a Windows AD FS zero-day is being exploited to escalate privileges — CVE-2026-56155, patch now

Microsoft confirmed CVE-2026-56155 in Active Directory Federation Services is being exploited in the wild. If AD FS underpins your single sign-on,…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

CVE-2026-56155 · CVSS 7.8 — elevation of privilege in Active Directory Federation Services (AD FS).

What you need to know

Zero-day, actively exploited — Microsoft confirmed in-the-wild exploitation at disclosure.

What you need to know

Why it's serious: AD FS underpins single sign-on; escalating privileges there threatens your identity layer.

What you need to know

Disclosed: Microsoft's July 2026 Patch Tuesday (July 14). Fix available now.

What you need to know

Priority: if you run AD FS, treat this above most other July fixes despite the sub-9 score.

Prioritize identity infrastructure

When a vulnerability lands in your identity provider — AD FS, a domain controller, an SSO broker — move it to the top of the queue regardless of the CVSS number. Compromise there undermines every…

Aliteq

Read the full story

a Windows AD FS zero-day is being exploited to escalate privileges — CVE-2026-56155, patch now

Read the full story on Aliteq