HIGHVulnerability
Verified
Global

CISA KEV: Microsoft Active Directory Federation Services — Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

Analysis

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. Added to CISA Known Exploited Vulnerabilities catalog on 2026-07-14. Remediation due: 2026-07-28.

Indicators of Compromise (1)

CVE (1)
CVE-2026-56155
Source Attribution

Originally published by CISA KEV on Jul 14, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

Overview On July 17, 2026, a GitHub Security Advisory was published for CVE-2026-63030 , a critical unauthenticated remote code execution vulnerability affecting WordPress Core . WordPress Core. While the official GitHub security advisory classifies the severity as Critical, the vulnerability has currently been assigned a CVSS score of 7.5. WordPress is one of the most widely deployed content mana

CVE-2026-63030
Rapid7
MEDIUMVulnerability

AI Takes On the Cyclospora Outbreak

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/how-ai-aiding-in-nasty-cyclospora-outbreak-image_small-7-a-32261.jpg" align=right hspace=4><b>Labs Use AI to Speed Testing as Experts Explore Broader Public Health Potential</b><br>It's been the most explosive U.S. public health crisis so far this summer: An outbreak of extreme intestinal illness caused by Cyclospora is sickening

Bank Info Security
MEDIUMVulnerability

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system. Adam Kues at Assetnote, Searchlight Cyber's attack surface management arm, found the flaw and reported

The Hacker News