Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Urgent Security Issue in Microsoft Active Directory Federation Services

A serious security weakness has been found in Microsoft’s Active Directory Federation Services (AD FS) that could let attackers gain higher access rights than they should have. This vulnerability is already being actively exploited, so it is important for organisations using this service to act quickly.

15 July 2026

Reference: CVE-2026-56155

1. What is being reported?

The report highlights a flaw in AD FS where the system does not properly control access permissions. This means someone who already has some access could exploit this weakness to increase their privileges on the local system, potentially gaining control over sensitive information or systems.

2. What this means in plain English

For a small organisation, this means if you use AD FS to manage user access and authentication, an attacker who manages to get inside your network could take advantage of this flaw to access more data or systems than they should. This could lead to data breaches or disruption of your IT services.

3. Could this affect a small business?

Small businesses or charities that use Microsoft Active Directory Federation Services could be affected, especially if AD FS is exposed to the internet or used to manage critical access. Organisations not using AD FS or those with limited internal access controls are less likely to be impacted.

4. What to do now

  • Check with your IT provider or software supplier if your systems use Microsoft Active Directory Federation Services.
  • Apply any security updates or patches provided by Microsoft immediately following their instructions.
  • Review your AD FS setup to ensure it is not unnecessarily exposed to the internet and access controls are properly configured.
  • Follow any additional guidance from your IT provider about mitigating this vulnerability and monitoring for suspicious activity.

5. Ask your IT provider

Can you confirm if our systems use Microsoft Active Directory Federation Services and what steps are being taken to protect us from the CVE-2026-56155 vulnerability?

6. Bottom line

If you use Microsoft AD FS, act quickly to apply security updates and reduce exposure to prevent attackers from gaining higher access.

Information based on CISA KEV, NVD and reputable security reporting.

Back to Vulnerability Briefs