← Knowledge Center
Advisory CVE-2026-15409, CVE-2026-15410, CVE-2026-56155, CVE-2026-56164

CISA Adds AD FS and SharePoint Auth Flaws to KEV Amid Active Exploitation

CISA has added four vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Two are directly identity-relevant: CVE-2026-56155, an insufficient granularity of access control flaw in Microsoft Active Directory Federation Services (AD FS), and CVE-2026-56164, a missing-authentication-for-critical-function issue in Microsoft SharePoint Server. The remaining two (CVE-2026-15409 and CVE-2026-15410) affect SonicWall SMA1000 remote-access appliances, which sit at the edge of many identity perimeters.

The AD FS flaw is especially significant for identity teams because AD FS brokers federated authentication and token issuance across on-prem and cloud services; a weakness in its access-control granularity could let attackers escalate privileges or obtain access they should not have. SonicWall SMA gateways are also a recurring target for initial access and credential harvesting, so exploitation there can feed directly into broader identity compromise.

What to take away: prioritize patching AD FS and any exposed SharePoint and SMA1000 appliances now, and review AD FS token issuance, delegation, and access-control configurations for signs of abuse. Federal agencies are bound by BOD 26-04 to remediate rapidly, but the same urgency applies to any organization running these identity-adjacent systems.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.