highZero-Day

Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

First seen Jul 15, 2026 · Updated Jul 15, 2026

CISA-KEVactive-exploitationprivilege-escalationADFSidentity-infrastructureactive-directoryagent-relevant

CVE-2026-56155 is a known-exploited privilege escalation vulnerability in Microsoft Active Directory Federation Services (ADFS) caused by insufficient granularity of access control. It allows an authorized but low-privileged attacker to elevate privileges locally, potentially leading to compromise of federated identity infrastructure. CISA has added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of July 28, 2026.

Technical Analysis

CVE-2026-56155 stems from overly coarse access control checks within ADFS, enabling an authenticated local attacker to perform actions or access resources beyond their intended privilege level, resulting in local privilege escalation. Because ADFS underpins SAML/WS-Federation token issuance for enterprise SSO, successful exploitation could allow an attacker to manipulate federation trust configurations or claims-issuance policies, potentially enabling forged or elevated security tokens across federated relying parties. CISA's KEV listing confirms active exploitation in the wild, making this a high-priority patching target despite the requirement for prior authorized access. Organizations that rely on ADFS-issued tokens to authenticate service principals, automation accounts, or OAuth/SAML flows feeding into AI agent orchestration platforms, RAG pipelines, or LLM tool-calling services are at risk: an attacker escalating privileges on the ADFS host could mint or manipulate tokens trusted by downstream agent systems, enabling unauthorized API access, credential theft, or lateral movement into agent infrastructure that trusts federated identity.

Affected Systems

Microsoft Active Directory Federation Services (ADFS) role on Windows Server; specific affected versions/builds should be confirmed via the official Microsoft security advisory referenced by CVE-2026-56155. Environments where ADFS issues tokens for federated SSO, hybrid identity (e.g., Azure AD/Entra ID federation), or third-party relying party trusts are impacted.

Indicators of Compromise

  • No public IOCs (hashes, IPs, domains) disclosed at this time; monitor CISA KEV catalog and Microsoft MSRC advisory for updates.

Remediation Steps

  1. 1

    Apply Microsoft Security Update

    Install the official Microsoft patch addressing CVE-2026-56155 on all ADFS servers as soon as it is available, prioritizing internet-facing and hybrid identity federation servers.

  2. 2

    Meet CISA KEV Deadline

    Federal agencies and recommended for all organizations to remediate by the July 28, 2026 due date per CISA Known Exploited Vulnerabilities directive.

  3. 3

    Audit ADFS Access Controls

    Review local user and service account permissions on ADFS servers to enforce least privilege and reduce the pool of 'authorized' users who could exploit this flaw.

  4. 4

    Rotate and Review Federated Tokens/Trusts

    Audit relying party trusts, claims-issuance rules, and any service principals or automation/agent credentials that rely on ADFS-issued tokens; rotate secrets and re-validate trust configurations after patching.

  5. 5

    Enhanced Monitoring

    Enable and review ADFS security event logging (e.g., 4624/4648 events, ADFS admin logs) for anomalous privilege escalation attempts or unusual token issuance patterns.

CVE / Advisory IDs

CVE-2026-56155

Industries Most Exposed

GovernmentFinancial ServicesHealthcareTechnologyEducationCritical Infrastructure

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.