CVE-2026-56155 — Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
- CVSS
- 8.8 (High)
- KEV status
- CISA KEV — Listed
- First seen (CISA KEV)
- Recommended change window
- Emergency change — ADFS is a Tier-0 identity dependency; patch within the next weekend maintenance window with a full farm rollback plan.
- Affected products
- Microsoft Active Directory Federation Services
Why this one matters to a CAB
ADFS is a Tier-0 identity system in the classic Microsoft Enterprise Access Model — anything that touches ADFS touches every federated SaaS your organization uses. An elevation-of-privilege bug that only needs an authorized attacker is exactly the pivot point a password-spray or MFA-fatigue campaign has been waiting for.
Defender’s angle
- Tier-0 discipline: no Tier-0 change should ever be scheduled inside a normal Wednesday change window. Book a dedicated ADFS farm maintenance window with a proxy failover pre-tested.
- Detection: Microsoft 365 Defender’s “unusual ADFS trust
modification” alert must be enabled before the patch runs — you
want the pre-patch baseline. After patching, watch for anomalous
Microsoft.IdentityServer.Servicehost.exechild processes. - Migration lever: every ADFS CVE is another data point for the Azure AD / Entra ID direct-federation migration business case. Include a bullet in the change record noting whether this farm is slated for retirement, and by when.
What to bring to CAB
The ADFS farm topology diagram (primary + secondary + WAP proxies), the certificate rotation checklist that must accompany a farm restart, and the Entra ID break-glass account attestation.
Sources
This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.