The US Cybersecurity and Infrastructure Security Agency added CVE-2026-56155 to its Known Exploited Vulnerabilities catalogue on July 14, 2026, the same day Microsoft shipped a fix as part of its July Patch Tuesday. CISA’s remediation deadline is today, July 28. The flaw sits in Active Directory Federation Services, the Microsoft component that handles federated single sign-on for a large share of enterprises running hybrid identity, and stems from insufficient granularity in its access controls. Microsoft rates it Important with a CVSS 3.1 score of 7.8, but has confirmed exploitation in the wild, and researchers have already published functional exploit code.
Why a 7.8 matters more than the number suggests
On its own, CVE-2026-56155 requires an attacker to already have authenticated access to a networked host, which is why it did not draw the same immediate panic as a pre-auth remote code execution bug. But security researchers have laid out the chain it enables: an attacker who achieves code execution anywhere on the network, through phishing, another vulnerability, or stolen credentials, can pivot to the AD FS server, exploit this access control gap to escalate to administrator, and from that position forge authentication tokens across the entire federated identity estate. That last step is what makes this dangerous well beyond the single host it starts on. AD FS tokens are trusted by every application and service that relies on that federation, so administrator access there does not stay contained. It becomes a master key.
The deadline is a floor, not a target
CISA’s KEV deadlines apply directly to US federal agencies, but they function as the industry’s de facto minimum bar for actively exploited flaws, and European organisations running AD FS for hybrid Microsoft 365 or Azure AD identity are just as exposed to the underlying chain regardless of which regulator’s deadline applies to them. Two weeks between patch release and today’s deadline is not generous for an identity component that many organisations are understandably cautious about touching, given how much federated authentication depends on it working correctly. That caution is exactly what attackers are counting on. A flaw already tied to a documented ransomware delivery path, with public exploit code available, is not one where “we will get to it during the next maintenance window” is still a defensible position.
If your organisation runs Active Directory Federation Services and needs help verifying this patch is deployed, auditing your identity infrastructure for the access control gaps this vulnerability class exploits, or building a faster path from CISA KEV advisory to production patch, contact Excello Digital. We help European enterprises secure the identity infrastructure that everything else in their environment ultimately trusts.
