Active Exploitation of Microsoft AD FS Vulnerability CVE-2026-56155 Detected
ID: 15fcefd0-e381-50bb-972b-824b13264f25
STIX ID: report--15fcefd0-e381-50bb-972b-824b13264f25
Feed Name: ThreatCluster
Threat Score
Microsoft confirmed active exploitation of CVE-2026-56155, an authenticated local elevation-of-privilege flaw in Active Directory Federation Services that can allow low-privilege users to gain administrator access; CVE-2026-56164 has also been observed with a proof-of-concept. Organizations are urged to apply Microsoft’s security updates (part of a batch fixing 622 vulnerabilities) and to retire or upgrade unsupported SharePoint Server 2016/2019 instances to reduce exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
