Historical catalog analysis: CISA added this entry on July 14, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.
What the vulnerability is
CVE-2026-56155 is a security flaw in Microsoft Active Directory Federation Services (AD FS) characterized by insufficient granularity of access control (CWE-1220). This vulnerability enables an attacker who already possesses authorized access to the system to elevate their privileges locally.
Exposure and applicability
This vulnerability affects environments deploying Microsoft Active Directory Federation Services. The risk is specifically tied to local privilege escalation; it does not involve remote initial access but rather the ability of a compromised or malicious authorized user to gain higher-level permissions on the affected host. Organizations utilizing AD FS for identity federation should identify all servers running this service to determine their exposure.
Remediation priorities
Based on the inclusion of this vulnerability in CISA’s Known Exploited Vulnerabilities catalog on July 14, 2026, remediation should be prioritized as a high-urgency task. Our analysis suggests the following priority sequence:
- Identify Affected Assets: Inventory all servers running Microsoft AD FS to establish the scope of exposure.
- Apply Vendor Mitigations: Implement the specific corrective actions detailed in the official Microsoft vendor instructions.
- Evaluate Asset Exposure: Assess whether affected assets are exposed to the internet, as this may influence the urgency and method of deployment according to risk-based patching guidelines.
- Decommissioning Review: For environments where AD FS is no longer required or mitigations cannot be applied, evaluate the feasibility of decommissioning the service using vendor guides.
How to validate remediation
Verification must go beyond confirming a version number or the presence of a patch. To ensure exposure has been reduced, defenders should:
- Verify Mitigation Application: Confirm that the specific configuration changes or updates mandated by the vendor instructions are active on all identified AD FS hosts.
- Access Control Audit: Review local privilege assignments and access control lists (ACLs) on the affected service components to ensure the “insufficient granularity” has been corrected.
- Configuration Baseline: Compare the post-remediation state against a known secure baseline for AD FS to ensure no unauthorized permissions remain.
Limits and open questions
Applying vendor mitigations could reduce the likelihood of local privilege escalation, but it does not eliminate all risks associated with authorized access. Residual risk remains if an attacker has already established persistence or elevated privileges prior to the mitigation being applied. It is currently unknown whether this vulnerability has been utilized in known ransomware campaigns. Furthermore, while CISA set a remediation deadline of July 28, 2026, for federal agencies, non-federal organizations must determine their own timelines based on their specific risk profile.
Source and editorial note
CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability · Source date: July 14, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Archive date: July 17, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 04, 2026 at 01:55 UTC.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗