{"id":581,"date":"2026-07-15T14:16:58","date_gmt":"2026-07-15T05:16:58","guid":{"rendered":"https:\/\/onepress.co.kr\/index.php\/briefing\/2026-07-15-microsoft-server-zero-day-check-en\/"},"modified":"2026-07-15T14:16:58","modified_gmt":"2026-07-15T05:16:58","slug":"2026-07-15-microsoft-server-zero-day-check-en","status":"publish","type":"briefing","link":"https:\/\/onepress.co.kr\/index.php\/briefing\/2026-07-15-microsoft-server-zero-day-check-en\/","title":{"rendered":"Microsoft confirms active exploitation in SharePoint Server and AD FS. Move these patches to the front"},"content":{"rendered":"<figure class=\"wp-block-image size-large\">\n  <img decoding=\"async\" src=\"https:\/\/onepress.co.kr\/wp-content\/uploads\/2026\/07\/microsoft-server-patch-response-scene.png\" alt=\"Two IT staff check a server rack and management screens in a bright public-service computer room\" \/><figcaption>A ONEPRESS technology and public-safety image focused on verifying server updates in a real operations setting.<\/figcaption><\/figure>\n<ul>\n<li><strong>Checked:<\/strong> 2026-07-15 14:16 KST<\/li>\n<li><strong>Basis:<\/strong> Microsoft\u2019s July 14 security update data and CISA\u2019s KEV catalog updated the same day<\/li>\n<\/ul>\n<p><strong>This should not wait for the next routine maintenance window merely because one score looks moderate.<\/strong> Microsoft marked CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services (AD FS) as exploited in the wild on July 14. CISA added both to its Known Exploited Vulnerabilities catalog the same day.<\/p>\n<p>Both are privilege-escalation flaws, but their prerequisites differ. The SharePoint issue can be reached over a network by an unauthenticated attacker with low complexity and no user interaction. The AD FS issue requires an authorized low-privilege attacker with local access, but Microsoft says successful exploitation can yield administrator privileges.<\/p>\n<p><strong>Confirmed exploitation does not mean every server is compromised; it means the remediation order must change.<\/strong> Public agencies, schools, healthcare providers and businesses that host these services should handle inventory, patching, exposure reduction and evidence preservation as one task.<\/p>\n<h2>What is being exploited<\/h2>\n<ul>\n<li><strong>CVE-2026-56164:<\/strong> missing authentication for a critical SharePoint Server function. Its CVSS base score is 5.3, yet exploitation is confirmed. CISA set July 17 as the U.S. federal civilian-agency due date.<\/li>\n<li><strong>CVE-2026-56155:<\/strong> insufficiently granular AD FS access control can let an authorized local attacker reach administrator privileges. Its CVSS base score is 7.8; CISA\u2019s federal due date is July 28.<\/li>\n<li>Those dates bind U.S. federal civilian agencies, not every organization worldwide. They are still a useful urgency signal for any operator of the affected products.<\/li>\n<\/ul>\n<h2>Separate the affected environments first<\/h2>\n<ul>\n<li><strong>SharePoint:<\/strong> Microsoft lists SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition. SharePoint Online is not listed as an affected product in this advisory.<\/li>\n<li><strong>AD FS:<\/strong> Microsoft lists Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, plus some Windows 10 long-term servicing builds. Confirm whether the AD FS role or related components are actually deployed.<\/li>\n<li><strong>Personal devices:<\/strong> a household using Microsoft 365 without hosting SharePoint Server or AD FS does not install these server patches. Ask the organization that manages the work or school account.<\/li>\n<\/ul>\n<h2>Six steps for today<\/h2>\n<ol>\n<li><strong>Fix the inventory and owner:<\/strong> list every on-premises SharePoint farm and AD FS server with version, public address, exposure and responsible team or provider.<\/li>\n<li><strong>Patch SharePoint first:<\/strong> Microsoft provides KB5002891 for 2016, KB5002883 for 2019 and KB5002882 for Subscription Edition. Follow the matching official instructions, back up, install, and verify farm build and health.<\/li>\n<li><strong>Use AMSI as reinforcement:<\/strong> Microsoft recommends active AMSI integration for SharePoint and IIS worker memory with Request Body Scan set to Full. It complements rather than replaces the security update.<\/li>\n<li><strong>Update AD FS hosts:<\/strong> apply the July Windows security update that matches the server version. Microsoft flags a restart, so check redundancy, maintenance timing and rollback before proceeding.<\/li>\n<li><strong>Preserve evidence and review recent activity:<\/strong> retain IIS, SharePoint, Windows event, authentication and administrative logs. Unusual logins, privilege changes, new administrators or unexpected management activity require incident response, not only patch closure.<\/li>\n<li><strong>Validate after installation:<\/strong> test SharePoint search, upload and sign-in, plus AD FS sign-in and token issuance. Record the KB, time, owner and user-path test for every server.<\/li>\n<\/ol>\n<h2>What users and service providers should check<\/h2>\n<ul>\n<li>Employees and students do not patch this by clicking a message or resetting passwords at an unsolicited link. Use only the official portal and help desk.<\/li>\n<li>Managed-service providers should report the affected server list, installed KB, completion time, restart and service-test results\u2014not simply say that automatic updates are enabled.<\/li>\n<li>If a management interface is directly internet-facing, review VPN, access controls and allowlists separately from patching. Confirm service impact and recovery before emergency blocking.<\/li>\n<\/ul>\n<h2>How to read the alert without overstatement<\/h2>\n<ul>\n<li>Do not let the SharePoint score of 5.3 or \u201cModerate\u201d override confirmed exploitation and an unauthenticated network path.<\/li>\n<li>Microsoft\u2019s exploitation finding is not proof that a particular organization has been breached; asset and log evidence are still required.<\/li>\n<li>Do not confuse SharePoint Online with on-premises SharePoint Server or instruct cloud-only users to install a server KB.<\/li>\n<li>AMSI alone does not replace the patch, and patching alone does not rule out earlier compromise.<\/li>\n<\/ul>\n<h2>Primary sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-56164\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Security Update Guide: CVE-2026-56164 (SharePoint Server)<\/a><\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-56155\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Security Update Guide: CVE-2026-56155 (AD FS)<\/a><\/li>\n<li><a href=\"https:\/\/api.msrc.microsoft.com\/cvrf\/v3.0\/cvrf\/2026-Jul\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft July 2026 security update data (official CVRF API)<\/a><\/li>\n<li><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener noreferrer\">CISA Known Exploited Vulnerabilities Catalog<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/sharepoint\/security-for-sharepoint-server\/configure-amsi-integration\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft: Configure AMSI integration with SharePoint Server<\/a><\/li>\n<\/ul>\n<p><strong>Bottom line:<\/strong> If you run SharePoint Server or AD FS, identify the exact product now, prioritize the SharePoint update, and close the task only after AMSI, logs and user-path service tests are checked.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft confirmed active exploitation of two SharePoint Server and AD FS flaws, and CISA added both to KEV. Organizations running on-premises servers should check assets, exposure, patches and logs today.<\/p>\n","protected":false},"featured_media":0,"template":"","meta":[],"class_list":["post-581","briefing","type-briefing","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/briefing\/581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/briefing"}],"about":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/types\/briefing"}],"wp:attachment":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/media?parent=581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}