Microsoft has disclosed an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS), tracked as CVE-2026-56155.
The flaw was released on July 14, 2026, as part of Microsoft’s largest Patch Tuesday on record, covering 622 CVEs, and carries a CVSS 3.1 base score of 7.8 with a temporal score of 7.2.
The root cause is classified under CWE-1220: Insufficient Granularity of Access Control, meaning AD FS fails to enforce sufficiently fine-grained permission boundaries between roles.
Microsoft Active Directory FS Privilege Escalation Flaw
According to Microsoft’s advisory, this weakness “allows an authorized attacker to elevate privileges locally”.
Zero Day Initiative researchers note that the flaw stems from insufficient access-control granularity and requires low-privilege local access to exploit, though this is a low bar given that AD FS servers are frequently accessed post-compromise.
Microsoft’s own security update guidance ties the issue directly to weak Access Control List (ACL) permissions on the AD FS Distributed Key Manager (DKM) container, a component responsible for storing and sharing encryption keys across an AD FS farm.
Microsoft’s exploitability index confirms exploitation has already been detected in the wild, and the vulnerability was not publicly disclosed prior to the advisory, suggesting it was uncovered through direct incident response rather than prior public research.
Zero Day Initiative analysts specifically flagged CVE-2026-56155 as “the only one being actively exploited” among several AD FS bugs patched this month, and warned it “can also be paired with an RCE as we often see in ransomware”.
Successful exploitation grants attackers administrator-level privilege. Because AD FS serves as core identity federation infrastructure, bridging on-premises Active Directory and cloud services such as Microsoft 365 and Azure AD, compromise at this level carries outsized consequences.
Zero Day Initiative bluntly summarized the risk by noting that “AD FS is exactly the kind of identity infrastructure attackers love to pivot through once they’re in”, since privileged access there can enable token forgery, authentication bypass, and lateral movement across federated cloud and on-premises environments.
Mitigation
Microsoft’s remediation approach is rolled out in phases rather than through a single automatic fix.
The July 14, 2026 update introduces an audit mode that detects insecure DKM container ACL configurations and logs Event ID 1132 in the AD FS Admin event log when attention is required, but it does not change permissions automatically.
Administrators can opt into remediation immediately by setting the RemediateDkmAcl registry key, and Microsoft has set October 13, 2026 as the date after which unconfigured environments will be remediated automatically.
Give your SOC the intelligence it needs to act with confidence.
Explore ANY.RUN Threat Intelligence Feeds to reduce noise and improve operational efficiency.
