CVE-2026-56155
Microsoft · Published July 14, 2026
7.8
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Affected Products
- Windows 10 1607 < 10.0.14393.9339
- Windows 10 1809 < 10.0.17763.9020
- Windows Server 2012
- Windows Server 2016 < 10.0.14393.9339
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H