Is Your Organization at Risk? Microsoft Confirms Active Exploitation of a 0-Day Vulnerability in Active Directory Federation Services (AD FS)
As part of its July 2026 Patch Tuesday security updates, Microsoft has addressed a 0-day vulnerability in Active Directory Federation Services (AD FS), tracked as CVE-2026-56155. The most concerning aspect is that Microsoft has officially confirmed that this vulnerability is being actively exploited in real-world cyberattacks.
If successfully exploited, the vulnerability could allow an attacker with basic user-level access to the system to elevate their privileges to administrator level. As a result, it is considered a serious threat to corporate networks and identity infrastructure.
Active Directory Federation Services (AD FS) is Microsoft’s centralized authentication and federated identity service that enables users to access multiple corporate services through Single Sign-On (SSO) using a single authentication.
Because AD FS servers generate authentication tokens and validate user identities, they represent one of the most critical components of an organization’s identity infrastructure.
CVE-2026-56155 is caused by a flaw in the Access Control mechanism.
More specifically, insufficient permission validation within AD FS allows a user with limited privileges to perform operations beyond their intended authorization under certain conditions.
Microsoft has rated the vulnerability as Important, assigning it a CVSS score of 7.8.
To exploit this vulnerability, an attacker must:
If exploitation is successful, the attacker may be able to:
This could ultimately compromise the trustworthiness of the organization’s entire identity infrastructure.
Why Is This Vulnerability Particularly Dangerous?
AD FS servers process user authentication requests and generate security tokens that provide access to enterprise services.
This is an extract. The publication continues at the source.
Read the original at the source: https://uzcert.uz/en/is-your-organization-at-risk-microsoft-confirms-active-exploitation-of-a-0-day-vulnerability-in-active-directory-federation-services-ad-fs/
Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- UZCERT — imported from official source
- Official source
- https://uzcert.uz/en/feed/ RSS
- Imported
- October 03, 2026 20:40
- Versions
- 1 recorded
- Identity
https://uzcert.uz/?p=39210