ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-56155

CRITICAL Export PDF

Microsoft Active Directory Federation Services Vulnerability

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

CVSS Score
9.8
CRITICAL
Published
14 Jul 2026 00:00
Modified
N/A
Vendor
Microsoft
Product
Active Directory Federation Services
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-1220

Affected Systems

Microsoft
Active Directory Federation Services
Microsoft
Windows Ancillary Function Driver For WinSock
SharePoint
Active Directory Federation Services
SharePoint Server
Windows
DirectX
Internet Explorer
Defender
Microsoft
Office
Visual Basic For Applications (VBA)

KEV Status

Known Exploited Vulnerability