CVE Tools

В июле Microsoft исправила рекордные 622 уязвимости в своих продуктах

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedSharePoint ServerActive Directory Federation Services

Our summary

Microsoft released its July update addressing a record-breaking 622 vulnerabilities across multiple products, including three zero-days already exploited in real-world attacks. Among them, CVE-2026-56164 affects SharePoint Server and allows privilege escalation without authentication. Another exploited flaw, CVE-2026-56155, impacts Active Directory Federation Services (AD FS), enabling local privilege elevation. A third zero-day, CVE-2026-50661, bypasses BitLocker encryption but requires physical access for exploitation. Microsoft also patched high-severity issues like CVE-2026-57092 in Windows VMSwitch and CVE-2026-50522 in SharePoint. Administrators are urged to apply patches immediately due to active exploitation of some flaws.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store