Overview
JPCERT/CC released advisory AT260020 on 2026‑07‑15 and added an update on 2026‑07‑31. The advisory concerns the July 2026 Microsoft security update bundle, which addresses a set of high‑severity vulnerabilities in SharePoint Server and Active Directory Federation Services (ADFS).
Key vulnerabilities
- CVE‑2026‑56164: Privilege‑escalation flaw in Microsoft SharePoint Server.
- CVE‑2026‑56155: Privilege‑escalation flaw in Active Directory Federation Services.
- CVE‑2026‑58644: Remote code execution (RCE) in SharePoint Server. Microsoft has confirmed that this vulnerability is being actively exploited.
- CVE‑2026‑50522: Another SharePoint Server RCE. Listed in the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog and exploitation observed by the security researcher group watchTowr.
Exploitation evidence
Microsoft’s update guide now states that CVE‑2026‑58644 is being used in the wild. For CVE‑2026‑50522, the CISA KEV catalog includes the CVE, and watchTowr published a LinkedIn post showing proof‑of‑concept attacks that stole machine keys from SharePoint Server instances.
Recommended actions
Organizations running affected SharePoint or ADFS versions should immediately apply the July 2026 security updates via Microsoft Update Catalog or Windows Update. The advisory also notes that SharePoint Server 2019 and 2016 reached end‑of‑support on 2026‑07‑14, so migration to supported versions is strongly advised.
References
- JPCERT/CC advisory AT260020 – https://www.jpcert.or.jp/at/2026/at260020.html
- Microsoft security update blog – https://www.microsoft.com/msrc/blog/2026/07/202607-security-update
- CISA KEV catalog entry for CVE‑2026‑50522 – https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522
- watchTowr exploitation alert – LinkedIn post