Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-56155

Published 2026-07-14
Updated 2 months ago
Vendor/s
Microsoft
Product/s
Active Directory Federation Services
Version/s
* > 10.0.14393.9339
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
7.8
/ 10
High
Severity Details
Base score
7.8 High
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-56155 is a high-severity local privilege escalation vulnerability in Microsoft AD FS, currently exploited in the wild. Patch immediately.

CPE

Microsoft logo
Microsoft
Product Version Start Version End (excl.) Status
windows_10_1607 * 10.0.14393.9339 vulnerable
windows_10_1607 * 10.0.14393.9339 vulnerable
windows_10_1809 * 10.0.17763.9020 vulnerable
windows_10_1809 * 10.0.17763.9020 vulnerable
windows_server_2012 - - vulnerable
windows_server_2012 r2 r2 vulnerable
windows_server_2016 * 10.0.14393.9339 vulnerable
windows_server_2019 * 10.0.17763.9020 vulnerable
windows_server_2022 * 10.0.20348.5386 vulnerable
windows_server_2025 * 10.0.26100.33158 vulnerable

Related weakness (CWE)

CWE-1220

Remediation plan

1

Apply official patches

Immediately download and install the security updates provided by Microsoft for your specific version of Windows Server and AD FS via Windows Update or the Microsoft Update Catalog.

2

Update affected systems

Ensure Windows Server instances are updated beyond the following versions: Server 2016 (10.0.14393.9339), Server 2019 (10.0.17763.9020), Server 2022 (10.0.20348.5386), and Server 2025 (10.0.26100.33158).

3

Restrict access

Strictly limit local logon rights (interactive and remote desktop) to AD FS servers. Ensure that only a minimal number of trusted administrators have access to the underlying operating system hosting the AD FS role.

4

Monitor for exploitation

Perform forensic triage as per CISA BOD 26-04 guidelines. Review Windows Security logs for Event ID 4672 (Special privileges assigned) and Event ID 4688 (Process creation) originating from non-admin accounts on AD FS nodes.

Detection Guidance

"Detecting exploitation of CVE-2026-56155 requires monitoring for unusual local activity on AD FS servers. Look for Security Event ID 4624 followed by rapid privilege elevation. Audit the AD FS configuration database for unauthorized modifications and monitor for the execution of PowerShell commands or administrative tools by service accounts or low-privileged users. Network signatures are less effective here due to the local attack vector, so focus on host-based endpoint detection (EDR) patterns."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management