Historic Patch Tuesday with more than 600 CVE and active attacks on SharePoint and AD FS forces to prioritize for real exploitation

Author: Published 4 min de lectura 262 reading

The images in this article were generated with artificial intelligence. How we publish

Microsoft has today delivered the largest Patch Tuesday in its history: more than 600 corrections in one batch and, among them, at least two vulnerabilities that are already being exploited on the ground. This massive figure is not a minor fact: it requires a rethinking of the classic priority by CVSS score and a focus on the response where there is really active risk.

The two active operating failures are of increased privileges and affect critical infrastructure of identity and collaboration: CVE-2026-56164 in SharePoint Server on-premises and CVE-2026-56155 in Active Directory Federation Services (AD FS). Although they are not "remote code execution" of 9.8, their context makes them strategic objectives: SharePoint stores company documents and AD FS signs tokens that give cascade access to the rest of the environment. Microsoft adjudicates both to incident response teams, which usually indicates finding within real attacks, and therefore must receive priority attention.

Historic Patch Tuesday with more than 600 CVE and active attacks on SharePoint and AD FS forces to prioritize for real exploitation
Image generated with IA.

If you manage SharePoint self-hosted, This is the first update you have to deploy. Microsoft indicates that vulnerability allows an unauthenticated attacker to scale privileges remotely, without interaction and through the network; in addition today it matches the end of the extended support for SharePoint Server 2016 and 2019, without a paid ESU option, which means that servers outside the support line become particularly dangerous. While you are patching, enable AMSI in Full mode on the server reduces the operating surface and should be considered as temporary mitigation.

AD FS deserves the same urgency of attention. The CVE-2026-56155 allows an already authenticated attacker to scale privileges in the host itself by failure in access controls. Although Microsoft's label as "local," AD FS acts as tokens authority for many SSO applications, so a privilege conclusion in that box can drag commitments to the entire estate. If you cannot apply the patch immediately, restrict access to AD FS from unreliable networks, review the tokens emission telemetry and prepare a containment plan to revoke or reevaluate sessions / tokens according to risk.

There is also a third zero-day released publicly (CVE-2026-50661), a BitLocker bypass that requires physical access; it must be parched but does not have the same priority as a remote explosion. Another outstanding correction closes a JWT bypass discovered by Rapid7 (CVE-2026-55040), which Rapid7 chained to a non-patched CERs yet: Microsoft solved the bypass in July, but the CERs part is scheduled for August, so this patch breaks a major attack chain.

This Patch Tuesday also completes the hardening of Kerberos against RC4: Microsoft eliminates the RC4DefaultDisablementPhase reversion option, so after the RC4 update will only work for explicitly configured accounts. That can lead to authentication failures if the service accounts are not audited and corrected before. The correct order is to audit using the RC4 events that Microsoft introduced, rotate passwords that lack AES keys to force modern key generation, test customers and services and, only after, deploy the update. If you apply the patch without hearing, you will risk operating interruptions (and calls at midnight).

Historic Patch Tuesday with more than 600 CVE and active attacks on SharePoint and AD FS forces to prioritize for real exploitation
Image generated with IA.

Beyond the specific technical actions, there are strategic lessons for security teams: automation that helps Microsoft to discover more faults (MDASH or other agent scanning systems) also agitates attackers when they differ patches to find the underlying defect. In a scenario where 600 + CVE comes out, the "Critical" label loses the ability to prioritize. Prioritizes for evidence of actual exploitation(Microsoft brand "exploded," catalogues like that of CISA Known Exploited Vulnerables and operating probability metrics like EPSS), not just by CVSS score; and reduces the time between test and deployment for exposed assets.

If you are responsible for response and mitigation, move urgently to apply the patches in SharePoint and AD FS, enable temporary mitigation such as AMSI Full Mode in SharePoint and network restrictions in AD FS, check log and telemetry tokens and issue, and prepare credentials rotations and critical certificates. For Kerberos, perform the audit of RC4 applications, plan the rotation of service accounts and program the update in controlled maintenance windows. And in the meantime, it monitors public catalogues and notices: check out the Microsoft update guide in Microsoft Security Update Guide and collates the list of exploited vulnerabilities known by CISA in CISA Known Exploited Vulnerabilities Catalog.

The conclusion is clear: with the current scale of findings and the speed of operation after the patch is published, the policies of "waiting a week" to update are no longer safe. It adapts your priority to evidence of use in attacks, accelerates deployments where there are operating flags and prepares operational contingencies for changes that can break legitimate authentication.

Coverage

Related

More news on the same subject.