CVE-2026-56155

Published Jul 14, 2026

Last updated a month ago

Exploit knownCVSS high 7.8
Cloud
Network
Zero-day
Server

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-56155 is an elevation of privilege vulnerability found in Microsoft Active Directory Federation Services (AD FS). This flaw stems from an insufficient granularity of access control within the service. An authorized attacker can exploit this vulnerability to locally elevate their privileges. Microsoft has addressed this issue, noting that it was actively exploited in the wild as a zero-day vulnerability. Organizations are advised to apply mitigations in accordance with vendor instructions to address this vulnerability.

Description
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Exploit added on
Jul 14, 2026
Exploit action due
Jul 28, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-1220

Social media

Hype score
Not currently trending
  1. Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164) https://t.co/vznD7BoR0u https://t.co/6IMyD4pXK2

    @dansantanna

    8 Aug 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Microsoft tarihinin en büyük Patch Tuesday'i: 622 açık, 3 sıfır gün, 2'si zaten aktif saldırıda! Temmuz güncellemesinde CVE-2026-56164 (SharePoint), kimlik doğrulaması gerektirmeden kritik işlevlere erişim sağlayarak aktif olarak istismar ediliyor. CVE-2026-56155

    @BTHaberler

    22 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Microsoft July Patch Tuesday: 622 CVEs, the largest release in company history, with 2 actively exploited zero-days. CVE-2026-58644 (SharePoint RCE, CVSS 9.8) and CVE-2026-56155 (AD FS priv esc) now on CISA KEV. Patch now. #InfoSec #ZeroDay #PatchTuesday

    @infrasecserv

    22 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Active Exploitation Alert: CVE-2026-56155 (CVSS 7.8) — Microsoft AD FS Privilege Escalation Low-priv local attackers can escalate to admin on AD FS servers. Already in CISA KEV. 🔗 https://t.co/PdsbKkoYy0 #CyberSecurity #ThreatIntel https://t.co/tdMRkMOKKZ

    @ThreatAft

    19 Jul 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Vulnerability Alert: CVE-2026-56155 Product: Microsoft Active Directory Federation Services (AD FS) CVE: CVE-2026-56155 CVSS v3.1: 7.8 (High) Impact: Local Privilege Escalation (Elevation of Privilege) Exploitation: ✅ Actively exploited in the wild (CISA KEV) #cveexposure

    @RaoulBiasso

    18 Jul 2026

    18 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. July 2026 Patch Tuesday drops 622 CVEs with three zero-days: SharePoint (CVE-2026-56164) and AD FS (CVE-2026-56155) are actively exploited and CISA KEV-listed. #DFIR_Radar https://t.co/pLY8VaBF7d

    @DFIR_Radar

    17 Jul 2026

    189 Impressions

    1 Retweet

    3 Likes

    1 Bookmark

    2 Replies

    0 Quotes

  7. Microsoft Patch Tuesday: Rekord-breaking 622 CVEs. Zwei Zero-Days (CVE-2026-56155, CVE-2026-56164) werden aktiv ausgenutzt. Sofort patchen! #PatchTuesday #CyberSecurity https://t.co/dKB08AxiKK

    @wall_your_x

    17 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. MS Patch Tuesday (Jul 14/15) addressed active zero-days: CVE-2026-56164 (SharePoint) & CVE-2026-56155 (ADFS) enable privilege escalation. SonicWall SMA1000 zero-days also exploited. Data integrity/privacy at risk. #Cybersecurity #InfoSec #Vulnerabilities

    @YourAnon_irc

    17 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🛡️ Microsoft's July Patch Tuesday: 622 CVEs, the largest on record. Two under active attack — CVE-2026-56164 (SharePoint) and CVE-2026-56155 (AD FS). What's exploitable and what to patch first: https://t.co/YdTCg7eWT0

    @colibrisec

    16 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 Microsoft July 2026 Patch Tuesday: 622 flaws fixed. 2 zero-days exploited. 🔴 CVE-2026-56164 — SharePoint 🔴 CVE-2026-56155 — AD FS Patch exploited identity and collaboration systems first. Don’t rely on CVSS alone. https://t.co/dGByZy5j04 #CyberSecurity #PatchTues

    @vulert_official

    16 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 今月気になるのは、既に悪用されていて今後も悪用されそうなADFSの権限昇格(CVE-2026-56155)、認証不要でのRDPのRCE(CVE-2026-56190)、あとはOWAでメール開くだけでスクリプト実行できる(CVE-2026-55008)は悪用され

    @autumn_good_35

    16 Jul 2026

    635 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. Microsoft ships its biggest Patch Tuesday ever with 2 zero-days already exploited: AD FS (CVE-2026-56155) + SharePoint (CVE-2026-56164). Plus a 4th BitLocker bypass in 5 weeks (CVE-2026-50661). Patch now.  https://t.co/qs2aI4iwIR https://t.co/opbzEJk06M #CyberSecurity http

    @DIESEC_GmbH

    16 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🔎 V rámci červencového Patch Tuesday bylo opraveno rekordních 622 zranitelností. Dvě zero day chyby umožňující zvýšení oprávnění již byly aktivně zneužívány: ⚠️ CVE-2026-56164 v on-premises SharePoint Serveru ⚠️ CVE-2026-56155 v ADFS Třetí zero

    @sec4good

    16 Jul 2026

    60 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🟦 PCMedicalist Signal · Jul 15 • IETF Community Survey 2025 — IETF Blog • CVE-2026-56155 — Microsoft Active Directory Federation Ser… — CISA KEV Vulns #VulnerabilityIntelligence #Standards SecOps · Blue Team · Autonomous Builds https://t.co/aQlS2qbAgC

    @PCMedicalist

    15 Jul 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164) https://t.co/dF0u4oO0St https://t.co/2Nnvf2s9pc

    @ggrubamn

    15 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Microsoft just shipped 622 CVE patches — biggest release in company history — and 2 are already exploited. If you're on Windows and haven't updated this week, your machine is a soft target for CVE-2026-56164 (SharePoint) + CVE-2026-56155 (AD FS). Update tonight.

    @FaultSignal_

    15 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164) https://t.co/RIwE8jAnDX https://t.co/72juYIrOoL

    @secured_cyber

    15 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Microsoft patches 3 zero-days in July 2026 Patch Tuesday — 2 already under attack 🚨 🔹 CVE-2026-56155: AD FS flaw grants admin privileges, exploited in the wild 🔹 CVE-2026-56164: SharePoint bug lets remote attackers elevate privileges 🔹 CVE-2026-50661: BitLocker byp

    @techepages

    15 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Microsoftは、Active Directory Federation Services(AD FS)に存在し、実際に悪用が確認されている権限昇格の脆弱性「CVE-2026-56155」の修正プログラムを公開した。認証済みの低権限ユーザーが管理者権限を取得できる恐れ

    @yousukezan

    15 Jul 2026

    1506 Impressions

    1 Retweet

    11 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  20. 【脆弱性の嵐】マイクロソフトさん、月例更新で史上最多となる622件の脆弱性を修正。ゼロデイはADFSのCVE-2026-56155とSharePointのCVE-2026-56164の2件。他外部指摘は物理でのBitLocker回避CVE-2026-50661。 https://t.co/zJK92NBTQE

    @__kokumoto

    14 Jul 2026

    1910 Impressions

    4 Retweets

    15 Likes

    3 Bookmarks

    1 Reply

    1 Quote

  21. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。月次更新関連。SonicWall SMA1000のCVE-2026-15409とCVE-2026-15410、ADFSのCVE-2026-56155、SharePointのCVE-2026-56164。

    @__kokumoto

    14 Jul 2026

    2150 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  22. Microsoft's July 2026 Patch Tuesday fixes 570 flaws. Zero-days CVE-2026-56155 and CVE-2026-56164 are exploited in the wild. Patch now. #PatchTuesday #Microsoft #ZeroDay #CVE #CyberSecurity https://t.co/cdi7Tiqj27

    @Daily_CyberSec

    14 Jul 2026

    339 Impressions

    3 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨 CRITICAL: CVE-2026-56155 in Microsoft AD FS allows privilege escalation by authorized attackers. Added to CISA KEV—patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/R1mNleti0Q

    @DFIR_Lab

    14 Jul 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 Microsoft Patch Tuesday (July 2026): Microsoft has patched ~570 vulnerabilities, including critical RCE flaws and three publicly disclosed issues: CVE-2026-56164, CVE-2026-56155, and CVE-2026-50661. #CyberSecurity #Microsoft #PatchTuesday #CVE #ThreatWire

    @ThreatWire_

    14 Jul 2026

    75 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Microsoft’s July 2026 Patch Tuesday delivers fixes for approximately 570 vulnerabilities across its product ecosystem, following June’s record-breaking release of 206 flaws that also included three publicly disclosed zero-days. 📌 CVE-2026-56164 📌 CVE-2026-56155 📌 ht

    @The_Cyber_News

    14 Jul 2026

    7760 Impressions

    33 Retweets

    130 Likes

    27 Bookmarks

    5 Replies

    0 Quotes

Configurations