then. The package is not established here — resolve it against the Security Update Guide for your Business Central or NAV build before scheduling, and do not assume the Windows update reaches it. Where the on-premises server is published to the internet, the deployment order argument is over: it is a listed exposed technology with an unauthenticated 9.8.
CVE-2026-55010 is grouped here for reporting convenience because it shares the vendor and the release, not because it shares a package or a tier — Minecraft Bedrock Dedicated Server is neither exposed technology nor core infrastructure in the frozen lists, so on its own it is Track. If it appeared in your Act queue on the strength of its 9.8, that is the queue mis-sorting, not the flaw being urgent.
SharePoint Server July 2026 PU cuts 2 chains and cannot slip. CVE-2026-55040 breaks the Rapid7-disclosed pair before its remote-code-execution half exists, and CVE-2026-56164 breaks the entry link on a farm where the post-exploitation machinery is already documented.
Basis. Stage 2 composition pass. Both chains co-locate on the SharePoint farm asset class. Rapid7 states the second half of its chain is embargoed and due in August, so cutting the July link removes the chain before the other end is public. CISA states the post-exploitation activity on exploited SharePoint flaws includes IIS machine key theft and deserialization for persistence, which is what the entry link buys. No advisory attests either chain; this is inferred from architecture and disclosure timing.
What would lower this. A farm that is not reachable from an untrusted network cuts both chains before the patch does, and the leverage drops to near zero. Machine keys already stolen in an earlier compromise also survive the cut, which makes the number optimistic on an estate that skipped the April or July KEV work on CVE-2026-32201 and CVE-2026-45659. If Microsoft publishes the August RCE half early, chain A re-forms against unpatched farms and the cut has to be re-run.
On SharePoint Server 2016 and 2019 the July PU is the last chance to cut the Rapid7 chain, because those versions reportedly reached extended end of support on 14 July with no ESU and will not receive the August fix for the other half.
Basis. Rapid7 states both the end-of-support date and the August timing for the embargoed half; the two facts are separately reported but the inference that joins them is ours. If both hold, a 2016 or 2019 farm that skips this PU has no future opportunity to break the chain through servicing.
What would lower this. The end-of-support date traces to a single research source rather than to Microsoft Lifecycle, so confirm it there before acting on the finality. Microsoft has previously introduced ESU programmes for products already past their extended end date — Exchange 2016 and 2019 Period 2 is the example sitting in this very release — and were it to do the same for SharePoint, the inference collapses.
No unit in this worklist becomes conditional on another shipping. The cut is self-contained within the SharePoint farm.
Basis. The escalation links in this release — CVE-2026-56155 on AD FS and CVE-2026-57092 on a Hyper-V host — do not co-locate on the same asset class as any of this month's entry links, so no Track-tier unit is being held up by another unit's deployment. We are declining to claim a cross-estate chain the architecture does not support.
What would lower this. An estate that runs SharePoint, AD FS or Hyper-V management on shared hosts, or that lets one service account span them, collapses the asset-class separation this rests on and re-creates the cross-unit chains. A single flat administrative tier would invalidate it outright.
The severity inversion this month is structural, not incidental: the two flaws being exploited score 5.3 and 7.8, while the highest-scored flaw at 9.9 has no exploitation signal.
Basis. Direct comparison of vendor-attested exploitation status against the vendor's and ZDI's own scores. The scores and the KEV listings are facts; the claim that this is structural rather than a one-off is the judgement, resting on the same pattern in the model's 2026 corpus.
What would lower this. One month is one data point and the corpus behind this model is thin and selected on months where something interesting happened. If the next two cycles see the top-scored flaw exploited first, the pattern claim weakens and the structural-first ordering loses its main argument.
Why now. It is not now. Office is the largest single block of Critical-rated items in this release and none of it is exposed technology or core infrastructure, so the tree never reaches the impact gate and the answer is Track on the normal cycle. ZDI flags a Preview Pane attack vector within the Office set, which is a real caveat and is called out in the caveats below as a place the model is thin.
| Product | Package | Carries |
|---|---|---|
| Microsoft Office (July 2026 updates) | KB5105810 | CVE-2026-50314, CVE-2026-55041 |
Then. Patch Office and reboot on the normal cycle. Do not let the Critical label pull it ahead of the four Act units — it is Critical because a user opening a file can lose their session, not because anyone can reach it unbidden.
| Source | Admiralty | Used for |
|---|---|---|
| https://msrc.microsoft.com/update-guide/en-us/releaseNote/2026-Jul | A1 | Vendor release note; primary for every Microsoft CVE in this brief |
| https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploi | A1 | KEV additions of 14 July 2026: CVE-2026-15409, CVE-2026-15410, CVE-2026-56155, CVE-2026-56164 |
| https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-harde | A1 | SharePoint exploitation and post-exploitation activity; machine key theft; KEV dates for CVE-2026-32201 and CVE-2026-45659 |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202 | A1 | KEV record for the May Exchange OWA XSS; basis for the session_xss_mail_edge impact class |
| https://support.microsoft.com/en-us/servicing/os/windows-server/2026/07/july-1 | A1 | Windows Server 2025 package and build; TDI transport hardening change |
| https://support.microsoft.com/en-us/servicing/os/windows-server/2026/07/july-1 | A1 | Windows Server 2022 package and build; TDI transport hardening change |
| https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5103 | A1 | Exchange Server SE RTM SU8 package; CVE list |
| https://techcommunity.microsoft.com/blog/exchange/released-july-2026-exchange- | A1 | Exchange servicing guidance; Period 2 ESU scope; CVE-2026-42897 mitigation rollback and EM service timing |
| https://blog.stefan-gossner.com/2026/07/14/sharepoint-security-fixes-released- | B2 | SharePoint per-product package numbers and the per-version CVE applicability table; Microsoft SharePoint escalation engineering, personal blog |
| https://www.tenable.com/blog/microsofts-july-2026-patch-tuesday-addresses-569- | B2 | Release counts and severity split; zero-day detail; DHCP and kernel CVE tables; Dynamics NAV detail |
| https://www.thezdi.com/blog/2026/7/14/the-july-2026-security-update-review | B2 | Counts; full CVE table with scores; VMSwitch, Exchange OWA XSS, RDP and DHCP analysis |
| https://www.rapid7.com/blog/post/em-patch-tuesday-july-2026/ | B2 | Counts; the CVE-2026-55040 chain and its embargoed half; SharePoint 2016/2019 end of support; LegacyHive |
| https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tues | B2 | Release counts and severity split by a different methodology |
| https://www.bleepingcomputer.com/news/microsoft/microsoft-some-dell-devices-sh | B2 | Change-management risk: update block on some Dell devices |
| https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5101650-and-kb509 | B2 | Windows 11 package numbers and builds |
| https://www.darkreading.com/vulnerabilities-threats/records-broken-patch-tuesd | B2 | Per-product-family counts; conflicting CVSS for CVE-2026-56155; CVE-2026-58644 as SharePoint RCE |
| https://www.helpnetsecurity.com/2026/07/15/microsoft-patch-tuesday-sharepoint- | B2 | AD FS DKM ACL hardening; LegacyHive PoC; CISA SharePoint hardening context |