Vulnerability intelligence
CVE-2026-56155
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
High
EPSS — Exploit Probability
0.3%
Riskier than 27% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-14
Remediation
Patch available
Federal deadline 2026-07-28
7 articles across 6 outlets · first covered Jul 14, 2026 · latest Jul 15, 2026
Coverage timeline
-
Microsoft, SonicWall bugs found; RabbitMQ patches auth flawssecurityonline.info · Jul 15, 2026
-
Microsoft patches 622 flaws, fixes three critical zero day bugswww.malwarebytes.com · Jul 15, 2026
-
Microsoft patches 570 flaws, two zero days actively exploitedsecurityonline.info · Jul 15, 2026
-
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakeswww.darkreading.com · Jul 14, 2026
-
CISA warns ADFS flaw allows local privilege escalationcisa.gov · Jul 14, 2026
-
Microsoft releases record 621 patches as Adobe updates key appswww.thezdi.com · Jul 14, 2026
-
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Dayswww.securityweek.com · Jul 14, 2026