All stories
highExploited VulnerabilitiesCVE-2026-56155

Authorized users can escalate local privileges via Microsoft Active Directory Federation Services vulnerability

An elevation of privilege vulnerability in Microsoft Active Directory Federation Services (AD FS) allows authorized users to gain higher privileges on local systems. This flaw is part of a massive July 2026 update cycle containing hundreds of vulnerabilities. Patch your AD FS instances immediately to prevent local privilege escalation.

Summary

Microsoft's July 2026 security update includes a high-severity elevation of privilege vulnerability affecting Active Directory Federation Services (AD FS). The flaw, identified as CVE-2026-56155, stems from insufficient granularity in access control mechanisms. An attacker who already has authorized access to a system can exploit this weakness to elevate their privileges locally.

This disclosure arrives alongside a significant volume of security updates; Microsoft released 622 vulnerabilities this month, including 57 classified as critical. Among these critical entries are 48 remote code execution (RCE) vulnerabilities and seven elevation of privilege (EoP) vulnerabilities affecting various Windows services, applications, and cloud platforms.

Technical Details

The vulnerability in AD FS (CVE-2026-56155) is characterized by a lack of granular access control. While the specific technical mechanism for the escalation is not fully detailed in public advisories, the impact allows an authorized attacker to move from a standard user context to a higher privilege level on the local machine.

The vulnerability affects Windows 10 Version 1607. Because it requires an authorized attacker to be present on the system first, the attack vector is categorized as local.

Exploitation Status

CISA has listed CVE-2026-56155 in its Known Exploited Vulnerabilities (KEV) catalog as of July 14, 2026. While Microsoft's monthly update notes that two vulnerabilities from this cycle have been exploited in the wild, they do not explicitly link this specific AD FS flaw to any particular threat actor or campaign.

Detection Opportunities

Cisco Talos has released Snort rules to detect exploitation attempts related to several vulnerabilities within this July update cycle. For organizations running Cisco Security Firewalls, updating the Snort ruleset via the latest SRU provides protection against many of these threats.

The following Snort 2 rules are included in the current release:

1:66733 - 1:66743
1:66745 - 1:66785
1:66791 - 1:66793
1:66800 - 1:66807

For those using Snort 3, the following rules are available:

1:301555 - 1:301579
1:301581 - 1:301583

Defender Guidance

Prioritize patching AD FS environments to mitigate the risk of local privilege escalation. Because this vulnerability is listed in the CISA KEV, it should be treated as a high-priority remediation task.

Review your Windows 10 Version 1607 deployments and ensure that all Microsoft security updates from the July 2026 cycle are applied. Beyond AD FS, monitor for other critical vulnerabilities disclosed this month that target high-value services such as:

  • Windows DHCP Server (CVE-2026-50370, CVE-2026-50518)
  • Microsoft SharePoint (CVE-2026-50522, CVE-2026-50655)
  • Microsoft Office and its components (Word, Excel, PowerPoint)

Sources

  1. https://blog.talosintelligence.com/microsoft-patch-tuesday-july-2026/
  2. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155
  3. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
  4. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50370
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -