Skip to main content
Change Risk Intel

CVE-2026-56155 — Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

CVSS
8.8 (High)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Emergency change — ADFS is a Tier-0 identity dependency; patch within the next weekend maintenance window with a full farm rollback plan.
Affected products
Microsoft Active Directory Federation Services

Why this one matters to a CAB

ADFS is a Tier-0 identity system in the classic Microsoft Enterprise Access Model — anything that touches ADFS touches every federated SaaS your organization uses. An elevation-of-privilege bug that only needs an authorized attacker is exactly the pivot point a password-spray or MFA-fatigue campaign has been waiting for.

Defender’s angle

  • Tier-0 discipline: no Tier-0 change should ever be scheduled inside a normal Wednesday change window. Book a dedicated ADFS farm maintenance window with a proxy failover pre-tested.
  • Detection: Microsoft 365 Defender’s “unusual ADFS trust modification” alert must be enabled before the patch runs — you want the pre-patch baseline. After patching, watch for anomalous Microsoft.IdentityServer.Servicehost.exe child processes.
  • Migration lever: every ADFS CVE is another data point for the Azure AD / Entra ID direct-federation migration business case. Include a bullet in the change record noting whether this farm is slated for retirement, and by when.

What to bring to CAB

The ADFS farm topology diagram (primary + secondary + WAP proxies), the certificate rotation checklist that must accompany a farm restart, and the Entra ID break-glass account attestation.

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.