CISA deadline July 28 to patch actively exploited AD FS zero-day CVE-2026-56155 that allows token forgery and user impersonation
Organizations running Microsoft AD FS have one day left. CISA's deadline to patch CVE-2026-56155, an actively exploited flaw, is July 28. An attacker who reaches admin can forge tokens and impersonate any user across every connected service, no extra login needed.
Federal agencies in the US have until July 28, tomorrow, to patch a Microsoft Active Directory Federation Services vulnerability tracked as CVE-2026-56155, under a deadline set by the Cybersecurity and Infrastructure Security Agency's Binding Operational Directive 26-04. The flaw allows an attacker who gains administrator access to forge authentication tokens and impersonate any user across every service connected to that AD FS server, without needing another login step. Microsoft credited the discovery to its own Detection and Response Team, the internal unit that typically identifies vulnerabilities while responding to active intrusions rather than during routine testing, which suggests this flaw was already being exploited before a patch existed. Under BOD 26-04, agencies that cannot apply the patch by the deadline are required to stop using the affected product entirely, and separately must determine whether their systems were already compromised, not just close the vulnerability going forward. AD FS underpins single sign-on across a large share of US government and enterprise networks, so the practical exposure here extends well beyond the agencies directly bound by the CISA directive.