VYPR
Vypr IntelligenceAI-generatedJul 14, 2026· 2 CVEs

Microsoft: 2 Actively-Exploited Flaws Added to CISA KEV

Microsoft has had two of its vulnerabilities confirmed as actively exploited in the wild and subsequently added to CISA's Known Exploited Vulnerabilities Catalog.

Key findings

  • Two Microsoft vulnerabilities, CVE-2026-56155 and CVE-2026-56164, added to CISA KEV.
  • Both CVEs are confirmed to be actively exploited in the wild by threat actors.
  • No ransomware association is currently noted for these specific Microsoft flaws.
  • Federal agencies must remediate these KEV-listed vulnerabilities by July 21, 2026.
  • All organizations should prioritize immediate patching of these critical vulnerabilities.

CISA has added two Microsoft vulnerabilities, CVE-2026-56155 and CVE-2026-56164, to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion signifies that these flaws are under active exploitation by threat actors, posing immediate and significant risks to federal agencies and other organizations. The KEV catalog serves as a critical resource for defenders, highlighting vulnerabilities that require urgent attention due to their proven exploitation in real-world attacks.

The two vulnerabilities, both from Microsoft, were added to the KEV catalog on July 14, 2026. While specific details regarding the nature of their exploitation or the products they affect have not been publicly detailed beyond their CVE IDs, their presence in the KEV catalog confirms their severity and the necessity for prompt mitigation.

  • **CVE-2026-56155**: A Microsoft vulnerability confirmed to be actively exploited.
  • **CVE-2026-56164**: Another Microsoft vulnerability, also under active exploitation by malicious actors.

There is no indication from the current CISA KEV listing that either CVE-2026-56155 or CVE-2026-56164 are currently associated with ransomware campaigns. However, any actively exploited vulnerability can serve as an initial access vector for various attack types, including ransomware deployment, data exfiltration, or further network compromise. The addition to the KEV catalog underscores the immediate threat these flaws represent, regardless of their specific exploitation methods.

Organizations, especially federal civilian executive branch (FCEB) agencies, are mandated by CISA's Binding Operational Directive (BOD) 22-01 to remediate KEV-listed vulnerabilities within specified timelines. For these newly added Microsoft flaws, the remediation due date is July 21, 2026. All organizations, regardless of their federal status, are strongly advised to prioritize patching these vulnerabilities immediately. Implementing a robust vulnerability management program that includes continuous scanning, prompt patching, and verification of remediation is crucial to defend against these and other actively exploited threats.

AI-written article. Grounded in 2 CVE records listed below.