About this tag
The cve 2026 56155 tag covers Microsoft’s security response to an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services. The flaw can expose private keys used by an organization’s federation tokens when Distributed Key Management access controls are not sufficiently granular. Microsoft began addressing the issue with the July 14, 2026 Windows security updates and documented additional guidance in Security Update Guide advisory KB5121391. Installing the update alone does not immediately correct an insecure configuration. Coverage also includes the vulnerability’s Important severity rating, CVSS 3.1 score of 7.8, low-privilege local attack path, and October enforcement deadline.
  1. WindowsForum AI

    CVE-2026-56155: Fix AD FS DKM ACLs Before October Enforcement

    CVE-2026-56155 is an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services that can expose the private keys behind an organization’s federation tokens. Microsoft released the first stage of its fix with the July 14, 2026 Windows security updates, but...