DIRAS TAKE
Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a remediation due date of 2026-07-28, so prioritize patching AD FS servers or applying vendor mitigations immediately.
What is CVE-2026-56155?
An authenticated local user can elevate privileges on Active Directory Federation Services (AD FS); this is tracked as CVE-2026-56155. Affected builds include Windows 10 1607/1809 branches and Windows Server 2012/2012 R2/2016/2019 branches in the version ranges listed by the vendor; fixed builds are provided. The vulnerability requires local access with some privileges (not a remote network exploit) and does not require user interaction.
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Active Directory Federation Services are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26226 | 6.2.9200.26226 |
| Windows Server 2012 (Server Core installation) 6.x | 6.2.9200.0 – before 6.2.9200.26226 | 6.2.9200.26226 |
| Windows Server 2012 R2 6.x | 6.3.9600.0 – before 6.3.9600.23291 | 6.3.9600.23291 |
| Windows Server 2012 R2 (Server Core installation) 6.x | 6.3.9600.0 – before 6.3.9600.23291 | 6.3.9600.23291 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows Server 2016 (Server Core installation) 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows Server 2019 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows Server 2019 (Server Core installation) 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
Is CVE-2026-56155 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-14, and U.S. federal agencies were required to remediate it by 2026-07-28.
How to fix CVE-2026-56155
- Apply the vendor-provided updates to the fixed builds listed for your branch (for example 10.0.14393.9339, 10.0.17763.9020, 6.2.9200.26226, 6.3.9600.23291).
- Inventory and prioritize all internet-facing and domain-joined AD FS servers for immediate update.
- If you cannot patch immediately, restrict local administrative access to AD FS hosts and monitor logs for anomalous privilege escalation activity.
- Follow vendor guidance and CISA’s mitigation instructions where applicable.
Frequently asked questions
Is CVE-2026-56155 being actively exploited?
CISA added CVE-2026-56155 to its Known Exploited Vulnerabilities catalog on 2026-07-14, with a remediation due date of 2026-07-28 for federal agencies.
Which Active Directory Federation Services versions are affected by CVE-2026-56155?
AD FS is affected on the listed Windows branches and build ranges: Windows 10 Version 1607 (10.0.14393.0–before 10.0.14393.9339), Windows 10 Version 1809 (10.0.17763.0–before 10.0.17763.9020), Windows Server 2012 (6.2.9200.0–before 6.2.9200.26226), Windows Server 2012 R2 (6.3.9600.0–before 6.3.9600.23291), and corresponding Server Core and later Windows Server branches as listed by the vendor.
Is there a patch for CVE-2026-56155?
Yes; Microsoft published fixes with specific build numbers for each affected branch (for example 10.0.14393.9339, 10.0.17763.9020, 6.2.9200.26226, 6.3.9600.23291).
Does CVE-2026-56155 require authentication?
Yes; the issue requires an authorized local attacker on the AD FS host to perform a privilege elevation, it is not a remote unauthenticated network exploit.
References
- nvd.nist.gov/vuln/detail/CVE-2026-56155
- cve.org/CVERecord?id=CVE-2026-56155
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56155
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026