Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
July 31, 2026 · CISA · Severity: CRITICAL
Microsoft Active Directory Federation Services (AD FS) has a critical vulnerability (CVE-2026-56155) that enables authorized attackers to locally escalate privileges due to insufficient access control granularity. The flaw, actively exploited in the wild, was added to CISA’s Known Exploited Vulnerabilities catalog on July 14, 2026, highlighting its immediate threat. Microsoft AD FS users are at risk, particularly organizations relying on the service for identity federation and single sign-on. This vulnerability matters because privilege escalation can lead to unauthorized access to sensitive systems or data, compromising entire networks. As AD FS is widely used in enterprise environments, attackers could exploit this flaw to bypass security controls. CISA’s inclusion of the bug in its catalog underscores the urgency for organizations to apply Microsoft’s patches or mitigations to prevent potential breaches.
Key Takeaways
- CVE-2026-56155 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The vulnerability involves privilege escalation or authentication bypass, granting unauthorized access to sensitive functions.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- Active exploitation has been confirmed, increasing urgency for patching across all affected deployments.
- Microsoft Active Directory Federation Services: Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.