logo

Microsoft Active Directory FS Privilege Escalation Flaw Exploited in Active Attacks

ID: 52e1e94b-ac71-58ee-9a12-7d8f0d9c3627

STIX ID: report--52e1e94b-ac71-58ee-9a12-7d8f0d9c3627

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Tamilselvan

...
...

Microsoft disclosed CVE-2026-56155, an actively exploited AD FS elevation-of-privilege vulnerability caused by insufficient DKM ACL granularity; exploitation yields administrator-level access and enables token forgery and lateral movement across federated environments. Microsoft released an audit mode to detect insecure DKM ACLs, an optional immediate remediation registry key, and will auto-remediate unconfigured systems after October 13, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.