THREATOPS
THREAT OPSCVEs › CVE-2026-56155

CVE-2026-56155 — Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

CISA KEVExploited: confirmedMicrosoft

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

Vulnerability details

Exploiting threat actors

Related reporting