HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Elevation‑of‑Privilege Flaws in Microsoft ADFS & SharePoint (CVE‑2026‑56155, CVE‑2026‑56164) Actively Exploited

Microsoft’s July 2026 Patch Tuesday fixed over 570 flaws, including two actively exploited elevation‑of‑privilege vulnerabilities in ADFS and SharePoint. Enterprises must patch immediately and capture remediation evidence to stay audit‑ready under SOC 2.

LiveThreat™ Intelligence · 📅 July 15, 2026· 📰 helpnetsecurity.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
helpnetsecurity.com

Multiple Elevation‑of‑Privilege Flaws in Microsoft ADFS & SharePoint (CVE‑2026‑56155, CVE‑2026‑56164) Threaten Enterprise Identity & Collaboration

What It Is – Microsoft’s July 2026 Patch Tuesday addressed 570+ vulnerabilities. Two of them—CVE‑2026‑56155 (Active Directory Federation Services) and CVE‑2026‑56164 (SharePoint Server)—are already being leveraged in the wild, providing attackers with elevation‑of‑privilege (EoP) paths that can be chained to remote code execution or ransomware.

Exploitability – Both flaws have public proof‑of‑concepts (Nightmare Eclipse’s “LegacyHive” for CVE‑2026‑56155 and a low‑complexity remote exploit for CVE‑2026‑56164). CVSS scores have not been published yet, but active exploitation and the ability to pivot through identity infrastructure place them in the Critical risk tier.

Affected Products – Microsoft Windows (client & server), Active Directory Federation Services (ADFS), Microsoft SharePoint Server (on‑premises).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access‑Control (CC6.1) evidence – Timely patching of identity‑infrastructure flaws is a core control; failure to remediate is a direct audit finding.
  • Continuous monitoring – Real‑time detection of exploit attempts (e.g., via SIEM or endpoint telemetry) provides the audit trail C‑suite and auditors demand.
  • Defensible due‑diligence – Documented hardening of ACLs on the AD FS Distributed Key Manager container satisfies the “change‑management” and “risk‑mitigation” criteria in a SOC 2 audit.

Recommended Actions

  • Map CVE‑2026‑56155 and CVE‑2026‑56164 to SOC 2 CC6.1 (Logical Access) and CC7.2 (System Operations) controls.
  • Deploy the July 2026 patches immediately; verify installation via automated patch‑management tools.
  • Capture patch‑deployment logs and ACL‑hardening configuration as immutable audit evidence.
  • Enable Microsoft’s Antimalware Scan Interface (AMSI) on SharePoint and monitor for anomalous privilege‑escalation alerts.
  • Incorporate a “zero‑day” watchlist into your threat‑intelligence feed to surface future ADFS/SharePoint exploits.

Source: Help Net Security – AI‑driven bug hunting fuels record Microsoft Patch Tuesday

📰 Original Source
https://www.helpnetsecurity.com/2026/07/15/microsoft-patch-tuesday-sharepoint-cve-2026-56164/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →