JPCERT warns of active exploitation of July 2026 Microsoft SharePoint vulnerabilities

Overview

JPCERT/CC released advisory AT260020 on 2026‑07‑15 and added an update on 2026‑07‑31. The advisory concerns the July 2026 Microsoft security update bundle, which addresses a set of high‑severity vulnerabilities in SharePoint Server and Active Directory Federation Services (ADFS).

Key vulnerabilities

  • CVE‑2026‑56164: Privilege‑escalation flaw in Microsoft SharePoint Server.
  • CVE‑2026‑56155: Privilege‑escalation flaw in Active Directory Federation Services.
  • CVE‑2026‑58644: Remote code execution (RCE) in SharePoint Server. Microsoft has confirmed that this vulnerability is being actively exploited.
  • CVE‑2026‑50522: Another SharePoint Server RCE. Listed in the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog and exploitation observed by the security researcher group watchTowr.

Exploitation evidence

Microsoft’s update guide now states that CVE‑2026‑58644 is being used in the wild. For CVE‑2026‑50522, the CISA KEV catalog includes the CVE, and watchTowr published a LinkedIn post showing proof‑of‑concept attacks that stole machine keys from SharePoint Server instances.

Recommended actions

Organizations running affected SharePoint or ADFS versions should immediately apply the July 2026 security updates via Microsoft Update Catalog or Windows Update. The advisory also notes that SharePoint Server 2019 and 2016 reached end‑of‑support on 2026‑07‑14, so migration to supported versions is strongly advised.

References