Skip to content
CC-4814

CC-4814

Digital.Nhs.Uk [email protected] (NHS Digital) July 15, 2026

Multiple other Microsoft platforms. Please see Microsoft's July 2026 Security Updates guide for full details.

Exploitation of CVE-2026-56164 and CVE-2026-56155

Microsoft states that exploitation of CVE-2026-56164 and CVE-2026-56155 has been detected. NHS England National CSOC assess that future exploitation is highly likely.

Microsoft has released security updates to address 622 vulnerabilities in Microsoft products, including the 4 vulnerabilities highlighted below.

SharePoint Server 2016 and 2019 are no longer supported

As of 14 July 2026, Microsoft's extended support for SharePoint Server 2016 and SharePoint Server 2019 has come to an end, therefore these products are now unsupported by Microsoft. Organisations are encouraged to switch to a supported version.

Affected organisations are encouraged to review Microsoft's July 2026 Security Updates and apply the relevant updates as soon as possible.

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Last edited: 15 July 2026 1:15 pm