Finding
indicator:216575:descriptionWhat happened
CISA KEV describes CVE-2026-56155 as: Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.