Code Defence Cyber security

CISA adds Microsoft AD FS privilege escalation zero day CVE-2026-56155 to KEV catalog

An actively exploited zero day privilege escalation vulnerability within a core directory single sign on framework has been formally added to the national registry of active internet threats. The defect enables local authenticated threat actors to bypass authorization checking libraries and claim absolute domain administrator rights.

Tracked within security registries as CVE-2026-56155, the flaw affects Active Directory Federation Services installations. The bug stems from an access control failure that fails to enforce granular privilege checking on local processes executing directory queries. If an attacker gains baseline, low privilege access to an AD FS server, they can execute specialized script strings to bypass the tenant boundaries, corrupt authentication checks, and elevate their credentials to domain administrator level.

Subverting a centralized identity federation controller compromises the trust boundaries of both local and cloud directory environments. Because federated identity servers manage single sign on parameters, user groups, and application access tokens, an administrative takeover lets threat networks forge trusted validation tokens, bypass multi factor authentication policies, and establish persistent backend entries into corporate cloud assets.

– Apply the July 2026 Patch Tuesday cumulative updates to all Active Directory Federation Services hosts immediately.

– Audit local system logging repositories to identify anomalous administrative creations or unrecognized security group adjustments.

– Restrict low privilege service profiles from executing shell processes or interacting with the core federation directory database.

– Enforce rigid risk based patching schedules matching federal operational directives to close exposure windows.

Identity perimeter stability relies on the continuous enforcement of least privilege policies over core authentication platforms to guarantee that centralized identity databases are completely protected from local elevation maneuvers. #CodeDefence #Microsoft #ADFS #PrivilegeEscalation #ZeroDay #PatchTuesday #IdentitySecurity #CISA #KEV
/

Scroll to Top