# Microsoft Patches Two Actively Exploited Flaws

Published: 2026-07-14 · Severity: high
Canonical: https://vorant.io/reports/dbfc71bd-ff36-5bf6-9d1e-caccc5fb3c0b/microsoft-patches-two-actively-exploited-flaws

> IPA warns two Microsoft vulnerabilities in the July 2026 patch Tuesday are being actively exploited and urges immediate patching.

Japan's IPA issued its monthly advisory following Microsoft's July 15, 2026 security update release, highlighting that two of the disclosed vulnerabilities, CVE-2026-56155 and CVE-2026-56164, have been confirmed by Microsoft as actively exploited in the wild. The broader patch batch addresses multiple issues that could cause application crashes or allow an attacker to gain control of an affected system.

IPA is urging both individual users and organizations to apply the security updates as soon as possible via Windows Update or centralized patch management, noting that a system restart may be required. No specific threat actor, malware family, or technical exploitation details were disclosed in the advisory; the notice functions as a patch-now alert rather than a detailed technical writeup.

## Mentioned in this report

- Vulnerabilities: CVE-2026-56155 (KEV), CVE-2026-56164 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/0715-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/dbfc71bd-ff36-5bf6-9d1e-caccc5fb3c0b/microsoft-patches-two-actively-exploited-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
