CVE-2026-56155CISA KEVEPSS p25.9%

CVE-2026-56155Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft / Active Directory Federation Services

Description

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

Scoring

CVSS 7.8 ()
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.35% probability of exploitation · percentile 25.9% · 2026-10-05T12:00:23Z
Last modified2026-07-15

CISA KEV entry

Added to KEV: 2026-07-14

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.