CVE-2026-56155 · Moderate · CISA KEV
Microsoft ADFS Privilege Escalation (CVE-2026-56155) Actively Exploited
Threat Engine Auto-Feed · data current as of 2026-07-15
CVE-2026-56155 is an actively exploited privilege escalation vulnerability in Microsoft Active Directory Federation Services (ADFS). An authorized attacker can leverage insufficient access control to elevate privileges locally. This vulnerability is listed in CISA's KEV catalog, indicating confirmed in-the-wild exploitation.
- CVSS:
- EPSS percentile: 0.30119
- Exploitation pressure: 43/100 (Moderate)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 30th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability stems from insufficient granularity of access control, meaning the system does not properly distinguish between different levels of user permissions. An attacker who already has some level of access can exploit this flaw to gain higher privileges than they should have, effectively bypassing intended security boundaries.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations utilizing Microsoft Active Directory Federation Services (ADFS)
- Enterprises with complex identity and access management (IAM) infrastructures
- Organizations where insider threat or compromised credentials are a concern
Misconfigurations that escalate it
- Overly permissive access controls within ADFS configurations
- Lack of granular monitoring for privilege changes or suspicious activity within ADFS
- Failure to segment networks or apply least privilege principles to ADFS servers
High-impact scenarios
- An attacker with initial authorized access could escalate privileges to gain control over ADFS, potentially impacting federated identity services.
- Compromise of ADFS could lead to broader network access, data exfiltration, or disruption of critical services relying on federated authentication.
- Successful exploitation could enable an attacker to impersonate other users or administrators within the federated environment.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor ADFS logs for unusual privilege escalation attempts or unauthorized configuration changes.
- Implement robust identity and access management (IAM) monitoring for ADFS-related activities.
- Regularly audit ADFS configurations for adherence to least privilege principles and secure access controls.
Contain
- Isolate affected ADFS servers from the network if compromise is suspected.
- Revoke or reset credentials for any accounts suspected of being compromised.
- Review and tighten access controls for ADFS administration and service accounts.
Patch
- Apply the latest security updates from Microsoft for Active Directory Federation Services (ADFS) to address CVE-2026-56155.
Frontier verdict — Moderate
High priority due to confirmed in-the-wild exploitation (CISA KEV) and potential for local privilege escalation in critical identity infrastructure.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.