Skip to main content

CVE detail

CVE-2026-56155

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · HighBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
25 evidence mentions in the snapshot
Diversity score
20.0
21 sources across 4 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
2
within the 30d window
Peak daily
2
highest bucket

Evidence

Source links by recency

Newest mentions first
25 source links · newest first
  • on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) explo

    newsthehackernews.comJul 20, 2026, 1:32 PM
  • 20th July – Threat Intelligence ReportCheck Point Research

    day, the largest monthly release recorded by the company. Two vulnerabilities were under active exploitation, including CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Both vulnerabilities could allow attackers to elevate privileges. Check Point IPS provides protection against these threats (Microsoft Sha

    vendorresearch.checkpoint.comJul 20, 2026, 12:18 PM
  • t families affected by July 2026 Patch Tuesday Exploited Zero-Day Vulnerability in Active Directory Federation Services CVE-2026-56155 is an Important elevation of privilege vulnerability affecting Active Directory Federation Services (AD FS) and has a CVSS score of 7.8 . An insufficient granularity of access control flaw (CWE-1220) allows a low-privil

    vendorwww.crowdstrike.comJul 17, 2026, 8:00 PM
  • s deployments. Key Takeaways CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence. Two additional SharePoint Server vulnerabilities disclosed

    vendorwww.tenable.comJul 16, 2026, 4:00 PM
  • Microsoft's July 2026 Patch Tuesday sets yet another record, fixing 622 Microsoft CVEs—three times as many as last month.

    newswww.malwarebytes.comJul 15, 2026, 12:21 PM
  • icrosoft shipped patches for a record 622 flaws , including two privilege escalation shortcomings in SharePoint Server (CVE-2026-56164, CVSS score: 5.3) and Active Directory Federation Services (CVE-2026-56155, CVSS score: 7.8) that have been flagged as actively exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both

    newsthehackernews.comJul 15, 2026, 11:07 AM
  • onicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog . The flaws added to the catalog are: CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient

    newssecurityaffairs.comJul 15, 2026, 10:49 AM
  • eased patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged by attackers (CVE-2026-56155 and CVE-2026-56164), and one that was previouly disclosed (CVE-2026-50661). The release was once again followed by Nightmare Eclipse publishing a stripped down proof-of-concept exploit for an unpatched Windows elevation

    newswww.helpnetsecurity.comJul 15, 2026, 10:20 AM
  • Microsoft Patches 570 CVEs in Record Patch TuesdayInfosecurity Magazine

    lnerabilities in July’s Patch Tuesday are three zero-day vulnerabilities; two of which have been exploited in the wild. CVE-2026-56155 is an elevation of privilege (EoP) vulnerability in Active Directory Federation Services which allows an authorized attacker to elevate privileges locally. “Eight other vulnerabilities are also published today in Active

    newswww.infosecurity-magazine.comJul 15, 2026, 9:20 AM
  • patched, including two that have been exploited in the wild. Those two are both elevation of privilege vulnerabilities: CVE-2026-56155, an Active Directory Federation Services (AD FS) flaw that allows attackers with limited access to elevate privileges to administrator, and CVE-2026-56164 , a Microsoft SharePoint Server vulnerability. The third is CVE-

    newswww.csoonline.comJul 15, 2026, 1:54 AM
  • ation of remediations as a trailing indicator. SharePoint: critical auth bypass by Rapid7 Today sees the publication of CVE-2026-55040 , a critical authentication bypass in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft, this vulnerability is the first i

    vendorwww.rapid7.comJul 14, 2026, 10:00 PM
  • urity updates" and continuous patching. High-Priority Vulnerabilities The immediate threats in this month's release are CVE-2026-56155 (CVSS: 7.2), an elevation of privilege (EoP) vulnerability in Microsoft Active Directory Federation Services that attackers can exploit to gain system level privileges; and CVE-2026-56164 (CVSS: 5.3), another EoP flaw,

    newswww.darkreading.comJul 14, 2026, 9:50 PM
  • this mess is anyone’s guess.” states the report published by ZDI. The following two bugs are being actively exploited: CVE-2026-56155 is an elevation of privilege flaw in Active Directory Federation Services. It requires local access and low privileges to start, which sounds like a limited threat until you remember that AD FS is identity infrastructur

    newssecurityaffairs.comJul 14, 2026, 9:33 PM
  • ication denial-of-service, and arbitrary code execution. Zero-day Vulnerabilities Patched in July Patch Tuesday Edition CVE-2026-56155: Active Directory Federation Services Elevation of Privilege Vulnerability Insufficient granularity of access control in Active Directory Federation Services (AD FS) could allow an authenticated attacker to elevate priv

    vendorblog.qualys.comJul 14, 2026, 9:23 PM
  • icrosoft’s massive month To start, let’s cover the pair of actively exploited issues that Microsoft patched. The first, CVE-2026-56155, is an Active Directory Federation Services elevation of privilege vulnerability. Attackers who exploit the issue, which Microsoft only described as being due to “insufficient granularity of access control on ADFS,” cou

    newswww.theregister.comJul 14, 2026, 8:49 PM
  • ed as "critical." Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild. CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileg

    vendorblog.talosintelligence.comJul 14, 2026, 8:27 PM
  • edits incident responders for both. Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Neither is one of the splashy remote code execution criticals. They are privilege bugs in two systems that matter more than th

    newsthehackernews.comJul 14, 2026, 8:25 PM
  • Microsoft Patches a Record 570 Security FlawsKrebs on Security

    Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

    newskrebsonsecurity.comJul 14, 2026, 7:22 PM
  • luding two bugs in Active Directory and SharePoint Server that have been exploited in the wild as zero-days. Tracked as CVE-2026-56155, the exploited AD flaw affects Federation Services (AD FS) and could allow attackers to elevate their privileges locally to administrator. Also leading to privilege escalation, the SharePoint Server flaw is tracked as C

    newswww.securityweek.comJul 14, 2026, 6:50 PM
  • of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 25.1%. Important CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege Vulnerability CVE-2026-56155 is an EoP vulnerability affecting Active Directory Federation Services. It received a CVSSv3 score of 7.8 and is rated important

    vendorwww.tenable.comJul 14, 2026, 6:23 PM
  • ile no official fix is available. The two actively exploited zero-days addressed during this month's Patch Tuesday are: CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability Microsoft has patched an actively exploited vulnerability in Active Directory Federation Services that grants administrative privileges. "Insuf

    newswww.bleepingcomputer.comJul 14, 2026, 6:01 PM
  • The July 2026 Security Update ReviewZero Day Initiative

    oser look at some of the more interesting updates for this month, starting with the bugs being exploited in the wild. - CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability This is one of several AD FS being patched this month, but it’s the only one being actively exploited. It stems from insufficient access-contro

    vendorwww.thezdi.comJul 14, 2026, 5:56 PM
  • No excerpt available.

    Mitigationwww.cisa.govJul 14, 2026, 5:17 PM
  • Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

    vendormsrc.microsoft.comJul 14, 2026, 2:00 PM
  • ur new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient

    governmentwww.cisa.govJul 14, 2026, 12:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence