CVE-2026-56155 · CVSS 7.8 HIGH · KEV 2026-07-14 · patch available
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Is CVE-2026-56155 exploited?
Listed in the CISA KEV catalog on 2026-07-14.
Federal remediation due 2026-07-28.
Past that date by 18 days.
Public exploit code: none found in monitored sources.