Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Reported exploitedActive Directory Federation Services (AD FS)SharePoint ServerOur summary
On July 14, 2026, Microsoft issued its monthly security update, addressing 622 vulnerabilities across multiple products, with 57 classified as 'critical.' Among these, two have already been exploited in the wild. The most notable include CVE-2026-56155, an elevation of privilege flaw in Active Directory Federation Services (AD FS), and CVE-2026-56164, a spoofing vulnerability in SharePoint Server. The update covers a wide range of services and applications, such as Windows DHCP Server, Microsoft Office, and Minecraft Bedrock Dedicated Server. Cisco Talos has also published new Snort rules to detect exploitation attempts.
Below is the opening; the full story is at Cisco Talos.
From Cisco Talos
Tuesday, July 14, 2026 16:27
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical".
Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.