[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2jKHAOWFBx9msZuaczw1wRAulXt3Dvt7FVs084FV9Fw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"491f395b-01d1-425b-959d-be66b264a211","microsofts-record-622-flaw-patch-tuesday-highlights-zero-day-crisis","4cde1397-339b-4e4a-8383-e0092f629dc6","Microsoft's Record 622-Flaw Patch Tuesday Highlights Zero-Day Crisis","Microsoft's July Patch Tuesday addressed a staggering 622 vulnerabilities, including two zero-days already being actively exploited in the wild — a stark reminder that attackers often move faster than defenders. The most critical flaw, CVE-2026-56164 in SharePoint Server, allows remote, unauthenticated elevation of privilege, meaning any internet-exposed SharePoint instance is a potential entry point requiring no credentials whatsoever. CVE-2026-56155 in Active Directory Federation Services compounds the risk by targeting identity infrastructure, which, if compromised, can grant attackers broad access across an organization. The sheer volume of patches highlights the growing complexity of maintaining a secure enterprise environment and underscores why a mature, prioritized patch management program is no longer optional.","**Immediate Actions:**\n- Apply Microsoft's July Patch Tuesday updates immediately, prioritizing CVE-2026-56164 (SharePoint) and CVE-2026-56155 (ADFS) as critical, actively exploited zero-days.\n- Temporarily restrict or firewall internet-facing SharePoint Server instances until the unauthenticated RCE patch is confirmed deployed.\n- Audit all ADFS infrastructure for indicators of compromise and review recent authentication logs for anomalous privilege escalation.\n\n**Long-Term Improvements:**\n- Establish a tiered, risk-based patch management policy that mandates emergency patching SLAs (e.g., 24–48 hours) for actively exploited critical CVEs.\n- Maintain a continuously updated asset inventory covering all Microsoft workloads, including SharePoint and ADFS, to ensure no system is missed during patch cycles.\n- Implement network segmentation to isolate identity infrastructure (ADFS, Active Directory) from general corporate and internet-facing networks.\n\n**Detection Measures:**\n- Deploy endpoint detection and response (EDR) tooling with rules tuned to detect privilege escalation behaviors consistent with these zero-days.\n- Enable centralized logging for SharePoint and ADFS events and alert on unauthenticated access attempts or unexpected privilege changes.\n- Subscribe to Microsoft Security Response Center (MSRC) advisories and threat intelligence feeds to receive zero-day notifications in real time.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST AC-6: Least Privilege","NIST RA-5: Vulnerability Monitoring and Scanning","NIST SC-7: Boundary Protection","ISO\u002FIEC 27001:2022 Annex A 8.8: Management of Technical Vulnerabilities","ITIL 4: Change Enablement & Problem Management Practices","GDPR Article 32: Security of Processing (timely remediation of known vulnerabilities)","published","2026-07-14T22:20:54.265394+00:00","2026-07-14T22:20:53.889+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fmicrosoft-patches-record-622-flaws.html","microsoft-patches-record-622-flaws-including-two-zero-days-under-active-attack-404b4f","Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]