Safeguard
Vulnerability Analysis

Four Microsoft CVEs Describe a Complete Access-to-Domain-Control Chain

One unauthenticated RCE and three local privilege-escalation bugs across Windows and Active Directory Federation Services, confirmed exploited between July and September 2026.

Safeguard Research Team
4 min read

Microsoft had four vulnerabilities across Windows and Active Directory Federation Services confirmed exploited between mid-July and early September 2026 — three local privilege-escalation bugs and one unauthenticated remote code execution vulnerability, together describing a fuller attack chain than any single CVE does alone.

CVE-2026-33824, CVSS 9.8, added 18 August, is a double-free in the Windows IKE Extension allowing an unauthorized attacker to execute code over a network — the only one of the four requiring no prior access at all. CVE-2026-56155, CVSS 7.8, added 14 July, is insufficient access-control granularity in Active Directory Federation Services allowing an authorized attacker to elevate privileges locally. CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8 and both added 8 September, are improper link resolution in the Windows Update Stack and a heap-based buffer overflow in Windows ALPC, respectively — both local privilege escalations requiring an authorized starting point.

Reading the four as stages, not four unrelated bugs

Three of the four CVEs need "an authorized attacker" — some form of existing access — to trigger. Only CVE-2026-33824 needs nothing. That single fact describes a plausible, common attack pattern precisely: gain initial access through any means (phishing, a separate remote vulnerability, or CVE-2026-33824 itself, since a network-based double-free reaching code execution is itself an initial-access vector), then use one of the three local privilege-escalation bugs to move from a limited foothold to full system or domain control.

CVE-2026-56155's placement in ADFS specifically raises the stakes of that chain. Federation services sit at the identity layer — the infrastructure that establishes trust between an organisation's directory and every application relying on it for authentication. A privilege-escalation bug there is not confined to one machine's local account structure; it potentially reaches the trust relationships an entire organisation's single sign-on depends on.

Why "authorized attacker" doesn't mean low priority

CVSS's requirement for prior privileges lowers a score, but it does not describe a rare precondition. Phishing, credential-stuffing against low-privilege accounts, and social engineering all reliably produce exactly the kind of limited, authorized foothold these three escalation bugs need. The realistic threat model for most organisations already assumes some accounts will be compromised at a low privilege level; these CVEs are what an attacker uses next.

Why endpoint privilege escalation deserves the same urgency as remote code execution

Vulnerability programmes commonly rank remote, unauthenticated code execution above local privilege escalation in urgency, on the reasoning that the former needs no prior access while the latter does. That ranking makes sense in isolation but breaks down once you account for how real intrusions actually proceed: an attacker rarely achieves full compromise through one vulnerability alone. Initial access — through phishing, a purchased credential, or a separate lower-severity bug — is typically cheap and reliable to obtain; what determines the ultimate damage is whether a local privilege-escalation path exists to convert that initial foothold into full control. Three of these four CVEs are exactly that conversion mechanism, which is why deprioritising them relative to the fourth, purely remote bug, understates their practical role in a complete attack.

What to check this week

Patch CVE-2026-33824 with particular urgency — it is the only one of the four an attacker can trigger without any existing access, and a CVSS 9.8 double-free reaching remote code execution deserves emergency-patch treatment on that basis alone.

Review ADFS access-control configuration specifically, since CVE-2026-56155's flaw is insufficient granularity — a design-level gap rather than a simple missing check, which may mean the fix requires configuration review beyond just applying the patch.

Treat the three escalation bugs as a reason to tighten what a low-privilege compromise can reach, not just a reason to patch. Assume some accounts are already compromised at low privilege, and ask what these three CVEs would let that access become.

How Safeguard helps

Safeguard's continuous inventory tracks identity infrastructure like ADFS with the same rigor as internet-facing services, because — as this cluster demonstrates — privilege-escalation bugs in identity and federation systems are frequently the pivot point that turns a contained, low-privilege compromise into full domain access. Reachability analysis helps confirm which of these four CVEs' preconditions are actually satisfiable in a given environment, rather than treating "requires authorization" as synonymous with "low risk."

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.