JPCERT-AT-2026-0020
JPCERT/CC
2026-07-15(Initial)
2026-07-31(Update)
Microsoft Corporation
July 2026 Security Updates
https://msrc.microsoft.com/update-guide/en-US/releaseNote/2026-Jul
According to Microsoft, among the vulnerabilities, the following vulnerabilities have been confirmed to be exploited in the wild. Please refer to the latest information provided by Microsoft and implement the measures described in "II. Solution."
CVE-2026-56164
Microsoft SharePoint Server Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56164
CVE-2026-56155
Active Directory Federation Services Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155
Microsoft Update Catalog
https://www.catalog.update.microsoft.com/
Windows Update: FAQ
https://support.microsoft.com/en-us/help/12373/windows-update-faq
Microsoft Corporation
Release Notes
https://msrc.microsoft.com/update-guide/
If you have any information regarding this alert, please contact JPCERT/CC.
2026-07-31 Updated "I. Overview" and "III. References"
2026-07-31 Updated information about exploit status of CVE-2026-50522
JPCERT Coordination Center (Cyber Security Coordination Group)
MAIL: ew-info@jpcert.or.jp
https://www.jpcert.or.jp/english/
JPCERT/CC
2026-07-15(Initial)
2026-07-31(Update)
I. Overview
Microsoft has released July 2026 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely without authentication, etc.Microsoft Corporation
July 2026 Security Updates
https://msrc.microsoft.com/update-guide/en-US/releaseNote/2026-Jul
According to Microsoft, among the vulnerabilities, the following vulnerabilities have been confirmed to be exploited in the wild. Please refer to the latest information provided by Microsoft and implement the measures described in "II. Solution."
CVE-2026-56164
Microsoft SharePoint Server Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56164
CVE-2026-56155
Active Directory Federation Services Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-56155
Update: July 31, 2026 Update
Microsoft has updated its advisory and stated that the remote code execution vulnerability in SharePoint (CVE-2026-58644), which was addressed in this month's security updates, has been exploited in the wild.
CVE-2026-58644
Microsoft SharePoint Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
In addition, another remote code execution vulnerability (CVE-2026-50522)has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.Information believed to include a proof-of-concept (PoC) exploit for this vulnerability has been published by a security researcher. Furthermore,watchTowr has reported observing attacks using the PoC exploit against its honeypots and published information indicating that machine keys were stolen from vulnerable SharePoint Server.
CVE-2026-50522
Microsoft SharePoint Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522
watchTowr
CVE-2026-50522 Exploitation Alert: SharePoint On-Premise Vulnerability
https://www.linkedin.com/posts/watchtowr_exploitation-alert-watchtowr-is-observing-activity-7485278595850940416-LSP8/
CISA
Known Exploited Vulnerabilities Catalog CVE-2026-50522
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522
As information regarding the exploitation of these vulnerabilities has been made publicly available, organizations using SharePoint Server are strongly advised to promptly apply the necessary mitigations and investigate their systems.
CVE-2026-58644
Microsoft SharePoint Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
In addition, another remote code execution vulnerability (CVE-2026-50522)has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.Information believed to include a proof-of-concept (PoC) exploit for this vulnerability has been published by a security researcher. Furthermore,watchTowr has reported observing attacks using the PoC exploit against its honeypots and published information indicating that machine keys were stolen from vulnerable SharePoint Server.
CVE-2026-50522
Microsoft SharePoint Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522
watchTowr
CVE-2026-50522 Exploitation Alert: SharePoint On-Premise Vulnerability
https://www.linkedin.com/posts/watchtowr_exploitation-alert-watchtowr-is-observing-activity-7485278595850940416-LSP8/
CISA
Known Exploited Vulnerabilities Catalog CVE-2026-50522
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522
As information regarding the exploitation of these vulnerabilities has been made publicly available, organizations using SharePoint Server are strongly advised to promptly apply the necessary mitigations and investigate their systems.
II. Solution
Please apply the security update programs through Microsoft Update, Windows Update, etc.Microsoft Update Catalog
https://www.catalog.update.microsoft.com/
Windows Update: FAQ
https://support.microsoft.com/en-us/help/12373/windows-update-faq
III. References
Microsoft Corporation
Release Notes
https://msrc.microsoft.com/update-guide/
Update: July 31, 2026 Update
Support for SharePoint Server 2019 and SharePoint Server 2016 ended on July 14, 2026. Users are encouraged to migrate to supported versions of the product.
SharePoint Server 2019
https://learn.microsoft.com/lifecycle/products/sharepoint-server-2019
SharePoint Server 2016
https://learn.microsoft.com/lifecycle/products/sharepoint-server-2016
SharePoint Server 2019
https://learn.microsoft.com/lifecycle/products/sharepoint-server-2019
SharePoint Server 2016
https://learn.microsoft.com/lifecycle/products/sharepoint-server-2016
If you have any information regarding this alert, please contact JPCERT/CC.
Revision History
2026-07-15 First edition2026-07-31 Updated "I. Overview" and "III. References"
2026-07-31 Updated information about exploit status of CVE-2026-50522
JPCERT Coordination Center (Cyber Security Coordination Group)
MAIL: ew-info@jpcert.or.jp
https://www.jpcert.or.jp/english/
