Is Your Organization at Risk? Microsoft Confirms Active Exploitation of a 0-Day Vulnerability in Active Directory Federation Services (AD FS)

Imported from official source

Announcement

As part of its July 2026 Patch Tuesday security updates, Microsoft has addressed a 0-day vulnerability in Active Directory Federation Services (AD FS), tracked as CVE-2026-56155. The most concerning aspect is that Microsoft has officially confirmed that this vulnerability is being actively exploited in real-world cyberattacks.

If successfully exploited, the vulnerability could allow an attacker with basic user-level access to the system to elevate their privileges to administrator level. As a result, it is considered a serious threat to corporate networks and identity infrastructure.

Active Directory Federation Services (AD FS) is Microsoft’s centralized authentication and federated identity service that enables users to access multiple corporate services through Single Sign-On (SSO) using a single authentication.

  • Business platforms supporting federated authentication.
  • Because AD FS servers generate authentication tokens and validate user identities, they represent one of the most critical components of an organization’s identity infrastructure.

    CVE-2026-56155 is caused by a flaw in the Access Control mechanism.

    More specifically, insufficient permission validation within AD FS allows a user with limited privileges to perform operations beyond their intended authorization under certain conditions.

  • CWE-1220 – Insufficient Granularity of Access Control
  • Microsoft has rated the vulnerability as Important, assigning it a CVSS score of 7.8.

    To exploit this vulnerability, an attacker must:

  • possess at least standard local user privileges.
  • If exploitation is successful, the attacker may be able to:

  • use the compromised server as a pivot point to attack other parts of the corporate network.
  • This could ultimately compromise the trustworthiness of the organization’s entire identity infrastructure.

    Why Is This Vulnerability Particularly Dangerous?

    AD FS servers process user authentication requests and generate security tokens that provide access to enterprise services.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://uzcert.uz/en/is-your-organization-at-risk-microsoft-confirms-active-exploitation-of-a-0-day-vulnerability-in-active-directory-federation-services-ad-fs/

    Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    UZCERT — imported from official source
    Official source
    https://uzcert.uz/en/feed/ RSS
    Imported
    October 03, 2026 20:40
    Versions
    1 recorded
    Identity
    https://uzcert.uz/?p=39210

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.