Mastodon Mastodon Mastodon Mastodon

CVE-2026-56155: AD FS privilege escalation vulnerability is already being exploited

Photo of author

CyberSecureFox Editorial Team

Published:

Microsoft has flagged the CVE-2026-56155 vulnerability in Active Directory Federation Services (AD FS) as actively exploited. The issue is related to insufficient granularity of access control and allows an authenticated attacker to perform local privilege escalation. The vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog with a remediation deadline of July 28, 2026 — this deadline has already passed. Organizations using AD FS must immediately check the status of patch deployment and apply available updates.

Technical details of the vulnerability

According to the Microsoft advisory, the root cause of CVE-2026-56155 is insufficient granularity of access control in the AD FS component. This means that the authorization mechanism in the federation service does not provide sufficiently fine-grained separation of privileges, opening a path to privilege escalation.

Key characteristics of the documented attack vector:

  • Precondition: the attacker must be authenticated in the system — the vulnerability does not allow unauthenticated exploitation
  • Impact type: local privilege escalation
  • Exploitation status: Microsoft notes “Exploited: Yes” and “Exploitation Detected” for current software versions
  • Public disclosure: at the time the advisory was published — no (Publicly Disclosed: No)

The NVD entry for this CVE is available, but the CVSS score, specific affected Windows Server versions, and the number of the fixing update are not provided in the available data. This is important to keep in mind when planning: administrators should consult the Microsoft Security Update Guide portal directly for the full list of affected platforms and corresponding KB updates.

Remediation priority assessment

The combination of two factors makes this vulnerability a priority for immediate response. First, Microsoft confirms that it is being exploited in real-world attacks. Second, CISA added CVE-2026-56155 to the KEV catalog on July 14, 2026 with a remediation deadline of July 28, 2026. For U.S. federal agencies this deadline is mandatory, and for other organizations it serves as an authoritative benchmark for prioritization.

The fact that exploitation requires authenticated access does not reduce its criticality. In real-world compromise scenarios, attackers often already possess credentials — obtained through phishing, password leaks, or the compromise of adjacent systems. Privilege escalation via AD FS can give an attacker control over the federated authentication infrastructure, potentially opening access to all applications and services that trust this identity provider.

AD FS remains a widely used component of corporate identity infrastructure, especially in organizations that have not yet completed migration to cloud-based solutions. Compromise of an AD FS server can affect the trust chain for all connected applications — both internal and cloud-based — that use federated authentication.

We have previously covered cases where vulnerabilities in Microsoft products were added to the CISA KEV catalog — in particular, SharePoint and RouterOS vulnerabilities. The current case with AD FS confirms that Microsoft identity infrastructure components remain an attractive target for attackers.

Recommendations

  • Install security updates: check for and apply the patch for CVE-2026-56155 via Windows Update or WSUS. Clarify the specific KB update number in the Microsoft advisory for your Windows Server version
  • Audit AD FS accounts: review which accounts have access to AD FS servers and ensure adherence to the principle of least privilege
  • Review event logs: analyze AD FS server logs for anomalous privilege escalation operations or unusual activity from authenticated users
  • Assess the need for AD FS: if the organization is already using cloud authentication, consider accelerating the decommissioning of AD FS in favor of modern solutions

Given the confirmed exploitation and the expired remediation deadline in the CISA KEV catalog, installing the patch for CVE-2026-56155 should not be delayed. Organizations using AD FS should treat this update as a top-priority task and apply it in the next maintenance window while simultaneously auditing access to federation servers.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.