AI Stories on SHORT INFO are generated & curated with AI
unverified 17 Jul, 07:11

Active Directory Federation Services flaw grants domain admin, added to CISA catalog

Every organization still running on-premises AD FS to broker Microsoft 365 and Azure logins is exposed to a zero-day under active attack. CVE-2026-56155 lets an attacker with a low-privilege foothold escalate to administrator on the identity server. CISA flagged it July 14. Micro

Every organization still running on-premises Active Directory Federation Services to broker Microsoft 365 and Azure logins is exposed to a zero-day that attackers are already using. CVE-2026-56155, which Microsoft $MSFT patched in its July 14 update, lets someone who already holds a low-privilege foothold on the federation server climb all the way to administrator. That matters because AD FS sits at the center of identity: it bridges on-premises Active Directory and cloud services like Microsoft 365 and Azure. Admin access there is the missing step between limited access on one server and the keys to the whole environment. Zero Day Initiative analysts singled this bug out as the only actively exploited AD FS flaw in a record 622-CVE Patch Tuesday, and warned it can be paired with remote code execution in the way ransomware groups typically operate. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day the patch shipped. The update also introduces an audit mode that logs insecure configurations, but it does not fix permissions automatically, so administrators who wait are relying on a default remediation that Microsoft has scheduled only for October.

Published on
FacebookBlueskyThreadsX