Microsoft Active Directory FS Privilege Escalation Flaw Exploited in Active Attacks
ID: 52e1e94b-ac71-58ee-9a12-7d8f0d9c3627
STIX ID: report--52e1e94b-ac71-58ee-9a12-7d8f0d9c3627
Feed Name: Cyber Press
Threat Score
Microsoft disclosed CVE-2026-56155, an actively exploited AD FS elevation-of-privilege vulnerability caused by insufficient DKM ACL granularity; exploitation yields administrator-level access and enables token forgery and lateral movement across federated environments. Microsoft released an audit mode to detect insecure DKM ACLs, an optional immediate remediation registry key, and will auto-remediate unconfigured systems after October 13, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
