CISA has added four vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Two are directly identity-relevant: CVE-2026-56155, an insufficient granularity of access control flaw in Microsoft Active Directory Federation Services (AD FS), and CVE-2026-56164, a missing-authentication-for-critical-function issue in Microsoft SharePoint Server. The remaining two (CVE-2026-15409 and CVE-2026-15410) affect SonicWall SMA1000 remote-access appliances, which sit at the edge of many identity perimeters.
The AD FS flaw is especially significant for identity teams because AD FS brokers federated authentication and token issuance across on-prem and cloud services; a weakness in its access-control granularity could let attackers escalate privileges or obtain access they should not have. SonicWall SMA gateways are also a recurring target for initial access and credential harvesting, so exploitation there can feed directly into broader identity compromise.
What to take away: prioritize patching AD FS and any exposed SharePoint and SMA1000 appliances now, and review AD FS token issuance, delegation, and access-control configurations for signs of abuse. Federal agencies are bound by BOD 26-04 to remediate rapidly, but the same urgency applies to any organization running these identity-adjacent systems.