• CISA KEV
  • EXPLOITED
  • PATCH AVAILABLE

CVE-2026-56155: local privilege escalation in Microsoft Active Directory Federation Services

An authenticated local user can elevate privileges on Active Directory Federation Services (AD FS); this is tracked as CVE-2026-56155. Affected builds include Windows 10 1607/1809 branches and Windows Server 2012/2012 R2/2016/2019 branches in the version ranges listed by the vendor; fixed builds are provided. The vulnerability requires local access with some privileges (not a remote network exploit) and does not require user interaction.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00346
CWE
CWE-1220
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a remediation due date of 2026-07-28, so prioritize patching AD FS servers or applying vendor mitigations immediately.

What is CVE-2026-56155?

An authenticated local user can elevate privileges on Active Directory Federation Services (AD FS); this is tracked as CVE-2026-56155. Affected builds include Windows 10 1607/1809 branches and Windows Server 2012/2012 R2/2016/2019 branches in the version ranges listed by the vendor; fixed builds are provided. The vulnerability requires local access with some privileges (not a remote network exploit) and does not require user interaction.

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Active Directory Federation Services are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.933910.0.14393.9339
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.232916.3.9600.23291
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.232916.3.9600.23291
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.933910.0.14393.9339
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.933910.0.14393.9339
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020

Is CVE-2026-56155 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-14, and U.S. federal agencies were required to remediate it by 2026-07-28.

How to fix CVE-2026-56155

  1. Apply the vendor-provided updates to the fixed builds listed for your branch (for example 10.0.14393.9339, 10.0.17763.9020, 6.2.9200.26226, 6.3.9600.23291).
  2. Inventory and prioritize all internet-facing and domain-joined AD FS servers for immediate update.
  3. If you cannot patch immediately, restrict local administrative access to AD FS hosts and monitor logs for anomalous privilege escalation activity.
  4. Follow vendor guidance and CISA’s mitigation instructions where applicable.

Frequently asked questions

Is CVE-2026-56155 being actively exploited?

CISA added CVE-2026-56155 to its Known Exploited Vulnerabilities catalog on 2026-07-14, with a remediation due date of 2026-07-28 for federal agencies.

Which Active Directory Federation Services versions are affected by CVE-2026-56155?

AD FS is affected on the listed Windows branches and build ranges: Windows 10 Version 1607 (10.0.14393.0–before 10.0.14393.9339), Windows 10 Version 1809 (10.0.17763.0–before 10.0.17763.9020), Windows Server 2012 (6.2.9200.0–before 6.2.9200.26226), Windows Server 2012 R2 (6.3.9600.0–before 6.3.9600.23291), and corresponding Server Core and later Windows Server branches as listed by the vendor.

Is there a patch for CVE-2026-56155?

Yes; Microsoft published fixes with specific build numbers for each affected branch (for example 10.0.14393.9339, 10.0.17763.9020, 6.2.9200.26226, 6.3.9600.23291).

Does CVE-2026-56155 require authentication?

Yes; the issue requires an authorized local attacker on the AD FS host to perform a privilege elevation, it is not a remote unauthenticated network exploit.

References