All CVEs
Vulnerability intelligence

CVE-2026-56155

CWE-1220

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS Score
7.8
High
EPSS — Exploit Probability
0.3%
Riskier than 27% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-14
Remediation
Patch available
Federal deadline 2026-07-28
NVD entry Vendor patch PoC / advisory CISA KEV

7 articles across 6 outlets · first covered Jul 14, 2026 · latest Jul 15, 2026

Coverage timeline