The July Windows Server updates start hardening the AD FS DKM container ACL. CVE-2026-56155 is under active exploitation; administrators should review audit events now and test remediation before October.
AD FSActive DirectoryCVE-2026-56155Windows ServerPatch Management
With Windows security updates released in or after July 2026, Microsoft removes the audit and rollback phase for CVE-2026-20833. Domain Controllers enforce RC4 hardening; remaining RC4 dependencies can cause authentication failures.
Active DirectoryKerberosWindows ServerMicrosoftPatch Management
CVE-2026-45480 affects Azure Active Directory/Microsoft Entra ID and is rated as critical privilege escalation. Microsoft reports completed service-side mitigation; operators should still review privileged tenant changes and evidence limits.
Microsoft Entra IDAzure Active DirectoryIdentity SecurityPrivileged AccessMicrosoft
CVE-2026-42904 affects the Windows TCP/IP stack and can lead to SYSTEM privileges if exploited successfully. Windows clients and servers are in scope; patch evidence and segment boundaries should be reviewed together.
The June 2026 Windows security update includes the fix for CVE-2026-45585. Teams should now document patch level, BitLocker protectors, WinRE state, and recovery key escrow for affected Windows 11 and Windows Server 2025 systems.
The June 2026 security updates address a critical remote code execution issue in Active Directory Domain Services. Windows Server 2022 and 2025 domain controllers are in scope; teams should verify patch level, completed reboots, and DC reachability.
Active DirectoryWindows ServerDomain ControllerPatch ManagementMicrosoft
CVE-2026-48579 affects information disclosure in Exchange Online. Microsoft rates the issue highly and has mitigated it in the service; tenant teams should still verify audit logs, permissions and unusual mailbox activity.
Microsoft Exchange OnlineMicrosoft 365Mailbox AuditIdentity SecurityMicrosoft
CVE-2026-42897 affects Outlook Web Access on on-premises Exchange servers and is being exploited. Verify that Exchange Emergency Mitigation Service rule M2.1.x is active and that OWA is not used through Internet Explorer mode.
Microsoft ExchangeOWAWindows ServerPatch ManagementKEVMicrosoft
CVE-2026-41091 and CVE-2026-45498 affect Microsoft Defender and are being exploited. Explicitly verify Malware Protection Engine and Antimalware Platform versions, especially on servers, VDI, DMZ and isolated Windows systems.
Microsoft DefenderWindowsEndpoint SecurityPatch ManagementKEVMicrosoft
From June 2026 onward, older Secure Boot certificates start expiring. Without coordinated firmware/DBX updates you may see boot failures and BitLocker recovery events. Recommendation: inventory, pilot ring, verify recovery keys, define rollback.
May 2026 security updates address a critical remote code execution issue in Windows Netlogon. Priority: patch domain controllers and admin systems, restrict network paths to DCs, and tighten monitoring for auth/Netlogon anomalies.
Active DirectoryWindows ServerNetlogonPatch ManagementMicrosoft
Since the April 2026 Windows updates, RC4 is no longer treated as an implicit Kerberos default fallback when accounts have no explicit encryption type configuration. Inventory, AES readiness for service accounts, and a controlled cutover before the July phase now matter.
Active DirectoryKerberosWindows ServerAuthenticationMicrosoft
Microsoft describes a known issue where certain domain controllers in PAM environments can repeatedly restart after April updates because LSASS fails during startup. Out-of-band updates are available.
Windows ServerActive DirectoryPatch ManagementMicrosoft