Home / The Brief / July 28, 2026
Federal IT Brief — July 28, 2026
The largest Microsoft patch cycle on record landed on the same day two of its own products stopped being supported. An on-premises SharePoint exploitation wave is running that patching alone will not close. And the Pentagon just pulled the November CMMC deadline off the calendar.
Patch, then hunt. The SharePoint campaign steals cryptographic keys that survive the patch — applying the update and moving on leaves the intruder inside.
Check your edge appliances. SonicWall, Check Point, Fortinet, and Oracle E-Business Suite all picked up actively-exploited entries on CISA’s Known Exploited Vulnerabilities catalog this month, several with three-day federal remediation clocks.
Two deadlines moved, several did not. CMMC Phase 2 is suspended. SharePoint Server 2016/2019 end-of-support, the October Windows dates, and the July Microsoft 365 price change all still stand.
1. The SharePoint wave — and why patching is only half the job
CISA issued an alert on July 14 (last revised July 16) confirming active
exploitation of four vulnerabilities in on-premises SharePoint Server —
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and
CVE-2026-58644. Every supported on-premises version is affected: Subscription
Edition, 2019, and 2016.
The detail that matters operationally is what happens after the initial compromise. Attackers are using the access to steal IIS machine keys. Those keys let an adversary forge their own authentication tokens — which means the access survives the patch. CISA's guidance is explicit and slightly counter-intuitive: hunt for machine-key harvesting activity before rotating keys, so you understand what was taken rather than destroying the evidence.
A fifth flaw, CVE-2026-50522, was added to the KEV catalog on July
22. A public proof-of-concept appeared on July 20; watchTowr's honeypots recorded
successful real-world compromises within hours of it going public. Same objective —
machine keys, forged tokens, persistence.
This is an incident-response event, not a patch cycle. If an exposed farm was reachable from the internet, credential rotation and a compromise assessment belong in the same work order as the update.
2. The end-of-support collision
SharePoint Server 2016 and 2019 reached end of extended support on July 14, 2026 — the same day Patch Tuesday shipped a fix for a zero-day being actively exploited in those very products. They received an actively-exploited zero-day fix as part of their final security update. Project Server 2016/2019, SQL Server 2016, and InfoPath 2013 went end-of-support on the same date.
There is no Extended Security Update program for SharePoint Server. An agency still running 2016 or 2019 is now operating an internet-adjacent application with no future patches, in the middle of an active exploitation campaign against it. The realistic paths are SharePoint Server Subscription Edition licensing or migration to SharePoint Online, and both are procurement actions with lead time.
3. A record patch cycle — and what the numbers actually say
Microsoft's July 14 Patch Tuesday was the largest on record, and you will see different totals depending on who counted. Malwarebytes and Security Boulevard report 622 Microsoft CVEs; Tenable counts 569 and BleepingComputer 570. The gap is methodology, not error — trackers differ on whether to include relayed upstream fixes and product entries patched earlier in the month. Roughly 59 were rated Critical.
Three zero-days were addressed. Two were under active exploitation:
CVE-2026-56155— elevation of privilege in Active Directory Federation Services, reportedly found during incident response.CVE-2026-56164— elevation of privilege in SharePoint Server (the flaw at the center of item 1).
The third, CVE-2026-50661, is a BitLocker security-feature bypass
that was publicly disclosed but not reported as exploited. It requires physical access to read
encrypted data — which puts it squarely in the lost-or-seized government laptop scenario.
An ADFS elevation-of-privilege bug is an identity-infrastructure problem, not an application one. For agencies still federating through ADFS, that is the item to schedule first.
4. WSUS stumbled during the biggest patch cycle of the year
Microsoft confirmed a Windows Server Update Services degradation — long synchronization times and sync timeouts — with impact rising from July 13, one day before Patch Tuesday. The cause was a buildup of published test detectoid metadata.
The important wrinkle: the service-side mitigation deployed July 18 only fixes newly installed or rebuilt WSUS servers. Existing installations require manual SUSDB cleanup per KB5121986. Microsoft marked the issue resolved on July 20, but an untouched existing server is not automatically healthy.
Separately, Microsoft withheld the July security update from some Dell devices after an incompatibility between an Intel driver and a new Windows USB-C Connection Manager interface, resolving it with an out-of-band update on July 18. Dell is a dominant federal endpoint OEM — those fleets sat through a cycle containing two exploited zero-days. Worth confirming they have since received it.
5. CMMC Phase 2 suspended
On July 13 the Pentagon announced the immediate suspension of Phase 2 of the Cybersecurity Maturity Model Certification program — the phase that would have required third-party (C3PAO) assessments on contracts involving sensitive but unclassified information starting November 10, 2026. Later phase milestones are frozen as well, and a CMMC Reform Task Force is running a 60-day review with a public request for information.
The stated reasoning is capacity and cost. SBA data cited by the department suggests later CMMC phases could cost small and midsize businesses more than $7 billion annually, against an assessor shortage of roughly 100 authorized C3PAOs for more than 100,000 companies needing assessment.
Suspension of the assessment requirement is not suspension of the security requirement. Phase 1 self-assessment obligations remain in force, and the underlying duty to protect covered defense information under NIST SP 800-171 is unchanged — the department says it will enforce through self-assessments and selected government-led assessments. A false self-attestation carries the same False Claims Act exposure it did in June.
6. The edge-appliance drumbeat
Four separate perimeter or business-critical products picked up actively-exploited KEV entries in two weeks. The pattern is consistent: unauthenticated, network-reachable, and aimed at devices that sit in front of everything else.
- SonicWall SMA1000 — a zero-day pair found by Rapid7 being exploited
together.
CVE-2026-15409is a server-side request forgery rated CVSS 10.0;CVE-2026-15410chains from it to root. Affects models 6210, 7210, and 8200v. Fixed in 12.4.3-03453 and 12.5.0-02835 or later. Added to KEV July 14. - Check Point SmartConsole —
CVE-2026-16232, an authentication bypass rated CVSS 9.1, exploited as a zero-day. An unauthenticated attacker can reach the management server with full administrative rights and rewrite policy across every managed gateway. KEV July 22, three-day federal deadline. - Fortinet FortiSandbox —
CVE-2026-25089andCVE-2026-39808, both CVSS 9.1 OS command injection, no credentials or user interaction required. KEV July 16. A malware-detonation appliance is designed to ingest untrusted files; compromising it blinds detection from the inside. - Oracle E-Business Suite —
CVE-2026-46817, CVSS 9.8, added to KEV July 15 with a federal remediation deadline of July 18. Three days, on a core financial system. Shadowserver documented over 1,000 internet-exposed EBS instances, more than half in the United States.
Oracle's July Critical Patch Update was itself the largest in company history — 1,449 patches across 32 product families, including ten CVSS 10.0 vulnerabilities in Fusion Middleware described as exploitable by unauthenticated attackers over HTTP.
7. Nation-state activity worth the read
Zimbra, and no click required. On July 23, CISA and 25 partner agencies
— including NSA, FBI, DCSA, DC3, and NCIS — published advisory
AA26-204A on a Russian state-supported actor tracked as LAUNDRY BEAR,
compromising Western government and commercial organizations running Zimbra Collaboration
Suite since at least July 2025. It exploits CVE-2025-66376, patched in November
2025.
The mechanism is the part to internalize: merely viewing a malicious email in a vulnerable webmail version triggers exfiltration of the previous 90 days of mail, the Global Address List, the password, 2FA tokens, and a newly created application passcode. No link click, no attachment. Security awareness training offers zero protection against this one — patching is the only control. The DCSA/DC3/NCIS co-seals point at defense-industrial-base targeting.
Routers, and it is not even a CVE. Advisory AA26-194A
(July 13) documents Russian FSB Center 16 actors compromising network devices worldwide. The
primary technique is scanning for SNMP agents that still accept default or common
community strings, then reconfiguring the device. CISA separately added
CVE-2008-4128 — a 2008 Cisco IOS flaw affecting end-of-life gear — to
the KEV catalog the same day. CISA notes substantial overlap with Salt Typhoon activity.
That last one is genuinely a procurement problem rather than a patching one. Default SNMP strings and end-of-life network hardware are fixed with a refresh and a configuration standard.
8. The lifecycle and licensing calendar
Four dates that will show up in somebody's budget:
- October 13, 2026 — Windows 11 version 24H2 Home and Pro and Windows 10 Enterprise LTSB 2016 stop receiving updates. 24H2 Enterprise and Education continue to October 12, 2027. LTSB 2016 in particular tends to live on fixed-function and OT-adjacent systems that often cannot take Windows 11 at all — that is a hardware replacement line item, not an in-place upgrade.
- July 1, 2026 — Microsoft 365 price increases took effect, with existing customers holding current pricing until renewal. Government pricing is being adjusted in line with commercial, and increases above 10% are phased over multiple years per federal regulation. Microsoft's cited government examples: Microsoft 365 G3 GCC up 8%, Office 365 G3 GCC up 13%. Standalone Teams and Copilot SKUs are excluded.
- July 4, 2026 — FedRAMP's 2026 Consolidated Rules took effect for optional early adoption, with mandatory compliance January 1, 2027 and legacy Rev5 available until June 11, 2027. The framework replaces low/moderate/high impact levels with certification classes A through D and drops the agency-sponsorship requirement. Practical consequence: "FedRAMP Authorized" language in existing solicitations and capability statements is going stale.
- Enterprise consolidation continues. The Defense Department awarded Oracle a roughly $7 billion agreement consolidating on-premises Oracle licensing across the department, the Coast Guard, and the intelligence community — five years with a five-year option, negotiated by the Navy, with projected savings of at least $441 million. It follows a comparable $9.69 billion Microsoft agreement in May.
What we would do this week
- Inventory on-premises SharePoint. If any farm was internet-reachable, treat it as a compromise assessment, not a patch. Rotate machine keys — after you have hunted, per CISA's sequencing.
- Walk the KEV list against your edge inventory. SonicWall SMA1000, Check Point management servers, FortiSandbox, Oracle EBS. The federal deadlines on several of these have already passed.
- Confirm WSUS actually recovered. An existing server needs the manual SUSDB cleanup; the July 18 service-side fix did not reach it.
- Patch Zimbra if you run it, and stop treating the risk as user-behavior dependent.
- Pull the October 13 list. Identify Windows 10 LTSB 2016 and 24H2 Home/Pro devices now — the ones that cannot take Windows 11 need hardware, and hardware needs lead time.
- Re-check your CMMC assumptions if you had budgeted a C3PAO assessment for this fiscal year, but do not let self-assessment discipline slip.
Several items above are refresh and renewal actions — end-of-support endpoints, appliance replacement, license and maintenance renewals. That is the lane we supply: IT hardware and software, OEM maintenance renewals, and communications equipment, sourced through authorized channels as an SBA-certified SDVOSB. Send a solicitation number and we will come back with a quote and sourcing confirmation.
Sources
- CISA — CISA Urges SharePoint Hardening After New Exploitations (July 14, 2026; revised July 16)
- CISA — CISA Adds Two Known Exploited Vulnerabilities to Catalog (July 22, 2026)
- CISA — CISA Adds Four Known Exploited Vulnerabilities to Catalog (July 14, 2026)
- CISA — CISA Adds Three Known Exploited Vulnerabilities to Catalog (July 16, 2026)
- CISA — AA26-204A: Russian State-Supported Actors Exploiting Zimbra Collaboration Suite (July 23, 2026)
- CISA — AA26-194A: FSB Center 16 Targeting Networking Devices (July 13, 2026)
- BleepingComputer — Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days (July 14, 2026)
- Malwarebytes — July 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days (July 2026)
- BleepingComputer — Critical SharePoint RCE flaw exploited to steal machine keys (July 21, 2026)
- BleepingComputer — CISA orders feds to patch actively exploited Oracle flaw by Saturday (July 16, 2026)
- Rapid7 — Rapid7 MDR discovers SonicWall SMA1000 zero-days being actively exploited (July 15, 2026)
- Rapid7 — CVE-2026-16232: Check Point SmartConsole authentication bypass exploited in the wild (July 2026)
- The Register — Attackers target critical FortiSandbox flaws as CISA issues patch order (July 17, 2026)
- Federal News Network — Pentagon suspends CMMC phase two requirements, launches review of program (July 13, 2026)
- Breaking Defense — Pentagon announces ‘immediate suspension’ of CMMC Phase II mandates (July 13, 2026)
- WilmerHale — Pentagon Suspends CMMC Phase 2 Requirements and Launches Review (July 20, 2026)
- Microsoft Learn — Windows release health: Windows 11 25H2 known issues (WSUS degradation; Dell update block)
- Microsoft — KB5121986: WSUS sync operations issues and timeouts (July 20, 2026)
- BleepingComputer — Windows 11 24H2 Home and Pro reach end of support in 90 days (July 16, 2026)
- Computerworld — July’s Patch Tuesday sees an end-of-support collision amidst a record-setting patch wave (July 17, 2026)
- Microsoft — Microsoft 365 packaging and pricing updates (effective July 1, 2026)
- InfoWorld — Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware (July 22, 2026)
- FedScoop — FedRAMP 20x widely available with release of 2026 Consolidated Rules (June 29, 2026)
- Orca Security — Microsoft July 2026 Patch Tuesday: SharePoint zero-day (July 15, 2026)
About this brief. Published by Lot 9 LLC, a Service-Disabled Veteran-Owned Small Business supplying IT, communications, and medical equipment to federal agencies. We summarize published reporting and add procurement context — we do not conduct original security research. Every item links to its source; verify against the primary advisory before acting. Vulnerability details and remediation deadlines change quickly, and figures cited by different trackers can legitimately differ.
Refresh, renewal, or replacement in one of these lanes?
Send the solicitation number and the requirement. You get a quote, sourcing confirmation, and any manufacturer authorization documentation the solicitation calls for.