Microsoft has released an updated security advisory on the 17th of July 2026 in line with their regular monthly patch schedule which includes a number of updates to address vulnerabilities in one (1) extremely high risk and twelve (12) medium risk products.
These updates address vulnerabilities which may impact services through Remote Code Execution, Denial of Service, Elevation of Privilege, Security Restriction Bypass, Information Disclosure, Data Manipulation, and Spoofing.
For more information please see: Microsoft Security Update
This release consists of security updates for the following products:
- Azure
- Defender
- Developer Tools
- Exchange Server
- Microsoft Edge
- Office
- Office 2016
- Other
- SharePoint Server
- SQL Server
- Windows
CVE-2026-56155 is being exploited and insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorised attacker to elevate privileges locally.
CVE-2026-56164 is being exploited and missing authentication for critical functions in Microsoft Office SharePoint allows an unauthorised attacker to elevate privileges over a network.
CVE-2026-58644 is being exploited and Microsoft SharePoint contains a deserialisation of untrusted data vulnerability that allows an unauthorised attacker to execute code over a network.