CVE detail
CVE-2026-56155
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 2
- within the 30d window
- Peak daily
- 2
- highest bucket
Evidence
Source links by recency
25 source links · newest first
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreThe Hacker News
on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) explo
newsthehackernews.comJul 20, 2026, 1:32 PM - 20th July – Threat Intelligence ReportCheck Point Research
day, the largest monthly release recorded by the company. Two vulnerabilities were under active exploitation, including CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Both vulnerabilities could allow attackers to elevate privileges. Check Point IPS provides protection against these threats (Microsoft Sha
vendorresearch.checkpoint.comJul 20, 2026, 12:18 PM - July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-DaysCrowdStrike
t families affected by July 2026 Patch Tuesday Exploited Zero-Day Vulnerability in Active Directory Federation Services CVE-2026-56155 is an Important elevation of privilege vulnerability affecting Active Directory Federation Services (AD FS) and has a CVSS score of 7.8 . An insufficient granularity of access control flaw (CWE-1220) allows a low-privil
vendorwww.crowdstrike.comJul 17, 2026, 8:00 PM s deployments. Key Takeaways CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence. Two additional SharePoint Server vulnerabilities disclosed
vendorwww.tenable.comJul 16, 2026, 4:00 PMMicrosoft's July 2026 Patch Tuesday sets yet another record, fixing 622 Microsoft CVEs—three times as many as last month.
newswww.malwarebytes.comJul 15, 2026, 12:21 PMicrosoft shipped patches for a record 622 flaws , including two privilege escalation shortcomings in SharePoint Server (CVE-2026-56164, CVSS score: 5.3) and Active Directory Federation Services (CVE-2026-56155, CVSS score: 7.8) that have been flagged as actively exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both
newsthehackernews.comJul 15, 2026, 11:07 AM- U.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
onicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog . The flaws added to the catalog are: CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient
newssecurityaffairs.comJul 15, 2026, 10:49 AM - AI-driven bug hunting fuels record Microsoft Patch TuesdayHelp Net Security
eased patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged by attackers (CVE-2026-56155 and CVE-2026-56164), and one that was previouly disclosed (CVE-2026-50661). The release was once again followed by Nightmare Eclipse publishing a stripped down proof-of-concept exploit for an unpatched Windows elevation
newswww.helpnetsecurity.comJul 15, 2026, 10:20 AM - Microsoft Patches 570 CVEs in Record Patch TuesdayInfosecurity Magazine
lnerabilities in July’s Patch Tuesday are three zero-day vulnerabilities; two of which have been exploited in the wild. CVE-2026-56155 is an elevation of privilege (EoP) vulnerability in Active Directory Federation Services which allows an authorized attacker to elevate privileges locally. “Eight other vulnerabilities are also published today in Active
newswww.infosecurity-magazine.comJul 15, 2026, 9:20 AM patched, including two that have been exploited in the wild. Those two are both elevation of privilege vulnerabilities: CVE-2026-56155, an Active Directory Federation Services (AD FS) flaw that allows attackers with limited access to elevate privileges to administrator, and CVE-2026-56164 , a Microsoft SharePoint Server vulnerability. The third is CVE-
newswww.csoonline.comJul 15, 2026, 1:54 AMation of remediations as a trailing indicator. SharePoint: critical auth bypass by Rapid7 Today sees the publication of CVE-2026-55040 , a critical authentication bypass in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft, this vulnerability is the first i
vendorwww.rapid7.comJul 14, 2026, 10:00 PMurity updates" and continuous patching. High-Priority Vulnerabilities The immediate threats in this month's release are CVE-2026-56155 (CVSS: 7.2), an elevation of privilege (EoP) vulnerability in Microsoft Active Directory Federation Services that attackers can exploit to gain system level privileges; and CVE-2026-56164 (CVSS: 5.3), another EoP flaw,
newswww.darkreading.comJul 14, 2026, 9:50 PM- Patch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one monthSecurity Affairs
this mess is anyone’s guess.” states the report published by ZDI. The following two bugs are being actively exploited: CVE-2026-56155 is an elevation of privilege flaw in Active Directory Federation Services. It requires local access and low privileges to start, which sounds like a limited threat until you remember that AD FS is identity infrastructur
newssecurityaffairs.comJul 14, 2026, 9:33 PM ication denial-of-service, and arbitrary code execution. Zero-day Vulnerabilities Patched in July Patch Tuesday Edition CVE-2026-56155: Active Directory Federation Services Elevation of Privilege Vulnerability Insufficient granularity of access control in Active Directory Federation Services (AD FS) could allow an authenticated attacker to elevate priv
vendorblog.qualys.comJul 14, 2026, 9:23 PM- Patchpocalypse Now: Microsoft tops last month's record with 622 Patch Tuesday CVEsThe Register Security
icrosoft’s massive month To start, let’s cover the pair of actively exploited issues that Microsoft patched. The first, CVE-2026-56155, is an Active Directory Federation Services elevation of privilege vulnerability. Attackers who exploit the issue, which Microsoft only described as being due to “insufficient granularity of access control on ADFS,” cou
newswww.theregister.comJul 14, 2026, 8:49 PM ed as "critical." Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild. CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileg
vendorblog.talosintelligence.comJul 14, 2026, 8:27 PMedits incident responders for both. Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Neither is one of the splashy remote code execution criticals. They are privilege bugs in two systems that matter more than th
newsthehackernews.comJul 14, 2026, 8:25 PM- Microsoft Patches a Record 570 Security FlawsKrebs on Security
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
newskrebsonsecurity.comJul 14, 2026, 7:22 PM luding two bugs in Active Directory and SharePoint Server that have been exploited in the wild as zero-days. Tracked as CVE-2026-56155, the exploited AD flaw affects Federation Services (AD FS) and could allow attackers to elevate their privileges locally to administrator. Also leading to privilege escalation, the SharePoint Server flaw is tracked as C
newswww.securityweek.comJul 14, 2026, 6:50 PMof the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 25.1%. Important CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege Vulnerability CVE-2026-56155 is an EoP vulnerability affecting Active Directory Federation Services. It received a CVSSv3 score of 7.8 and is rated important
vendorwww.tenable.comJul 14, 2026, 6:23 PMile no official fix is available. The two actively exploited zero-days addressed during this month's Patch Tuesday are: CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability Microsoft has patched an actively exploited vulnerability in Active Directory Federation Services that grants administrative privileges. "Insuf
newswww.bleepingcomputer.comJul 14, 2026, 6:01 PM- The July 2026 Security Update ReviewZero Day Initiative
oser look at some of the more interesting updates for this month, starting with the bugs being exploited in the wild. - CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability This is one of several AD FS being patched this month, but it’s the only one being actively exploited. It stems from insufficient access-contro
vendorwww.thezdi.comJul 14, 2026, 5:56 PM No excerpt available.
Mitigationwww.cisa.govJul 14, 2026, 5:17 PM- CVE-2026-56155 Active Directory Federation Services Elevation of Privilege VulnerabilityMicrosoft MSRC
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
vendormsrc.microsoft.comJul 14, 2026, 2:00 PM ur new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient
governmentwww.cisa.govJul 14, 2026, 12:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-62721CVSS 7.8 · High
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-50502CVSS 8.0 · High
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
- CVE-2026-50405CVSS 7.8 · High
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
- CVE-2026-70347CVSS 7.8 · High
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-70346CVSS 7.8 · High
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2026-70345CVSS 7.8 · High
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.