ALITEQ.

a Windows AD FS zero-day is being exploited to escalate privileges CVE-2026-56155, patch now

Microsoft confirmed CVE-2026-56155 in Active Directory Federation Services is being exploited in the wild. If AD FS underpins your single sign-on, this is a priority fix.

Priya NairUpdated 1h ago10 min read
A padlock on a keyboard lit in red and green

Buried in Microsoft's record-breaking July 2026 Patch Tuesday is a zero-day that deserves priority attention: CVE-2026-56155, an elevation-of-privilege flaw in Active Directory Federation Services (AD FS) with a CVSS score of 7.8, confirmed as actively exploited in the wild. The score is lower than a headline 9.8 RCE, but the target makes it dangerous — AD FS is the identity backbone that brokers single sign-on for countless organizations, so a privilege escalation here can translate into control over authentication itself.

Why an AD FS bug is worse than its score suggests

CVSS measures technical severity, not business impact, and this is a case where the target matters more than the number. AD FS issues security tokens that other applications trust for authentication — it's the thing standing between a login and access to email, file shares, and cloud apps across an organization. An attacker who can escalate privileges within AD FS is operating at the most sensitive layer of your environment, potentially able to forge or manipulate the trust that everything else depends on. That's why identity-infrastructure vulnerabilities get prioritized above many higher-scoring bugs in less critical software: the blast radius is the entire authentication estate. Microsoft flagging this as already exploited removes any excuse to wait — attackers are using it now.

A digital security and authentication concept
AD FS brokers single sign-on — a privilege escalation there threatens the trust your whole environment relies on. · Unsplash

What to do

Apply the July 2026 AD FS security update on all federation servers now — this is a priority patch.

Review AD FS sign-in and admin logs for anomalous token activity or privilege changes.

Consider rotating AD FS token-signing certificates if you suspect exposure.

Reduce AD FS internet exposure and enforce MFA on all federated access.

Quick answers

What is CVE-2026-56155?
CVE-2026-56155 is an elevation-of-privilege vulnerability (CVSS 7.8) in Windows Active Directory Federation Services (AD FS), disclosed in Microsoft's July 2026 Patch Tuesday and confirmed as an actively-exploited zero-day. AD FS issues authentication tokens for single sign-on, so an attacker escalating privileges within it operates at a highly sensitive layer of an organization's identity infrastructure. Despite a score below the 9.8 range of some RCEs, its position in the authentication stack makes it a priority fix for anyone running AD FS.
Why is an AD FS vulnerability so serious if the CVSS is only 7.8?
Because CVSS measures technical severity, not business impact, and AD FS sits at the most sensitive point in an environment — it brokers the single sign-on trust that email, file shares, and cloud apps rely on. An attacker who escalates privileges in AD FS can potentially manipulate the authentication other systems trust, giving a blast radius far larger than the number implies. Identity-infrastructure flaws are routinely prioritized above higher-scoring bugs in less critical software for exactly this reason. Active exploitation makes it more urgent still.
How do I protect against CVE-2026-56155?
Apply Microsoft's July 2026 security update to all AD FS federation servers immediately — treat it as a priority given active exploitation. Then review AD FS sign-in and administrative logs for anomalous token activity or unexpected privilege changes, consider rotating AD FS token-signing certificates if you suspect exposure, reduce AD FS internet exposure, and enforce multi-factor authentication on all federated access. Because this is an identity-layer flaw, err toward over-response: a compromise here can undermine every other security control you have.

CVE-2026-56155 is a reminder that the scariest vulnerabilities aren't always the highest-scored — they're the ones sitting on your identity layer. Patch AD FS now and audit it. It arrived alongside a record patch load: see our July 2026 Patch Tuesday breakdown. Sources: Rapid7 and Microsoft's MSRC advisory.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading