Microsoft
Vulnerabilities and patches across Windows, Exchange Server, Outlook, Active Directory, and Azure — including Patch Tuesday triage and zero-days under active exploitation.
Windows BitLocker security feature bypass
Publicly disclosed BitLocker Device Encryption bypass fixed in Microsoft's July 2026 Patch Tuesday. Requires physical access; no confirmed exploitation as of publication.
SharePoint Server JWT token authentication bypass
Critical authentication bypass in Microsoft SharePoint Server's JWT validation pipeline. Half of a pre-auth RCE chain disclosed by Rapid7; patched in the July 2026 cumulative update.
AD FS elevation of privilege — insufficient access-control granularity
Active Directory Federation Services access-control granularity flaw lets an authorized attacker escalate privileges locally. Exploited in the wild; added to CISA KEV 2026-07-14.
SharePoint Server elevation of privilege — missing authentication for critical function
SharePoint Server ships a critical function that's reachable without authentication, letting an unauthenticated attacker escalate over a network. Exploited in the wild; added to CISA KEV 2026-07-14.
Microsoft SharePoint deserialization of untrusted data (unauth RCE)
A critical unauthenticated deserialization RCE in on-prem Microsoft Office SharePoint (CVE-2026-58644, CVSS 9.8). Patched July 14 in Microsoft's July 2026 updates; added to CISA KEV on July 16.
Microsoft Defender Malware Protection Engine race-condition EoP ('RoguePlanet')
Race-condition EoP in the Microsoft Malware Protection Engine (Defender) that lets a local user reach SYSTEM. Fixed in engine build 1.1.26060.3008. Public PoC.
Microsoft SharePoint Server deserialization remote code execution
A high-severity deserialization-of-untrusted-data flaw in on-premises Microsoft SharePoint Server that leads to remote code execution. Patched by Microsoft in the May 2026 security update; added to the CISA Known Exploited Vulnerabilities catalog on July 2, 2026 after confirmed exploitation in the wild.
SharePoint Server spoofing via improper input validation
Network-reachable spoofing flaw in on-premises Microsoft SharePoint Server (Enterprise 2016, Server 2019, Subscription Edition). Patched by Microsoft in April 2026; on CISA KEV since 2026-04-14.
Microsoft Defender Antimalware Platform Local Privilege Escalation (BlueHammer)
A local privilege escalation flaw in Microsoft Defender Antimalware Platform caused by insufficient access-control granularity. An authorized local attacker can elevate privileges. Patched in April 2026 Patch Tuesday, added to the CISA KEV catalog on 2026-04-22, and confirmed by CISA in July 2026 as weaponized in ransomware attacks. Disclosed as a zero-day by researcher "Chaotic Eclipse" (aka Nightmare-Eclipse) alongside two sibling flaws — RedSun and UnDefend — as a protest of Microsoft's disclosure coordination.
Microsoft Outlook MonikerLink Remote Code Execution
A vulnerability in how Microsoft Outlook processes specially crafted hyperlinks (the "MonikerLink" flaw) allows an attacker to bypass Outlook's Protected View and trigger remote code execution simply by having a user click a malicious link in an email.
Follina — Microsoft Windows Support Diagnostic Tool Remote Code Execution
A remote-code-execution vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT) allows an attacker to execute arbitrary code when a malicious Office document is opened — triggered via a remote template reference that invokes MSDT through the ms-msdt URI scheme, without requiring macros.
MSHTML Remote Code Execution via Malicious Office Document
A remote-code-execution vulnerability in the MSHTML (Trident) browser engine component used by Microsoft Office allows an attacker to execute arbitrary code when a victim opens a specially crafted Office document — exploited in the wild as a zero-day before Microsoft's patch shipped.
PrintNightmare — Windows Print Spooler Remote Code Execution
A remote-code-execution vulnerability in the Windows Print Spooler service allows an authenticated attacker to run arbitrary code with SYSTEM privileges, or a domain-authenticated attacker to compromise a domain controller, by abusing the spooler's remote printer-driver installation functionality.
ProxyLogon — Microsoft Exchange Server Server-Side Request Forgery
A server-side request forgery vulnerability in Microsoft Exchange Server allows an unauthenticated attacker to send arbitrary HTTP requests and authenticate as the Exchange server. Chained with three additional Exchange vulnerabilities (CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) it delivers full pre-authentication remote code execution — the "ProxyLogon" chain exploited at mass scale in early 2021.

WSUS sync fix only for new installs, old servers still stuck
WSUS servers on Windows Server 2012+ have failed to sync since roughly July 13. Microsoft's July 18 mitigation restores fresh installs; older ones wait on a metadata cleanup step.

Microsoft ships KB5121767 OOB for Dell IPF driver hold
Microsoft shipped KB5121767 on 2026-07-20 to patch the Intel IPF driver incompatibility stranding a subset of Dell PCs off July's Windows 11 security update.

LegacyHive: PoC drops for unpatched Windows LPE zero-day
A researcher publishing as "Nightmare Eclipse" dropped a PoC for LegacyHive — an unpatched local privilege escalation in Windows' User Profile Service.

LegacyHive: unpatched Windows LPE zero-day, PoC public
Researcher Nightmare Eclipse dropped LegacyHive — an unpatched Windows User Profile Service LPE — hours after July Patch Tuesday. No CVE, PoC on GitHub.

Windows Server 2022 mainstream support ends Oct 13
Microsoft's Windows Server 2022 leaves mainstream support October 13, 2026 — but extended support runs five more years with security updates at no extra cost.

Windows 11 24H2 Home and Pro: 90 days to end of updates
Microsoft has set October 13, 2026 as the last patch day for Windows 11 24H2 Home and Pro. Enterprise and Education get one more year — the usual split.

CISA adds a fourth SharePoint bug to KEV in 48 hours
CVE-2026-58644 — an unauthenticated deserialization RCE, CVSS 9.8 — landed on CISA KEV this morning, two days after Microsoft shipped the SharePoint fix.

The July patch count Microsoft warned would come
Microsoft credited AI discovery for July's record 622-CVE Patch Tuesday. That's the second half of the story the MDASH post previewed a week earlier.

KB5099539 lands: Windows 10 ESU carries the July zero-days
Microsoft's KB5099539 delivers July's Patch Tuesday to Windows 10 22H2 and LTSC 2021 fleets, including two exploited zero-days. Enrollment required.

LegacyHive: Chaotic Eclipse's fourth Windows zero-day
Researcher 'Chaotic Eclipse' released LegacyHive, a Windows User Profile Service arbitrary-hive-load LPE PoC, hours after July Patch Tuesday. Unpatched.

CISA: three SharePoint bugs exploited, patch by July 17
CISA named three actively exploited on-prem SharePoint CVEs and put a July 17 remediation clock on federal agencies. Shadowserver counts 800+ unpatched servers. Patch on one maintenance touch.

Microsoft blocks Dell PCs from July KB5101650 rollout
Microsoft applied a safeguard hold on July's KB5101650 for a limited set of Dell devices running Windows 11 25H2 and 24H2 after a June preview update triggered Intel IPF driver crashes, heat, and battery drain.

Entra ID passkeys go default in Sept; SMS/voice out Feb 1
Microsoft is auto-enrolling Entra ID SMS/voice MFA users into passkeys starting September 2026 and retiring native SMS/voice delivery on Feb 1, 2027. What to do.

SharePoint JWT bypass fixed; RCE half of chain still open
Rapid7 disclosed CVE-2026-55040 today — a SharePoint JWT auth bypass patched in July Patch Tuesday. Second half of a pre-auth RCE chain lands next month. Patch now.

Microsoft July Patch Tuesday: 570 CVEs, 3 zero-days out
Microsoft's July 2026 Patch Tuesday ships 570 CVEs, including two exploited zero-days in AD FS and SharePoint plus a publicly disclosed BitLocker bypass. Patch AD FS first.

OAuth client ID spoofing sneaks past Entra sign-in logs
Proofpoint tracked two credential-stuffing crews that submit fake OAuth application IDs to Entra ID's token endpoint. The sign-in logs don't record what defenders are looking for.

ESET: 11 old signed UEFI shims still bypass Secure Boot
ESET's Martin Smolár found 11 old Microsoft-signed UEFI shims that still bypass Secure Boot — CVE-2026-8863, revoked via the June DBX update.

Microsoft's MDASH and the humans downstream of it
Microsoft says AI-found Windows bugs will make Patch Tuesdays bigger. The interesting part isn't the AI — it's the human queue that signs off on what ships.

Microsoft: MDASH will grow Patch Tuesday numbers
Microsoft EVP Pavan Davuluri says a multi-model AI scanner called MDASH will surface more Windows bugs — expect higher-volume monthly releases.

Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365
ZeroBEC flagged a new phishing-as-a-service, Forg365, bundling AiTM proxying with OAuth device-code prompts and AI lures against Microsoft 365 accounts.

Microsoft to retire OWA Light in Exchange Server
Microsoft is disabling OWA Light in an August 2026 Exchange Server update, ending a legacy client shipped when IE6 was current. Admins can disable it today.

Microsoft patches Defender 'RoguePlanet' LPE; PoC public
Microsoft shipped an out-of-band Defender engine update for RoguePlanet (CVE-2026-50656), a race-condition LPE to SYSTEM. Public PoC. Verify auto-update landed.

Pink Vishing Enrolls Rogue Entra Passkeys on M365 Tenants
Okta and Unit 42 attribute an ongoing vishing campaign — active since April — that walks Microsoft 365 users through enrolling a passkey the attacker controls.

DEBULL Kit Runs M365 Device-Code Phishing, Storm-2372
ZeroBEC reports DEBULL — a device-code phishing kit repackaging Storm-2372 tradecraft — active against M365 tenants late June to early July. Block it.

BlueHammer Defender LPE Now Used in Ransomware
CVE-2026-33825, the Microsoft Defender local privilege escalation disclosed as a zero-day by 'Chaotic Eclipse' in April, is confirmed weaponized in ransomware. Patched. Ransomware family unnamed.

SharePoint RCE now on CISA KEV: patch it this week, not next
CISA added CVE-2026-45659, a high-severity SharePoint Server deserialization RCE, to the Known Exploited Vulnerabilities catalog on July 2 after confirming active exploitation. Microsoft's May patch is your remediation.

Follina: The MSDT Bug That Skipped Macro Warnings
CVE-2022-30190 let a Word document trigger arbitrary code execution through the Windows Support Diagnostic Tool — no macros, and in some configurations no explicit click required beyond opening the file.

The MSHTML Zero-Day That Weaponized a Word Doc
CVE-2021-40444 let attackers execute arbitrary code through a malicious Office document with no macros required — exploited in the wild before Microsoft's patch existed.

ProxyLogon: Inside the Exchange Server Attack Chain
CVE-2021-26855 and three chained Exchange Server bugs gave attackers unauthenticated remote code execution — and led to a compromise event so widespread the FBI obtained a court order to remove webshells itself.

PrintNightmare: A Leaked PoC Forced an Emergency Patch
CVE-2021-34527 let attackers turn the Windows Print Spooler service — running by default on nearly every Windows machine — into a path to SYSTEM privileges or full domain compromise.

Outlook MonikerLink Bug Bypasses Protected View
CVE-2024-21413 let attackers bypass Outlook's Protected View sandbox with a single specially crafted hyperlink, leading to code execution and potential credential leakage. Patched in February 2024's Patch Tuesday.