CVE Tools

The cve.tools Blog

Product updates, the weekly threat signal, and monthly trends — what shipped, what's exploited, and where we're heading.

Follow CVE Pulse on Telegram
The 'local' AD FS bug that forges your cloud logins: CVE-2026-56155, exploited in the wild
vuln-breakdownmicrosoftadfs

The 'local' AD FS bug that forges your cloud logins: CVE-2026-56155, exploited in the wild

CVE-2026-56155 is an exploited AD FS elevation-of-privilege flaw. Its CVSS is a 'local' 7.8, but it lets a low-privileged attacker steal the token-signing key and forge identities across Microsoft 365 — the Golden SAML technique. Here's who's exposed, how the chain works, and how to fix it (patch, remediate the ACL, rotate keys) before the July 28 deadline.

Jul 17, 2026·12 min read