<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Microsoft SharePoint - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/microsoft-sharepoint/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 21 Jul 2026 03:36:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/microsoft-sharepoint/feed.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday</title><link>https://feed.craftedsignal.io/briefs/2026-07-microsoft-patches-zero-days/</link><pubDate>Tue, 21 Jul 2026 03:36:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-microsoft-patches-zero-days/</guid><description>Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.</description><content:encoded><![CDATA[<p>Microsoft released its July 2026 Patch Tuesday updates, addressing a total of 622 vulnerabilities, a significant increase from previous months. This release includes fixes for two zero-day vulnerabilities (CVE-2026-56155 and CVE-2026-56164) confirmed to be under active exploitation in the wild. CVE-2026-56155 is an Important elevation of privilege flaw in Active Directory Federation Services (AD FS) with a CVSS score of 7.8, allowing local privilege escalation without user interaction. CVE-2026-56164 is a Moderate elevation of privilege vulnerability in Microsoft SharePoint, with a CVSS score of 5.3, enabling unauthenticated remote attackers to gain privileges over the network. Additionally, one publicly disclosed but unexploited zero-day (CVE-2026-50661) affects Windows BitLocker, bypassing device encryption. CrowdStrike's Counter Adversary Operations Advanced Research Team discovered four of the patched CVEs. An unpatched privilege escalation vulnerability affecting the Windows User Profile Service was also disclosed shortly after the Patch Tuesday release, with a PoC exploit named LegacyHive, enabling potential registry-based persistence, credential theft, or security product tampering. This extensive update package underscores the critical need for prompt patching to mitigate active and potential threats.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of the actively exploited CVE-2026-56155 in Active Directory Federation Services could grant a low-privileged local attacker administrator privileges, potentially leading to full system compromise. The exploited CVE-2026-56164 in Microsoft SharePoint allows unauthenticated remote attackers to elevate privileges over a network, posing a significant risk to data integrity and system access. The publicly disclosed CVE-2026-50661, a BitLocker bypass, permits an unauthenticated attacker with physical access to gain access to encrypted data on the storage device. The unpatched Windows User Profile Service vulnerability, if exploited, could enable attackers to establish registry-based persistence, steal credentials, or tamper with security products, affecting all currently supported Windows desktop and server versions. The wide range of affected products, including Microsoft Windows, Extended Security Updates (ESU), and Microsoft Office, indicates a broad potential impact across enterprise environments, with elevation of privilege and remote code execution being the most prevalent risk types.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li><strong>Patch CVE-2026-56155 and CVE-2026-56164 immediately</strong> on all affected Active Directory Federation Services and Microsoft SharePoint installations, respectively, as they are actively exploited zero-days.</li>
<li><strong>Apply patches for CVE-2026-50661</strong> to mitigate the Windows BitLocker security feature bypass vulnerability.</li>
<li><strong>Ensure Anti-Malware Scan Interface (AMSI) is actively integrated</strong> and scanning SharePoint and IIS worker process memory, with Request Body Scan mode set to Full, as a pre-patch mitigation for CVE-2026-56164.</li>
<li><strong>Monitor Microsoft's official channels for an upcoming patch</strong> for the unpatched privilege escalation vulnerability affecting the Windows User Profile Service.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>patch-tuesday</category><category>zero-day</category><category>vulnerability</category><category>microsoft</category><category>windows</category><category>sharepoint</category><category>active-directory-federation-services</category><category>bitlocker</category><category>elevation-of-privilege</category><category>security-feature-bypass</category></item></channel></rss>