Skip to content
Rush Commerce
Field Notes3 min read

AD FS zero-day CVE-2026-56155: patch your login layer

CISA gave federal agencies until July 28 to fix an actively exploited AD FS zero-day. If you still run federated sign-on, this is your identity layer.

Most security news is noise you can safely skip. This one isn't. There's an actively exploited zero-day in Active Directory Federation Services — the box that issues sign-on tokens for every app hooked to your Windows domain — and the federal remediation deadline is July 28. If you're still running AD FS on-prem, the patch has been out for a week and the clock is public.

What actually happened

CVE-2026-56155 is an insufficient-granularity-of-access-control flaw in AD FS that lets an already-authorized attacker escalate privileges locally. It carries a CVSS 3.1 base score of 7.8, published July 14, affecting AD FS on Windows Server 2012 through 2019. Microsoft shipped the fix in its July 14 security updates, and CISA added the CVE to the Known Exploited Vulnerabilities catalog the same day with a remediation deadline of July 28, 2026.

Two details make this worse than the score suggests. First, it was reported as exploited before a patch existed — a real zero-day, not a theoretical finding. Second, per The Hacker News, it landed alongside a separately exploited SharePoint zero-day in what was Microsoft's largest Patch Tuesday on record. The severity math on AD FS specifically is about what the box holds, not the CVSS vector: a federation server owns the token-signing certificate that proves user identity to every downstream application. Local admin on that machine is not "one server compromised." It's the ability to mint identities.

Why it matters for your business

The mental model to correct: patching your login layer is not the same class of chore as patching a laptop. Identity infrastructure is the one system where a single compromise invalidates every other control you've bought. Your MFA, your conditional access rules, your per-app permissions — all of it assumes the token issuer is honest.

Three things to do this week. One: find out whether you actually run AD FS. Plenty of small companies inherited it from a managed-services provider years ago and never touched it — if it's on Server 2012 or 2012 R2, you have a bigger problem than this CVE, because those platforms are long past mainstream support. Two: apply the July 14 updates and confirm the build number, don't just trust that "updates are automatic." Three: if you're already fully on Entra ID or another cloud identity provider and that AD FS server is a leftover nobody logs into, decommission it. Dormant infrastructure that still issues tokens is the definition of unmanaged risk. The general rule holds beyond this CVE: patch the systems that grant access before you patch the systems that use it.

Key takeaways

  • CVE-2026-56155 is an actively exploited AD FS privilege-escalation zero-day, CVSS 7.8, patched in Microsoft's July 14 updates
  • CISA added it to the KEV catalog on July 14 with a federal remediation deadline of July 28, 2026
  • AD FS holds the token-signing certificate for every federated app — compromise there undermines MFA and per-app permissions alike
  • Confirm whether you still run AD FS, verify the patched build number, and decommission leftover federation servers you no longer use

Not sure what's still running in your stack? We map the systems that grant access, kill the dormant ones, and put patching on a schedule that doesn't depend on someone remembering. See how we harden small-business infrastructure or book an audit.

Sources: NVD, The Hacker News, CISA KEV catalog.

  • #cve-2026-56155
  • #active-directory
  • #adfs
  • #cisa-kev
  • #patch-management
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.