CVE-2026-56155
Summary
A privilege-escalation flaw in Microsoft Active Directory Federation Services, one of two zero-days under active exploitation in Microsoft's July 2026 Patch Tuesday release.
Details
AD FS is the token issuer for federated identity in a Windows estate, which makes a privilege-escalation flaw there an identity-layer problem rather than an endpoint one: the artefact worth protecting is the token and the trust relationship it carries, and an escalation inside the federation service is a route to claims the attacker should not hold. The digest recorded it as one of two exploited zero-days in a record 622-flaw release, the other being a SharePoint Server escalation (CVE-2026-56164); both are the class of flaw that benefits from checking for pre-patch compromise, not just patching.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-56155 |
| CVSS | 7.8 |
| Vendor / product | Microsoft (Active Directory Federation Services) |
| Reported in the digest | 2026-07-15 |
Related Pages
Sources: raw/digests/Cyber-Digest-2026-07-15.md