CVE-2026-56155 is a high-severity local privilege escalation vulnerability in Microsoft AD FS, currently exploited in the wild. Patch immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| windows_10_1607 | * | 10.0.14393.9339 | vulnerable |
| windows_10_1607 | * | 10.0.14393.9339 | vulnerable |
| windows_10_1809 | * | 10.0.17763.9020 | vulnerable |
| windows_10_1809 | * | 10.0.17763.9020 | vulnerable |
| windows_server_2012 | - | - | vulnerable |
| windows_server_2012 | r2 | r2 | vulnerable |
| windows_server_2016 | * | 10.0.14393.9339 | vulnerable |
| windows_server_2019 | * | 10.0.17763.9020 | vulnerable |
| windows_server_2022 | * | 10.0.20348.5386 | vulnerable |
| windows_server_2025 | * | 10.0.26100.33158 | vulnerable |
Immediately download and install the security updates provided by Microsoft for your specific version of Windows Server and AD FS via Windows Update or the Microsoft Update Catalog.
Ensure Windows Server instances are updated beyond the following versions: Server 2016 (10.0.14393.9339), Server 2019 (10.0.17763.9020), Server 2022 (10.0.20348.5386), and Server 2025 (10.0.26100.33158).
Strictly limit local logon rights (interactive and remote desktop) to AD FS servers. Ensure that only a minimal number of trusted administrators have access to the underlying operating system hosting the AD FS role.
Perform forensic triage as per CISA BOD 26-04 guidelines. Review Windows Security logs for Event ID 4672 (Special privileges assigned) and Event ID 4688 (Process creation) originating from non-admin accounts on AD FS nodes.
"Detecting exploitation of CVE-2026-56155 requires monitoring for unusual local activity on AD FS servers. Look for Security Event ID 4624 followed by rapid privilege elevation. Audit the AD FS configuration database for unauthorized modifications and monitor for the execution of PowerShell commands or administrative tools by service accounts or low-privileged users. Network signatures are less effective here due to the local attack vector, so focus on host-based endpoint detection (EDR) patterns."
Experience superior visibility and a simpler approach to cyber risk management