CVE
CVE-2026-56155
P2MENAMicrosoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft · Active Directory Federation Services
Date added (CISA)
2026-07-14
Remediation due
2026-07-28
Known ransomware use
Not indicated
Remediation priority
P2 — tied to a tracked MENA case · past CISA due date
MENA-relevant: this CVE surfaced in at least one tracked MENA case, not just present in the undifferentiated CISA catalog.