{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/active-directory-federation-services/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*","cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*","cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*","cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*","cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*","cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*","cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:-:*:x64:*","cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:-:*:x64:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-56155"},{"cvss":5.3,"id":"CVE-2026-56164"},{"cvss":6.1,"id":"CVE-2026-50661"},{"cvss":9.9,"id":"CVE-2026-57092"}],"_cs_exploited":true,"_cs_has_poc":true,"_cs_poc_references":[],"_cs_products":["Active Directory Federation Services","Microsoft SharePoint","Windows BitLocker","Windows User Profile Service","Microsoft Windows","Microsoft Office","Windows VMSwitch","Microsoft SharePoint Server","Microsoft Windows VMSwitch","IIS"],"_cs_severities":["critical"],"_cs_tags":["patch-tuesday","zero-day","vulnerability","microsoft","windows","sharepoint","active-directory-federation-services","bitlocker","elevation-of-privilege","security-feature-bypass"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMicrosoft released its July 2026 Patch Tuesday updates, addressing a total of 622 vulnerabilities, a significant increase from previous months. This release includes fixes for two zero-day vulnerabilities (CVE-2026-56155 and CVE-2026-56164) confirmed to be under active exploitation in the wild. CVE-2026-56155 is an Important elevation of privilege flaw in Active Directory Federation Services (AD FS) with a CVSS score of 7.8, allowing local privilege escalation without user interaction. CVE-2026-56164 is a Moderate elevation of privilege vulnerability in Microsoft SharePoint, with a CVSS score of 5.3, enabling unauthenticated remote attackers to gain privileges over the network. Additionally, one publicly disclosed but unexploited zero-day (CVE-2026-50661) affects Windows BitLocker, bypassing device encryption. CrowdStrike's Counter Adversary Operations Advanced Research Team discovered four of the patched CVEs. An unpatched privilege escalation vulnerability affecting the Windows User Profile Service was also disclosed shortly after the Patch Tuesday release, with a PoC exploit named LegacyHive, enabling potential registry-based persistence, credential theft, or security product tampering. This extensive update package underscores the critical need for prompt patching to mitigate active and potential threats.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of the actively exploited CVE-2026-56155 in Active Directory Federation Services could grant a low-privileged local attacker administrator privileges, potentially leading to full system compromise. The exploited CVE-2026-56164 in Microsoft SharePoint allows unauthenticated remote attackers to elevate privileges over a network, posing a significant risk to data integrity and system access. The publicly disclosed CVE-2026-50661, a BitLocker bypass, permits an unauthenticated attacker with physical access to gain access to encrypted data on the storage device. The unpatched Windows User Profile Service vulnerability, if exploited, could enable attackers to establish registry-based persistence, steal credentials, or tamper with security products, affecting all currently supported Windows desktop and server versions. The wide range of affected products, including Microsoft Windows, Extended Security Updates (ESU), and Microsoft Office, indicates a broad potential impact across enterprise environments, with elevation of privilege and remote code execution being the most prevalent risk types.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePatch CVE-2026-56155 and CVE-2026-56164 immediately\u003c/strong\u003e on all affected Active Directory Federation Services and Microsoft SharePoint installations, respectively, as they are actively exploited zero-days.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eApply patches for CVE-2026-50661\u003c/strong\u003e to mitigate the Windows BitLocker security feature bypass vulnerability.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eEnsure Anti-Malware Scan Interface (AMSI) is actively integrated\u003c/strong\u003e and scanning SharePoint and IIS worker process memory, with Request Body Scan mode set to Full, as a pre-patch mitigation for CVE-2026-56164.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMonitor Microsoft's official channels for an upcoming patch\u003c/strong\u003e for the unpatched privilege escalation vulnerability affecting the Windows User Profile Service.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T12:04:11Z","date_published":"2026-07-21T03:36:29Z","id":"https://feed.craftedsignal.io/briefs/2026-07-microsoft-patches-zero-days/","summary":"Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.","title":"Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday","url":"https://feed.craftedsignal.io/briefs/2026-07-microsoft-patches-zero-days/"}],"language":"en","title":"CraftedSignal Threat Feed - Active-Directory-Federation-Services","version":"https://jsonfeed.org/version/1.1"}