CVE-2026-56155: Microsoft AD FS Elevation-of-Privilege Vulnerability Actively Exploited
CVE-2026-56155 (TL-2026-1349) is a high-severity software vulnerability scored CVSS 7.8, first published 2026-07-15. It has no confirmed attribution, affects Microsoft Active Directory Federation Services (AD FS), references 1 CVE (CVE-2026-56155), maps to 16 MITRE ATT&CK techniques (T1003, T1036, T1068), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-1349
- Threat ID
- TL-2026-1349
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-15
- Last reviewed
- 2026-07-15
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, enterprise-it, critical-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in CVE-2026-56155
Malware and tooling: Golden SAML forged token abuse
An elevation-of-privilege vulnerability in Microsoft Active Directory Federation Services (AD FS), caused by insufficient granularity of access control (CWE-1220), lets an authenticated local low-privileged attacker escalate to administrator-level access. Microsoft confirmed in-the-wild zero-day exploitation, credited discovery to its own Detection and Response Team (DART), and shipped fixes on July 14, 2026 as part of a record 569/570/622-CVE July 2026 Patch Tuesday.
How CVE-2026-56155 works
CVE-2026-56155 is an important-severity (CVSS 3.1 base score 7.8) elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS), the on-premises identity federation role that underpins SAML/WS-Federation single sign-on and hybrid trust between on-prem Active Directory and Microsoft Entra ID (Azure AD). The root cause is insufficient granularity of access control (CWE-1220): AD FS fails to sufficiently restrict a class of local operations available to authenticated, low-privileged accounts, allowing those operations to be abused to obtain administrator-level privileges on the AD FS server itself.
The attack vector is local (AV:L) with low attack complexity (AC:L), requiring low privileges (PR:L) and no user interaction (UI:N) from an attacker who already holds an authenticated, low-privileged foothold on the AD FS host -- for example via stolen credentials, a compromised service account, or a low-privilege session obtained through an earlier intrusion stage. Successful exploitation yields high confidentiality, integrity, and availability impact (C:H/I:H/A:H), consistent with full local administrator compromise of the federation server.
Microsoft confirmed active exploitation in the wild prior to patch release and credited discovery to Jeremy Kingston and Scott Clark of Microsoft's own Detection and Response Team (DART) -- an incident-response unit that investigates live intrusions -- strongly suggesting the flaw was identified during real-world breach investigations rather than through proactive research. Microsoft has not published indicators of compromise, the initial access vector used by attackers, or the scope of observed exploitation, leaving defenders without forensic breadcrumbs to hunt on directly; detection must instead focus on anomalous local privilege transitions and post-elevation AD FS administrative activity.
Zero Day Initiative's July 2026 review assigned this bug its highest deployment priority (Priority 1), noting it is "one of several AD FS [bugs] being patched this month, but it's the only one being actively exploited," and explicitly warned that this class of local AD FS EoP "can also be paired with an RCE as we often see in ransomware" -- describing a realistic chain where a remote-code-execution bug (e.g., against SharePoint, Exchange, or another exposed service) delivers initial code execution and low-privilege local access, and CVE-2026-56155 is then used as the second-stage privilege-escalation primitive to reach AD FS server administrator.
AD FS is a high-value target for privilege escalation because a local administrator on an AD FS server can access the federation service's token-signing certificate and configuration database, enabling forgery of SAML tokens ("Golden SAML") that are trusted across every relying party federated with that AD FS instance -- including hybrid Entra ID/Azure AD trust relationships. A Golden SAML forgery lets an adversary impersonate any user, including global administrators, to any relying party without further authentication, and can persist across password resets and even survive removal of the original foothold unless the token-signing certificate itself is rotated.
The same July 2026 AD FS patch batch also fixed a distinct, unauthenticated, network-reachable denial-of-service vulnerability, CVE-2026-50695, which lets a remote attacker without any credentials crash AD FS and disrupt organization-wide sign-in, plus at least six further AD FS denial-of-service bugs rooted in similar buffer-overflow and infinite-loop conditions, including CVE-2026-54983, a stack-based buffer overflow (CVSS 7.5, no user interaction required). While CVE-2026-56155 is the only actively-exploited AD FS bug in the batch, the concentration of DoS and EoP fixes in the same component in a single release underscores AD FS as a current focus of both attacker interest and internal Microsoft/DART hardening work.
The fix shipped as part of Microsoft's July 2026 Patch Tuesday (variously reported as 569, 570, or 622 CVEs across vendors due to differing counting methodologies -- vendor breakdowns cite roughly 254 elevation-of-privilege, 145 remote-code-execution, 102 information-disclosure, 35 denial-of-service, 17 security-feature-bypass, and 16 spoofing vulnerabilities), alongside a second actively-exploited zero-day, CVE-2026-56164 (SharePoint Server, missing authentication for a critical function, CVSS 5.3, unauthenticated and network-reachable), and other high-severity identity-infrastructure fixes including CVE-2026-49164 (Windows Active Directory Domain Services RCE, Critical) and CVE-2026-54121 (Active Directory Certificate Services EoP, Critical). The same release also disclosed a publicly-known BitLocker bypass issue, underscoring a broader theme of identity- and disk-encryption-adjacent hardening in this patch cycle. CISA added CVE-2026-56155 to its Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026 with a remediation due date of July 28, 2026 under Binding Operational Directive BOD 26-04.
MITRE ATT&CK techniques used in TL-2026-1349
Credential Access
T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1649 Steal or Forge Authentication Certificates
Defense Evasion
T1036 Masquerading; T1211 Exploitation for Stealth
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1098 Account Manipulation; T1548 Abuse Elevation Control Mechanism
Discovery
T1069 Permission Groups Discovery; T1087 Account Discovery
Initial Access
Persistence
Impact
T1499 Endpoint Denial of Service
Lateral Movement
T1550 Use Alternate Authentication Material
Resource Development
Reconnaissance
T1591 Gather Victim Org Information
defense-impairment
Affected products and versions in CVE-2026-56155
- Microsoft — Active Directory Federation Services (AD FS)
Vulnerable versions: Windows 10 Version 1607 < 10.0.14393.9339; Windows 10 Version 1809 < 10.0.17763.9020; Windows Server 2012 (x64) < 6.2.9200.26226; Windows Server 2012 R2 (x64) < 6.3.9600.23291; Windows Server 2016 (x64) < 10.0.14393.9339; Windows Server 2019 (x64) < 10.0.17763.9020; Windows Server 2022 (x64) < 10.0.20348.5386; Windows Server 2025 (x64) < 10.0.26100.33158
Fixed in: Windows 10 Version 1607/1809 with July 2026 cumulative update; Windows Server 2012-2025 with July 2026 security update
Remediation for CVE-2026-56155
Patches
- Windows 10 Version 1607 (x86/x64): update to build 10.0.14393.9339 or later
- Windows 10 Version 1809 (x86/x64): update to build 10.0.17763.9020 or later
- Windows Server 2012 (x64): update to build 6.2.9200.26226 or later
- Windows Server 2012 R2 (x64): update to build 6.3.9600.23291 or later
- Windows Server 2016 (x64): update to build 10.0.14393.9339 or later
- Windows Server 2019 (x64): update to build 10.0.17763.9020 or later
- Windows Server 2022 (x64): update to build 10.0.20348.5386 or later
- Windows Server 2025 (x64): update to build 10.0.26100.33158 or later
Immediate actions
- Apply Microsoft's July 2026 security update for AD FS on all affected Windows Server hosts running the federation role
- Prioritize AD FS servers per CISA KEV / BOD 26-04 due date of 2026-07-28 and per ZDI's Priority-1 deployment guidance
- Audit AD FS servers for anomalous local logons, privilege-token changes, and administrative group membership changes since before the patch date
- Also apply the July 2026 fixes for CVE-2026-50695 and the related AD FS denial-of-service bugs (e.g. CVE-2026-54983) shipped in the same batch, since they affect the same AD FS role
Workarounds
- No official workaround published by Microsoft; patching is the only confirmed remediation
Longer-term hardening
- Reduce the number of accounts with local logon rights on AD FS servers to the minimum required
- Rotate the AD FS token-signing and token-decryption certificates if compromise is suspected, and audit all relying-party trusts for Golden SAML abuse
- Deploy EDR/behavioral monitoring on AD FS servers specifically for local privilege-escalation and LSASS/AD FS service-account access patterns
- Segment AD FS servers from general-purpose Windows infrastructure and restrict administrative access to a hardened jump-path
- Monitor for SAML token anomalies (unexpected issuer claims, token lifetimes, or relying-party access patterns) that could indicate forged token use following an AD FS admin compromise
- Treat any RCE against internet-facing services (SharePoint, Exchange, etc.) on a network segment reachable from AD FS as a potential precursor stage to CVE-2026-56155 exploitation, per ZDI's RCE+EoP ransomware-chain warning
CVEs associated with CVE-2026-56155
Weaknesses (CWE) in CVE-2026-56155
CWE-1220
Timeline of CVE-2026-56155
- The same July 2026 batch fixes an unauthenticated, network-reachable AD FS denial-of-service vulnerability, CVE-2026-50695, and at least six further AD FS DoS bugs including CVE-2026-54983 (stack-based buffer overflow, CVSS 7.5), alongside a disclosed BitLocker bypass -- underscoring AD FS and identity infrastructure as a concentrated hardening focus this cycle.
- Zero Day Initiative's July 2026 security update review assigns CVE-2026-56155 its top deployment priority (Priority 1) and warns the local EoP class of bug 'can also be paired with an RCE as we often see in ransomware,' flagging it as a likely second-stage escalation primitive in intrusion chains.
- In the same Patch Tuesday release, Microsoft discloses a second actively-exploited zero-day, CVE-2026-56164 (SharePoint Server missing authentication for a critical function), plus critical identity-infrastructure fixes CVE-2026-49164 (AD Domain Services RCE) and CVE-2026-54121 (AD Certificate Services EoP).
- CISA adds CVE-2026-56155 to its Known Exploited Vulnerabilities (KEV) catalog, mandating remediation under BOD 26-04.
- Microsoft releases the July 2026 Patch Tuesday security updates, fixing CVE-2026-56155 across Windows 10 (1607, 1809) and Windows Server 2012 through 2025, as part of a record-setting 569/570/622-CVE release (source counts vary by vendor).
- Microsoft confirms CVE-2026-56155 was exploited in the wild as a zero-day prior to patch release; no indicators of compromise or initial access vector were disclosed publicly.
- Jeremy Kingston and Scott Clark of Microsoft's Detection and Response Team (DART) are credited with discovering CVE-2026-56155, suggesting it was identified during a live incident-response engagement rather than proactive research.
- Cyber Security News and other outlets publish coverage of the actively-exploited AD FS zero-day, prompting inclusion in the harness backlog as TL-2026-1349.
- CISA's BOD 26-04 remediation deadline for CVE-2026-56155 for U.S. federal agencies.
Sources cited for CVE-2026-56155
- Microsoft Security Update Guide - CVE-2026-56155
- CISA Known Exploited Vulnerabilities Catalog - CVE-2026-56155
- NVD - CVE-2026-56155 Detail
- Microsoft's July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
- Zero Day Initiative — The July 2026 Security Update Review
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
- Record-Breaking Microsoft Patch Tuesday Update: 570 Vulnerabilities Fixed, Including 3 Zero-Days
- Active Directory Services 0-Day Exploited
- Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
- Microsoft's July 14 Patch Blocks a Network Attack That Can Crash AD FS Without Authentication
- July 2026 Patch Tuesday: Fix 2 Exploited AD FS and SharePoint Zero-Days
- Microsoft Fixes Zero-Day Attacks Hitting SharePoint, AD FS in Massive July Patch Tuesday
- Microsoft's 570-Fix Patch Tuesday: Two Zero-Days Exploited, BitLocker Bypass Disclosed
- Microsoft's July Patches Stop Unauthenticated AD FS Crashes — Patch Your Identity Servers Now
Threats related to CVE-2026-56155
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164 SharePoint) Among Record 570+ Fixes
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation (CVE-2026-56155, CVE-2026-56164)
- Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP)
Detection coverage for TL-2026-1349
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1349 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.