Microsoft Windows July 2026 patches CVE-2026-56155 actively exploited
Microsoft released patches for multiple Windows and .NET vulnerabilities on 14 July 2026, including CVE-2026-56155 reported as actively exploited, enabling remote code execution, privilege escalation, and denial of service across Windows 10, 11, Server 2012-2025, and .NET versions.
ANSSI and Microsoft disclosed a significant patch batch addressing multiple vulnerabilities across Windows desktop and server platforms, as well as .NET runtimes. The bulletin explicitly notes that CVE-2026-56155 is under active exploitation, making this batch critical for organizations running any affected Windows version or .NET runtime. Affected systems span Windows 10 (versions 1607, 1809, 21H2, 22H2) across 32-bit, x64, and ARM64 architectures; Windows 11 (versions 23H2, 24H2, 25H2, 26H1); Windows Server 2012 through 2025; and .NET 8.0, 9.0, and 10.0. The vulnerabilities enable arbitrary remote code execution, privilege escalation, data integrity compromise, confidentiality breaches, and service disruption. Administrators must prioritize patching systems running actively exploited CVE-2026-56155 and apply corresponding updates to all in-scope Windows and .NET versions per Microsoft's security bulletins.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0869
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free