Multiple Elevation‑of‑Privilege Flaws in Microsoft ADFS & SharePoint (CVE‑2026‑56155, CVE‑2026‑56164) Threaten Enterprise Identity & Collaboration
What It Is – Microsoft’s July 2026 Patch Tuesday addressed 570+ vulnerabilities. Two of them—CVE‑2026‑56155 (Active Directory Federation Services) and CVE‑2026‑56164 (SharePoint Server)—are already being leveraged in the wild, providing attackers with elevation‑of‑privilege (EoP) paths that can be chained to remote code execution or ransomware.
Exploitability – Both flaws have public proof‑of‑concepts (Nightmare Eclipse’s “LegacyHive” for CVE‑2026‑56155 and a low‑complexity remote exploit for CVE‑2026‑56164). CVSS scores have not been published yet, but active exploitation and the ability to pivot through identity infrastructure place them in the Critical risk tier.
Affected Products – Microsoft Windows (client & server), Active Directory Federation Services (ADFS), Microsoft SharePoint Server (on‑premises).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access‑Control (CC6.1) evidence – Timely patching of identity‑infrastructure flaws is a core control; failure to remediate is a direct audit finding.
- Continuous monitoring – Real‑time detection of exploit attempts (e.g., via SIEM or endpoint telemetry) provides the audit trail C‑suite and auditors demand.
- Defensible due‑diligence – Documented hardening of ACLs on the AD FS Distributed Key Manager container satisfies the “change‑management” and “risk‑mitigation” criteria in a SOC 2 audit.
Recommended Actions
- Map CVE‑2026‑56155 and CVE‑2026‑56164 to SOC 2 CC6.1 (Logical Access) and CC7.2 (System Operations) controls.
- Deploy the July 2026 patches immediately; verify installation via automated patch‑management tools.
- Capture patch‑deployment logs and ACL‑hardening configuration as immutable audit evidence.
- Enable Microsoft’s Antimalware Scan Interface (AMSI) on SharePoint and monitor for anomalous privilege‑escalation alerts.
- Incorporate a “zero‑day” watchlist into your threat‑intelligence feed to surface future ADFS/SharePoint exploits.
Source: Help Net Security – AI‑driven bug hunting fuels record Microsoft Patch Tuesday