CVE Tools

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

The Hacker NewsBy The Hacker News

Reported exploitedSharePoint ServerActive Directory Federation Services

Our summary

Microsoft issued its largest-ever Patch Tuesday update, addressing 622 vulnerabilities, including two zero-day flaws currently being exploited in the wild. The most urgent fixes address CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Both allow privilege escalation and are already being used by attackers. These bugs were reported by incident response teams, indicating real-world exploitation. While neither is a high-severity remote code execution flaw, their impact on core enterprise infrastructure makes them critical to patch immediately.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store