Skip to main content

Active Directory Federation Services vulnerabilities

1 published alerts for Microsoft Active Directory Federation Services.

Actively exploited (KEV)

CVE-2026-56155

Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft Active Directory Federation Services is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-56155). Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. CISA remediation due date: 2026-07-28. If you need help checking exposure, call (864) 335-9223.