CVE-2026-56155
published 2026-07-14CVE-2026-56155: Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
PriorityP184high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-07-28
Exploited in the wild
EPSS
0.38%
30.3th percentile
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.9339 | 10.0.14393.9339 |
| microsoft | windows_10_1809 | < 10.0.17763.9020 | 10.0.17763.9020 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.9339 | 10.0.14393.9339 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.9020 | 10.0.17763.9020 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.26226 | 6.2.9200.26226 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.23291 | 6.3.9600.23291 |
| microsoft | windows_server_2016 | < 10.0.14393.9339 | 10.0.14393.9339 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.9339 | 10.0.14393.9339 |
| microsoft | windows_server_2019 | < 10.0.17763.9020 | 10.0.17763.9020 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.9020 | 10.0.17763.9020 |
| microsoft | windows_server_2022 | < 10.0.20348.5386 | 10.0.20348.5386 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.5386 | 10.0.20348.5386 |
| microsoft | windows_server_2025 | < 10.0.26100.33158 | 10.0.26100.33158 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.33158 | 10.0.26100.33158 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2026-56155 is an Active Directory Federation Services (AD FS) insufficient granularity of access control vulnerability allowing local privilege escalation; it is confirmed actively exploited in the wild and listed in CISA KEV with a remediation due date of 2026-07-28. ↗
- →CVE-2026-56155 carries a CVSS score of 7.8 and has been flagged as actively exploited; prioritize patching AD FS deployments immediately, especially internet-facing instances. ↗
- →CISA has added CVE-2026-56155 to its Known Exploited Vulnerabilities catalog; Federal Civilian Executive Branch agencies must apply fixes by 2026-07-28. Monitor AD FS environments for unauthorized privilege escalation activity. ↗
- →The official Microsoft patch guidance and advisory for CVE-2026-56155 is available at the MSRC update guide; use this as the authoritative source for patch verification and forensic triage requirements per BOD 26-04. ↗
- ·The vulnerability requires an already-authorized (authenticated) attacker to exploit; the privilege escalation is local, not remote. Attack surface is limited to users with existing access to the AD FS system. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
ghsa_unreviewed·2026-07-14
CVE-2026-56155 [HIGH] CWE-1220 Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
VulDB
Microsoft Windows up to 2025 Active Directory Federation Services access control
vuldb·2026-07-14·CVSS 7.8
CVE-2026-56155 [HIGH] Microsoft Windows up to 2025 Active Directory Federation Services access control
A vulnerability classified as problematic was found in Microsoft Windows up to 2025. The affected element is an unknown function of the component Active Directory Federation Services. Such manipulation leads to improper access controls.
This vulnerability is referenced as CVE-2026-56155. The attack can only be performed from a local environment. Furthermore, an exploit is available.
VulnCheck
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
vulncheck·2026·CVSS 7.8
CVE-2026-56155 [HIGH] CWE-1220 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
Affected: Microsoft Active Directory Federation Services
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and e
CISA
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
cisa·2026-07-14·CVSS 7.8
CVE-2026-56155 [HIGH] CWE-1220 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Vulnerability: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Affected: Microsoft Active Directory Federation Services
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet
No detection rules found.
No public exploits indexed.
Checkpoint
20th July – Threat Intelligence Report
blogs_checkpoint·2026-07-20
CVE-2026-56164 20th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance.
Jscrambler,
Hackernews
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
blogs_hackernews·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full recap of what broke, what was exploited, and what needs attention now.
## ⚡ Threat of the Week
New wp2shell WordPress Core Flaw Lets Unauthe
Tenable
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2026-07-16·CVSS 6.5
CVE-2026-32201 [MEDIUM] CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
## CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.
## Key Takeaways
CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet
Hackernews
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
blogs_hackernews·2026-07-15
CVE-2026-56164 Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse ) has released a new proof-of-concept (PoC) exploit called LegacyHive.
It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments.
"The PoC requires another standard user credential and a third username (which can be an administrator account)," Chaotic Eclipse said . "If the PoC is successful, it will e
Tenable
Understanding Claude Tag’s access model in Slack and how to configure it securely
blogs_tenable·2026-07-15
CVE-2026-15409 Understanding Claude Tag’s access model in Slack and how to configure it securely
## Understanding Claude Tag’s access model in Slack and how to configure it securely
Anthropic’s new AI agent for Slack acts under an admin-configured access bundle rather than each user’s own credentials. Here’s how that model works, what admins should understand and how to securely configure it.
## Key takeaways
Claude Tag, Anthropic’s newly launched AI agent for Slack, acts on connected services using shared credentials an admin configures for a workspace or for a specific private channel, not the credentials of the user tagging it.
Claude Tag uses the service-identity pattern, like deploy bots, workflow automations, and incoming webhooks, rather than per-user OAuth delegation. As a result, one admin-configured bundle serves everyone in the channel.
Inviting someone to a channel wh
Tenable
5 reasons to bring application security data into your exposure management platform
blogs_tenable·2026-07-15
CVE-2026-15409 5 reasons to bring application security data into your exposure management platform
## 5 reasons to bring application security data into your exposure management platform
When you incorporate data from application security scanners into your exposure management platform, you can assess the threat from formerly isolated code flaws using a broader risk context, which illuminates hidden exposures that your security and development teams can eliminate together.
## Key takeaways
Break application security silos and obtain full code-to-runtime visibility by integrating standalone code scanner data with your exposure management platform.
By contextualizing application security findings, filtering out alert noise, and automating patches, exposure management helps organizations pinpoint and fix the riskiest coding flaws to your organization.
Leveraging exposure management, CI
Tenable
CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
blogs_tenable·2026-07-15·CVSS 10.0
CVE-2026-15409 [CRITICAL] CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
## CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.
## Key takeaways
CVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances.
Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall.
Patches and indicators of compromise are available and urgent patching is recommended.
## Background
SonicWall's Secure Mobile Access (SMA) 1000 Series appliances are enterprise-grade SSL VPN gateways which serve
Hackernews
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
blogs_hackernews·2026-07-15·CVSS 7.8
CVE-2026-56164 [HIGH] Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200 .
Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Serv
Rapid7
Patch Tuesday - July 2026
blogs_rapid7·2026-07-14·CVSS 9.6
CVE-2026-58617 [CRITICAL] Patch Tuesday - July 2026
Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public disclosure for one other. As usual, browser vulns are not included in the Patch Tuesday count above. Rapid7 noted last month that Microsoft no longer enumerates Chromium CVEs in the Security Update Guide. However, Microsoft has now taken the pursuit of minimalism much further, since today’s Security Update Guide no longer lists out even Microsoft vulnerabilities! Instead, we now receive a summary table of vulnerability counts by product family, as well as a new slimline “Notable CVEs” section. All of this only ser
Talos
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-07-14·CVSS 8.8
CVE-2026-56155 [HIGH] Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical".
Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild.
CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileges locally.
CVE-2026-56164 is a moderate-severity vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function. An unauthorized attacker could exploit i
Sans Isc
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
blogs_sans_isc·2026-07-14·CVSS 6.1
CVE-2026-56155 [MEDIUM] Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here
Published: 2026-07-14. Last Updated: 2026-07-14 19:14:58 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This patch Tuesday includes a staggering 622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft's Edge browser. 62 of the vulnerabilities are rated critical. One was disclosed before today, and two have already been exploited.
Given the large number of vulnerabilities, it is difficult to point out "noteworthy" issues.
Already exploited vulnerabilities:
CVE-2026-56155 : Active Directory Federation Services Elevation of Privilege Vulnerability. This is an important (not critical) vulnerablity.
CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege Vulnerability. Micr
Krebs
Microsoft Patches a Record 570 Security Flaws
blogs_krebs·2026-07-14·CVSS 9.6
CVE-2026-56155 [CRITICAL] Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.
Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows syste
Qualys
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
blogs_qualys·2026-07-14
CVE-2026-50661 Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday forJuly2026
Adobe Patch for July 2026
Zero-day Vulnerabilities Patched inJulyPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inJulyPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
Microsoft’s July 2026 Patch Tuesday delivers security updates for a broad range of products and services, including several vulnerabilities that pose significant risks to enterprise environments. As attackers continue to target unpatched systems, the timely deployment of these updates remains one of the most effective defenses against exploitation. This blog provides an overview of the month’s key security fixes, highlights the most critical vulnerabilities, and offers guidanc
Tenable
Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
blogs_tenable·2026-07-14·CVSS 7.8
CVE-2026-56155 [HIGH] Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
## Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
56 Critical
510 Important
3 Moderate
0 Low
Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.
Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June . Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will see a higher volume of security updates included in each security release.”
This month’s upda
Crowdstrike
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
blogs_crowdstrike
CVE-2026-56155 July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity Jul 15, 2026
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Jul 14, 2026
Why AI Governance Without Guardrails Is Theater Jul 09, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security Jul 08, 2026
AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity Jul 15, 2026
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Jul 14, 2026
Why AI Governance Without Guardrails Is Theater Jul 09, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security Jul 08, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&
2026-07-14
Published
2026-07-14
Added to CISA KEV
Exploited in the wild