Microsoft has flagged the CVE-2026-56155 vulnerability in Active Directory Federation Services (AD FS) as actively exploited. The issue is related to insufficient granularity of access control and allows an authenticated attacker to perform local privilege escalation. The vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog with a remediation deadline of July 28, 2026 — this deadline has already passed. Organizations using AD FS must immediately check the status of patch deployment and apply available updates.
Technical details of the vulnerability
According to the Microsoft advisory, the root cause of CVE-2026-56155 is insufficient granularity of access control in the AD FS component. This means that the authorization mechanism in the federation service does not provide sufficiently fine-grained separation of privileges, opening a path to privilege escalation.
Key characteristics of the documented attack vector:
- Precondition: the attacker must be authenticated in the system — the vulnerability does not allow unauthenticated exploitation
- Impact type: local privilege escalation
- Exploitation status: Microsoft notes “Exploited: Yes” and “Exploitation Detected” for current software versions
- Public disclosure: at the time the advisory was published — no (Publicly Disclosed: No)
The NVD entry for this CVE is available, but the CVSS score, specific affected Windows Server versions, and the number of the fixing update are not provided in the available data. This is important to keep in mind when planning: administrators should consult the Microsoft Security Update Guide portal directly for the full list of affected platforms and corresponding KB updates.
Remediation priority assessment
The combination of two factors makes this vulnerability a priority for immediate response. First, Microsoft confirms that it is being exploited in real-world attacks. Second, CISA added CVE-2026-56155 to the KEV catalog on July 14, 2026 with a remediation deadline of July 28, 2026. For U.S. federal agencies this deadline is mandatory, and for other organizations it serves as an authoritative benchmark for prioritization.
The fact that exploitation requires authenticated access does not reduce its criticality. In real-world compromise scenarios, attackers often already possess credentials — obtained through phishing, password leaks, or the compromise of adjacent systems. Privilege escalation via AD FS can give an attacker control over the federated authentication infrastructure, potentially opening access to all applications and services that trust this identity provider.
AD FS remains a widely used component of corporate identity infrastructure, especially in organizations that have not yet completed migration to cloud-based solutions. Compromise of an AD FS server can affect the trust chain for all connected applications — both internal and cloud-based — that use federated authentication.
We have previously covered cases where vulnerabilities in Microsoft products were added to the CISA KEV catalog — in particular, SharePoint and RouterOS vulnerabilities. The current case with AD FS confirms that Microsoft identity infrastructure components remain an attractive target for attackers.
Recommendations
- Install security updates: check for and apply the patch for CVE-2026-56155 via Windows Update or WSUS. Clarify the specific KB update number in the Microsoft advisory for your Windows Server version
- Audit AD FS accounts: review which accounts have access to AD FS servers and ensure adherence to the principle of least privilege
- Review event logs: analyze AD FS server logs for anomalous privilege escalation operations or unusual activity from authenticated users
- Assess the need for AD FS: if the organization is already using cloud authentication, consider accelerating the decommissioning of AD FS in favor of modern solutions
Given the confirmed exploitation and the expired remediation deadline in the CISA KEV catalog, installing the patch for CVE-2026-56155 should not be delayed. Organizations using AD FS should treat this update as a top-priority task and apply it in the next maintenance window while simultaneously auditing access to federation servers.