{"id":108043,"date":"2026-07-16T11:26:11","date_gmt":"2026-07-16T11:26:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/108043\/"},"modified":"2026-07-16T11:26:11","modified_gmt":"2026-07-16T11:26:11","slug":"microsoft-patches-622-cves-active-sharepoint-and-ad-fs-zero-days-demand-first-action","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/108043\/","title":{"rendered":"Microsoft Patches 622 CVEs: Active SharePoint and AD FS Zero-Days Demand First Action"},"content":{"rendered":"<p><img decoding=\"async\" loading=\"lazy\" class=\"mapping-embed imgPhoto\" id=\"i467417\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1784201171_179_microsoft.jpg\" alt=\"Microsoft\" width=\"836\" height=\"557\"\/><\/p>\n<p>The Microsoft store on Fifth Avenue in Midtown Manhattan is shown June 4, 2018 in New York City. Microsoft officially announced today an agreement to buy GitHub, a code repository company popular with software developers, for $7.5 billion in stock.<br \/>\nGetty images\/Drew Angerer<\/p>\n<p>Microsoft&#8217;s July 2026 Patch Tuesday arrived on July 14 as <a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Jul\" target=\"_blank\">the largest security update in the company&#8217;s history<\/a> \u2014 622 CVEs, more than triple June&#8217;s prior record. Buried inside that volume are two vulnerabilities that matter more than the number: one in SharePoint Server that lets an unauthenticated attacker escalate privileges over the network without touching a credential or prompting a user interaction, and one in Active Directory Federation Services that lets an attacker who already has a low-privilege foothold seize administrator control over the box that signs every identity token in the organization.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">Both bugs are being actively exploited right now<\/a>. Federal civilian agencies face a government-mandated deadline of tomorrow \u2014 July 17 \u2014 to remediate the SharePoint flaw. For the AD FS bug, the federal deadline is July 28. Security teams that have not already deployed these patches are operating inside an active threat window, not a theoretical one.<\/p>\n<p>The 622 CVEs matter \u2014 not as a number to file away, but as a structural signal about what Microsoft&#8217;s AI-powered discovery pipeline has already done to the monthly patch cadence. This is not a spike that will normalize next month. The volume is the new floor.<\/p>\n<p>SharePoint Server Patch Cannot Wait: Unauthenticated Network Exploit Is Already in Use<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-56164\" target=\"_blank\">CVE-2026-56164<\/a> is a missing-authentication vulnerability in on-premises SharePoint Server \u2014 covering SharePoint Server 2016, 2019, and the Subscription Edition \u2014 that allows an unauthenticated attacker to escalate privileges over the network. The technical class is CWE-306: Missing Authentication for Critical Function. No credentials. No user interaction. Remote.<\/p>\n<p>Microsoft assigned the bug a CVSS score of 5.3, a &#8220;Moderate&#8221; rating that has drawn unanimous industry criticism. The <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-56164\" target=\"_blank\">National Vulnerability Database independently scored it 9.8<\/a> \u2014 Critical. <a rel=\"nofollow noopener\" href=\"https:\/\/www.automox.com\/blog\/patch-fix-tuesday-july-2026\" target=\"_blank\">Automox&#8217;s July 2026 patch analysis<\/a> put the operational contradiction plainly: &#8220;Moderate severity and active exploitation are not the same thing. Don&#8217;t let the 5.3 talk you out of prioritizing it.&#8221; The disconnect is a known limitation of CVSS: the scoring system evaluates severity at a point in time and doesn&#8217;t adjust retroactively when active exploitation is later confirmed.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/14\/cisa-urges-sharepoint-hardening-after-new-exploitations\" target=\"_blank\">CISA&#8217;s advisory on the vulnerability<\/a> is more precise about the attack pattern. Attackers are chaining CVE-2026-56164 with older, previously disclosed SharePoint weaknesses to steal Internet Information Services machine keys, establish persistence on compromised servers, and deploy malware. This is the same mechanical fingerprint as the <a rel=\"nofollow noopener\" href=\"https:\/\/attack.mitre.org\/campaigns\/C0058\/\" target=\"_blank\">ToolShell campaign of July 2025<\/a> \u2014 when Chinese nation-state actors Linen Typhoon, Violet Typhoon, and ransomware actor Storm-2603 exploited SharePoint at scale across finance, healthcare, government, and energy sectors. CISA added CVE-2026-56164 to its Known Exploited Vulnerabilities catalog on July 14, the same day patches shipped, and set a remediation deadline of July 17 for all Federal Civilian Executive Branch agencies.<\/p>\n<p>Microsoft credits discovery to incident responders, including from Mandiant and Google&#8217;s FLARE team \u2014 a detail that signals the bug was found during active attacks rather than in a research environment. CISA&#8217;s recommended interim mitigation for organizations that cannot immediately patch: <a rel=\"nofollow noopener\" href=\"https:\/\/learn.microsoft.com\/en-us\/sharepoint\/security-for-sharepoint-server\/configure-amsi-integration\" target=\"_blank\">enable AMSI in Full Mode on SharePoint servers<\/a>, which causes the Antimalware Scan Interface to scan POST request bodies before SharePoint processes them, intercepting malicious payloads in-flight.<\/p>\n<p>SharePoint&#8217;s exploitation history makes this particularly acute. The ToolShell chain swept through unpatched on-premises servers in summer 2025. A separate SharePoint deserialization RCE \u2014 CVE-2026-45659 \u2014 was patched in an out-of-band release in May 2026; organizations that missed it remain exposed. Internet-facing, on-premises SharePoint installations should be treated as the first priority in this patch cycle, regardless of CVSS score.<\/p>\n<p>There is also a compounding end-of-life factor. <a rel=\"nofollow noopener\" href=\"https:\/\/learn.microsoft.com\/en-us\/lifecycle\/products\/sharepoint-server-2019\" target=\"_blank\">SharePoint Server 2016 and SharePoint Server 2019 reached end of extended support on July 14<\/a> \u2014 the exact day this patch was released. No further security updates will arrive for those versions. Organizations that cannot immediately migrate to SharePoint Server Subscription Edition are advised to remove those servers from direct internet exposure, enforce strict firewall rules, and treat the interim period as a sustained high-alert window.<\/p>\n<p>Why an AD FS &#8220;Local&#8221; Privilege Bug Deserves Immediate Treatment as a Remote Threat<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-56155\" target=\"_blank\">CVE-2026-56155<\/a> is an elevation-of-privilege vulnerability in Active Directory Federation Services, rated CVSS 7.8. Microsoft&#8217;s official description \u2014 &#8220;an authorized attacker to elevate privileges locally&#8221; \u2014 carries a modifier that can mislead. AD FS is not a typical file server or endpoint. It is the service that issues and signs the authentication tokens trusted by every application that federates to it: cloud services, SaaS platforms, on-premises applications. An attacker who reaches administrator on an AD FS host gains the ability to forge tokens and impersonate any user across every connected service, with no further authentication step required.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days\/\" target=\"_blank\">Microsoft&#8217;s own Detection and Response Team, known as DART<\/a>, gets credit for discovery \u2014 and that credit matters operationally. DART is the company&#8217;s incident-response unit, called in when real attacks are already underway. DART finding this bug means Microsoft&#8217;s responders encountered it during a live intrusion investigation. CISA added CVE-2026-56155 to the KEV catalog alongside the SharePoint bug on July 14, and set the federal remediation deadline at July 28.<\/p>\n<p>The combination ZDI notes as dangerous: CVE-2026-56155 paired with a remote code execution vulnerability makes for a ransomware delivery chain. An attacker who achieves code execution on a networked system can then pivot to an AD FS host using the access control gap, escalate to administrator, and from that position forge tokens for the entire federated estate. The blast radius extends well beyond the AD FS box.<\/p>\n<p>BitLocker Bypass (CVE-2026-50661): Real Risk, Lower Queue Position<\/p>\n<p>The third zero-day, <a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-50661\" target=\"_blank\">CVE-2026-50661<\/a>, is a protection mechanism bypass in Windows BitLocker that allows an unauthorized person with physical access to reach encrypted data stored on the device. Microsoft has not confirmed active exploitation. <a rel=\"nofollow noopener\" href=\"https:\/\/www.securityweek.com\/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-days\/\" target=\"_blank\">Tenable senior staff research engineer Satnam Narang<\/a> suggested the disclosure may connect to a researcher known as Nightmare Eclipse or Chaotic-Eclipse, though no official attribution has been made.<\/p>\n<p>Physical access is the meaningful operational constraint here. This vulnerability does not queue ahead of the two identity-infrastructure bugs for enterprise deployment. It does warrant prompt attention on laptops, shared workstations, and devices in environments with elevated physical security risk, where BitLocker is the primary protection against data exposure from theft or loss.<\/p>\n<p>What Else Warrants Elevated Attention in 622 CVEs<\/p>\n<p>Beyond the three zero-days, several vulnerabilities in this release carry characteristics that place them above routine:<\/p>\n<p>CVE-2026-55040 (SharePoint JWT Authentication Bypass): <a rel=\"nofollow noopener\" href=\"https:\/\/www.rapid7.com\/blog\/post\/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed\/\" target=\"_blank\">Rapid7 Labs disclosed this during a Pwn2Own Berlin research entry<\/a>. Rapid7 chained it to a separate, as-yet-unpatched remote code execution flaw to achieve unauthenticated RCE against a vulnerable server. The RCE component is not fixed in this release; Microsoft has scheduled the fix for August. Patching the July JWT bypass now breaks the exploit chain before an attacker can use it.<\/p>\n<p>CVE-2026-57092 (Windows VMSwitch, CVSS 9.9): The <a rel=\"nofollow noopener\" href=\"https:\/\/www.securityweek.com\/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-days\/\" target=\"_blank\">highest-scored vulnerability in the release<\/a>. Two additional SharePoint CVEs \u2014 CVE-2026-50522 and CVE-2026-58644 \u2014 score 9.8, both reachable without authentication or user interaction via deserialization of untrusted data.<\/p>\n<p>CVE-2026-50518 and CVE-2026-56159 (Windows DHCP Server, CVSS 9.8): <a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-50518\" target=\"_blank\">Buffer overflow vulnerabilities exploitable through malicious DHCP packets<\/a>. DHCP infrastructure is often overlooked during patch prioritization because it lacks the visibility of internet-facing services, but DHCP servers process traffic from every networked device.<\/p>\n<p>CVE-2026-56188 (Windows Server Network Driver, CVSS 9.8): <a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-56188\" target=\"_blank\">Unauthenticated remote code execution via network traffic<\/a>.<\/p>\n<p>CVE-2026-55008 (Exchange Server \/ OWA, CVSS 9.6): A <a rel=\"nofollow noopener\" href=\"https:\/\/www.thezdi.com\/blog\/2026\/7\/14\/the-july-2026-security-update-review\" target=\"_blank\">cross-site scripting flaw in Outlook Web Access<\/a> that ZDI recommends treating as a stored XSS despite the &#8220;spoofing&#8221; label, because the practical attack path allows persistent JavaScript execution inside authenticated OWA sessions.<\/p>\n<p>CVE-2026-56190 (Remote Desktop Protocol): An <a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-56190\" target=\"_blank\">RCE vulnerability in the RDP stack<\/a> exploitable via specially crafted network traffic. RDP servers exposed to the internet are a perennial target and a common ransomware entry vector.<\/p>\n<p>Kerberos RC4 Removal: The Change With No Security Alert and No Recovery Path<\/p>\n<p>Separate from the CVE list, but shipped as part of the July cumulative update, is a behavioral change that can produce authentication failures across enterprise environments without generating a single security alert: the permanent removal of the Kerberos RC4 rollback registry key.<\/p>\n<p>The underlying vulnerability driving this change is <a rel=\"nofollow noopener\" href=\"https:\/\/support.microsoft.com\/en-us\/topic\/how-to-manage-kerberos-kdc-usage-of-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833-1ebcda33-720a-4da8-93c1-b0496e1910dc\" target=\"_blank\">CVE-2026-20833<\/a> \u2014 an information disclosure flaw that makes Kerberos service tickets encrypted with RC4 susceptible to offline brute-force attacks through a technique called Kerberoasting. Any authenticated domain user can request a service ticket for any account with a Service Principal Name (SPN). If that ticket is encrypted with RC4, an attacker can capture it without triggering alerts, take it offline, and crack the service account&#8217;s password using commodity GPU hardware. AES-encrypted tickets do not crack like that.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/techcommunity.microsoft.com\/discussions\/microsoft-security\/kerberos-and-the-end-of-rc4-protocol-hardening-and-preparing-for-cve%E2%80%912026%E2%80%9120833\/4502262\" target=\"_blank\">Microsoft rolled out the RC4 hardening in three stages<\/a>:<\/p>\n<p>January 2026: Audit mode added event IDs 201\u2013209 in the domain controller System log, flagging every RC4-dependent authentication.April 2026: KDC moved to AES-only defaults for accounts with unset encryption type attributes. Authentication began failing for service accounts without AES key material.July 14, 2026: The RC4DefaultDisablementPhase registry key is permanently removed. Domain controllers no longer read that key. There is no rollback.<\/p>\n<p>Service accounts with RC4-only key material \u2014 those with a blank or null msDS-SupportedEncryptionTypes attribute, or explicitly set to value 4 (RC4 only) \u2014 will now fail authentication with event ID 4769 failure code 0x19 (KDC_ERR_ETYPE_NOSUPP). This will surface as: SQL Server linked-server failures, broken application pool authentication under Windows auth, WMI and PowerShell remoting errors, and Java applications with rc4-hmac specified in krb5.ini.<\/p>\n<p>The remediation sequence matters: audit DC Security Event Log for event IDs 4768 and 4769 with Ticket Encryption Type 0x17 (RC4) first, then reset passwords on flagged service accounts \u2014 which triggers AES key generation automatically \u2014 then deploy the July update. Deploying before auditing and remediation is the path to a 2 a.m. authentication outage. The change is not reversible after the update installs.<\/p>\n<p>This is not an attacker-accessible vulnerability in this release. But a missed audit step produces the same operational impact as a ransomware-induced outage \u2014 silent, widespread, and with no quick fix available.<\/p>\n<p>Why the Record Volume Is Not Going Away: What AI-Assisted Discovery Has Already Changed<\/p>\n<p>Five days before this release, <a rel=\"nofollow noopener\" href=\"https:\/\/blogs.windows.com\/windowsexperience\/2026\/07\/09\/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery\/\" target=\"_blank\">Pavan Davuluri, Microsoft&#8217;s executive vice president for Windows and Devices<\/a>, told customers directly: expect permanently elevated patch volumes. The system behind that statement is MDASH \u2014 the Microsoft Security multi-model agentic scanning harness \u2014 which <a rel=\"nofollow noopener\" href=\"https:\/\/blogs.windows.com\/windowsexperience\/2026\/07\/09\/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery\/\" target=\"_blank\">Microsoft&#8217;s Autonomous Code Security team<\/a> built and deployed in production.<\/p>\n<p>MDASH operates as a three-stage pipeline: 100+ specialized AI agents first build attack-surface models of the codebase, then specialized auditor agents debate candidate findings for exploitability, then a proving pipeline constructs proof-of-concept triggers to filter false positives before any finding reaches the engineering team. The system scored 88.45% on the public CyberGym benchmark at launch in May 2026 and reached <a rel=\"nofollow noopener\" href=\"https:\/\/blogs.windows.com\/windowsexperience\/2026\/07\/09\/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery\/\" target=\"_blank\">96.55% by Build 2026<\/a> three weeks later \u2014 a gain that reflects continuous model-panel refinement, not a fixed capability snapshot. In May, the pipeline surfaced 16 previously unknown vulnerabilities in Windows networking and authentication components on its own, including four Critical RCEs.<\/p>\n<p>Microsoft has not attributed a specific number of July&#8217;s 622 CVEs to MDASH&#8217;s pipeline. Analysts correctly note that expanded code review coverage, broader product scope, coordinated disclosure volume, and accumulated remediation backlog all contributed to the record count. But the structural implication is not softened by those other factors: MDASH is a production-grade scanner running continuously. It does not pause between patch cycles. Its discovery rate is a function of the scanning system&#8217;s capability, not of how many vulnerabilities are remaining to find. The July release is not a one-time clearing of technical debt that will be followed by a return to 150-CVE months. It is, as Davuluri&#8217;s statement implies, a preview of what the program looks like when AI-assisted discovery runs at scale.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/hackread.com\/microsoft-july-2026-patch-tuesday-fixes-zero-days\/\" target=\"_blank\">Shane Barney, chief information security officer at Keeper Security<\/a>, put the operational consequence bluntly: &#8220;Patch programs designed around a manageable monthly queue cannot process hundreds of fixes quickly without risk-based prioritization as the foundation.&#8221; Security teams whose patch SLAs were built on the assumption of 100\u2013200 CVEs per month are now operating on a structurally wrong baseline. The recalibration needed is not tactical \u2014 it is programmatic.<\/p>\n<p>What Organizations Need to Do Now<\/p>\n<p>The immediate priority is short:<\/p>\n<p>First: Patch CVE-2026-56164 on every on-premises SharePoint instance, prioritizing those with direct internet exposure. Enable AMSI in Full Mode on all SharePoint servers immediately, regardless of patch status.<\/p>\n<p>Second: Patch CVE-2026-56155 on AD FS servers. Given DART&#8217;s discovery during an active intrusion and the token-forging blast radius, treat this as equivalent urgency to the SharePoint bug.<\/p>\n<p>Third: For organizations on SharePoint Server 2016 or 2019 that cannot immediately migrate: take those servers off the internet, enforce firewall isolation, and initiate migration planning as an active remediation priority, not a roadmap item.<\/p>\n<p>Fourth: Before deploying the July cumulative update in Active Directory environments, run the RC4 audit on domain controllers \u2014 review Security event IDs 4768 and 4769 for Ticket Encryption Type 0x17. Reset passwords on any flagged service account to generate AES keys. Only then deploy the update. Discovering the audit was needed after the update is installed means discovering it during an outage.<\/p>\n<p>Fifth: Review CISA&#8217;s federal deadlines as an industry signal even if you are not a federal agency. CISA&#8217;s threshold for KEV catalog entry is confirmed real-world exploitation \u2014 not elevated risk, not theoretical concern. Both bugs meet that bar.<\/p>\n<p>Frequently Asked QuestionsWhat makes CVE-2026-56164 dangerous if Microsoft scored it only a 5.3?<\/p>\n<p>CVSS scores describe a vulnerability&#8217;s theoretical severity under standardized conditions, but they are assigned at a specific point in time and don&#8217;t automatically update when active exploitation is later confirmed. CVE-2026-56164 requires no credentials and no user interaction, allows remote network access, and is already being used in active attacks \u2014 a combination that defines operational urgency regardless of the score. <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-56164\" target=\"_blank\">The National Vulnerability Database independently assessed it at 9.8<\/a>. The National Institute of Standards and Technology&#8217;s guidance is explicit: exploit code maturity and confirmed exploitation status should override base CVSS scores in patch prioritization.<\/p>\n<p>What happens to organizations still running SharePoint Server 2016 or 2019 after July 14?<\/p>\n<p>Both versions <a rel=\"nofollow noopener\" href=\"https:\/\/learn.microsoft.com\/en-us\/lifecycle\/products\/sharepoint-server-2019\" target=\"_blank\">reached end of extended support on July 14, 2026<\/a> \u2014 the same day this patch released. The July security update is the last patch either version will receive. Future vulnerabilities discovered in those codebases will not be fixed by Microsoft. Organizations that remain on those versions without network isolation are running software with a growing, permanent gap between discovered vulnerabilities and available patches.<\/p>\n<p>What is Kerberos RC4 removal and why could it cause outages?<\/p>\n<p>Kerberos is the authentication protocol Active Directory uses to verify identities across a Windows domain. RC4 is an older, weaker encryption algorithm that has historically been used to encrypt Kerberos service tickets. Attackers can request these encrypted tickets without triggering alerts, take them offline, and crack the service account&#8217;s password using modern GPU hardware \u2014 an attack known as Kerberoasting. <a rel=\"nofollow noopener\" href=\"https:\/\/support.microsoft.com\/en-us\/topic\/how-to-manage-kerberos-kdc-usage-of-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833-1ebcda33-720a-4da8-93c1-b0496e1910dc\" target=\"_blank\">Microsoft&#8217;s July update permanently removes the registry key<\/a> that allowed administrators to roll back to RC4 behavior. Service accounts that never had AES encryption key material generated \u2014 typically those whose passwords were never reset in a modern Active Directory domain \u2014 will now fail authentication without warning. The failure is not a security breach; it is a configuration gap that the July update makes visible in the worst possible way.<\/p>\n<p>What does Microsoft&#8217;s AI vulnerability scanner mean for enterprise patch programs going forward?<\/p>\n<p>MDASH, Microsoft&#8217;s multi-model agentic scanning harness, is a production system running continuously against the Windows codebase. It does not pause between monthly cycles. The July 2026 record of 622 CVEs is not a one-time surge that will be followed by a return to lower monthly counts \u2014 it reflects the output rate of a system that runs at speed humans cannot match. Security teams whose patch capacity was sized for 100\u2013200 CVEs per month are now operating against a larger surface than their programs were designed to handle. <a rel=\"nofollow noopener\" href=\"https:\/\/blogs.windows.com\/windowsexperience\/2026\/07\/09\/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery\/\" target=\"_blank\">Risk-based prioritization<\/a> \u2014 leading with active exploitation status, internet exposure, and infrastructure criticality rather than CVE count \u2014 is no longer an operational upgrade. It is a prerequisite.<\/p>\n","protected":false},"excerpt":{"rendered":"The Microsoft store on Fifth Avenue in Midtown Manhattan is shown June 4, 2018 in New York City.&hellip;\n","protected":false},"author":2,"featured_media":98663,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[420,7829,6455,55860,313,320,7828,55859,51164,55861,3246],"class_list":["post-108043","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-azure","tag-azure-ai","tag-cisa","tag-cve-2026-56164","tag-cybersecurity","tag-microsoft","tag-microsoft-ai","tag-microsoft-patch-tuesday-july-2026","tag-patch-management","tag-sharepoint-server-zero-day","tag-windows"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/108043","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=108043"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/108043\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/98663"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=108043"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=108043"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=108043"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}