CVE-2026-56155: Microsoft AD FS Access Control Flaw Enables Golden SAML Attacks
ID: a18e5d6f-7063-5994-b69e-baa24328bf18
STIX ID: report--a18e5d6f-7063-5994-b69e-baa24328bf18
Feed Name: CosmicBytez Labs
A high-severity AD FS DKM ACL vulnerability (CVE-2026-56155, CVSS 7.8) is being actively exploited to enable Golden SAML attacks that allow attackers to extract token-signing keys, forge SAML assertions (bypassing MFA), and gain broad access to hybrid Azure AD and SaaS resources; Microsoft released a patch on July 8, 2026, CISA added the CVE to the KEV catalog on July 14, 2026, and recommended mitigations include applying the July updates, auditing and tightening DKM ACLs, and rotating AD FS certificates if compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
