logo

Active Exploitation of Microsoft AD FS Vulnerability CVE-2026-56155 Detected

ID: 15fcefd0-e381-50bb-972b-824b13264f25

STIX ID: report--15fcefd0-e381-50bb-972b-824b13264f25

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

...
...

Microsoft confirmed active exploitation of CVE-2026-56155, an authenticated local elevation-of-privilege flaw in Active Directory Federation Services that can allow low-privilege users to gain administrator access; CVE-2026-56164 has also been observed with a proof-of-concept. Organizations are urged to apply Microsoft’s security updates (part of a batch fixing 622 vulnerabilities) and to retire or upgrade unsupported SharePoint Server 2016/2019 instances to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.