LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 14, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 28, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-56155 to its Known Exploited Vulnerabilities catalog on Jul 14, 2026, with a federal patch deadline of Jul 28, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

This vulnerability affects Microsoft Active Directory Federation Services. It arises from insufficient granularity of access control and permits an authorized attacker to elevate privileges locally on the affected system.

How it works

The weakness is categorized as CWE-1220, insufficient granularity of access control. In this class of flaw, permissions assigned to an authorized user or process are broader than required for the intended operation. An attacker who already possesses valid credentials or a session on the system can leverage the coarse access rules to perform actions that should be restricted, resulting in local privilege elevation.

Am I affected? How to find it in your systems

Microsoft Active Directory Federation Services runs on Windows Server systems configured for identity federation and authentication services. Inventory all servers that host the ADFS role or related federation components. Review installed server roles, service accounts, and configuration files to identify ADFS deployments. Check the specific versions and configurations in use against the vendor advisory, as the provided details do not list exact affected releases.

How to remediate

Apply the vendor update named in the advisory as the primary step. Follow all instructions provided by Microsoft for installing and verifying the fix on ADFS servers. After patching, review access control configurations for the affected component class to ensure permissions are limited to the minimum required for each role or operation.

If you can't patch immediately

Apply mitigations in accordance with vendor instructions while ensuring compliance with CISA BOD 26-04 guidance on prioritizing security updates. Segment ADFS servers from general-purpose networks to limit lateral movement opportunities. Monitor authentication and authorization activity for anomalies. Disable or restrict non-essential federation features if they are not required. Stakeholders must evaluate each asset's internet exposure and follow applicable BOD 26-04 requirements for cloud services or discontinue use if mitigations cannot be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this type can contribute to unauthorized access and subsequent data exposure. You can run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Active Directory Federation Services
WeaknessCWE-1220
Added to CISA KEVJul 14, 2026
Federal patch deadlineJul 28, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities