Microsoft's July 2026 Patch Tuesday, released July 14, 2026, included a fix for an Active Directory Federation Services flaw that was already being used in attacks before the patch existed. The vulnerability, tracked as CVE-2026-56155, lets a low-privileged local attacker elevate to administrator on an AD FS server, and Microsoft confirmed it was exploited in the wild as a zero-day (Microsoft Security Response Center, 2026).
What happened
CVE-2026-56155 is an elevation-of-privilege vulnerability caused by insufficient granularity in AD FS access control, catalogued as CWE-1220 (Tenable, 2026). It carries a CVSS 3.1 base score of 7.8 and Microsoft rates it Important rather than Critical, a rating based on the local attack vector rather than the scope of what the flaw enables once triggered (Tenable, 2026). Exploitation requires no user interaction and low attack complexity: an attacker who already has low-privilege local access to an AD FS host can use the flaw to reach administrator rights on that server (Microsoft Security Response Center, 2026).
The discovery is credited to Microsoft's own Detection and Response Team, meaning Microsoft identified the in-the-wild activity through its own incident response rather than an outside researcher's disclosure (Tenable, 2026).
Who is affected
The flaw affects Active Directory Federation Services, the component that issues and signs the authentication tokens every federated application trusts. That makes it more consequential than the "local" attack vector suggests: gaining administrator on an AD FS server gives an attacker the ability to forge tokens and impersonate any user across every application that federates to it, not just resources on that one server. CISA added CVE-2026-56155 to its Known Exploited Vulnerabilities catalog on July 14, 2026, the same day Microsoft published the fix, and set a remediation deadline of July 28, 2026 for federal civilian agencies under Binding Operational Directive 26-04 (CISA, 2026).
What affected organizations should know
The patch was included in the July 2026 cumulative update, one of 622 vulnerabilities Microsoft addressed that month across its product line, of which 63 were rated Critical (Microsoft Security Response Center, 2026). Organizations running AD FS should prioritize this specific patch ahead of the broader monthly rollout given the confirmed in-the-wild exploitation and CISA's KEV listing. Because AD FS sits at the center of federated authentication, a compromised AD FS host is not contained to that machine; every downstream service that trusts its tokens is exposed until the token-signing keys are rotated and the host is confirmed clean.
Microsoft's advisory does not disclose exploit code or attacker tooling beyond confirming that exploitation occurred, and this brief does not go beyond what the advisory and CISA's alert state.
What happens next
The federal remediation deadline under BOD 26-04 is July 28, 2026 (CISA, 2026). That deadline applies to federal civilian agencies, not private organizations, but it is a reasonable benchmark for any organization running AD FS to target. Watch for whether Microsoft or CISA issues a follow-up advisory if exploitation activity broadens beyond what has been confirmed so far.
Sources
- Microsoft Security Response Center, "Security Update Guide, CVE-2026-56155" - https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-56155
- CISA, "CISA Adds Four Known Exploited Vulnerabilities to Catalog" - https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalog
- Tenable, "Microsoft's July 2026 Patch Tuesday Addresses 569 CVEs Including CVE-2026-56155, CVE-2026-56164" - https://www.tenable.com/blog/microsofts-july-2026-patch-tuesday-addresses-569-cves-cve-2026-56155-cve-2026-56164
