CVE-2026-56155: The Actively Exploited AD FS Flaw That Hands Over Your Identity Keys
CVE-2026-56155 is an actively exploited AD FS flaw exposing token-signing keys — why patching alone isn't enough, and today's CISA deadline.
On July 28, 2026, the deadline passed to fix a security flaw in Microsoft's Active Directory Federation Services (AD FS) known as CVE-2026-56155. This vulnerability, added to the Known Exploited Vulnerabilities (KEV) catalog by CISA on July 14, exposes private cryptographic keys used by AD FS to sign and encrypt tokens that prove user identities. An attacker who gains access to these keys does not need to steal passwords or bypass multi-factor authentication; they can create trusted identities at will.
AD FS is a component many enterprises use to federate identity, allowing employees to sign in once and access applications, including cloud services, using tokens issued by AD FS. The security of this system relies on private token-signing and token-encryption keys stored in a Distributed Key Manager (DKM) container within Active Directory. CVE-2026-56155 is caused by insufficient access control on this container, allowing low-privileged but authorized accounts to access key material they should not be able to read.
Microsoft has classified the vulnerability as Important, warning of high impact to confidentiality, integrity, and availability. The flaw allows a local attacker to elevate their access and forge authentication tokens, enabling them to access email, file storage, and administrative consoles without triggering normal login or MFA prompts. These forged tokens appear genuine to downstream applications and platforms.
Simply applying the security patch released in July 2026 is not enough to fully address the vulnerability, as the update only hardens the access-control model and does not automatically correct an already-insecure DKM configuration. Organizations must manually adjust the permissions on the DKM container to prevent further exposure. Additionally, if an attacker exploited the flaw before the patch was applied, the stolen signing keys remain valid until rotated.
This vulnerability highlights the growing trend of attackers targeting identity infrastructure rather than individual accounts. Compromising the machinery that issues trust, such as AD FS, federation servers, certificate authorities, and directory services, can undermine all authentication decisions that depend on them. To mitigate this risk, organizations should apply the July updates, tighten the DKM container ACLs, rotate AD FS token-signing and token-encryption certificates, and review authentication logs for anomalies indicating forged tokens.
Ultimately, this incident emphasizes the importance of protecting identity infrastructure as tier-zero assets in the environment, given the potential impact on trust in authentication decisions.
Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.