[KEV] CVE-2026-56155 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-56155 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-56155 is a local privilege escalation vulnerability in Microsoft Active Directory Federation Services (AD FS), caused by insufficient granularity of access control within the service.
Technical Detail
The flaw stems from inadequate access control enforcement within AD FS, allowing an already-authenticated local attacker to escalate their privileges beyond their intended permission level. Because exploitation requires an existing foothold on the system or network, the attack surface is limited to authorized users or processes that have already achieved some level of access. Successful exploitation could allow an attacker to gain elevated privileges within the AD FS environment, potentially enabling further lateral movement or administrative control over federated identity infrastructure.
Exploitation Status
CISA has confirmed active exploitation in the wild, with this vulnerability added to the Known Exploited Vulnerabilities catalog on July 14, 2026. The exploit maturity is rated Operational, meaning functional exploit code exists and is being used in real-world attacks, not merely demonstrated in controlled research settings. Organizations should treat this as an actively weaponized vulnerability requiring immediate attention.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations are available in current intelligence. Given the nature of the vulnerability and its KEV listing, attribution analysis is likely ongoing.
What To Do
Apply the relevant Microsoft security update for Active Directory Federation Services immediately. Per CISA's Known Exploited Vulnerabilities catalog listing dated July 14, 2026, federal agencies under BOD 22-01 are required to remediate this vulnerability according to CISA's specified deadline. All organizations running AD FS should treat patching as a high priority given confirmed active exploitation. In environments where immediate patching is not feasible, restrict local access to AD FS servers to the minimum necessary accounts, audit AD FS service account permissions, and review event logs for anomalous privilege use or unexpected authentication activity. Monitor for unusual token issuance patterns or privilege changes within federated identity workflows as potential indicators of exploitation.