DKM: The AD FS Master Key That Decrypts Your Token Signer
CVE-2026-56155 is an overly permissive ACL on the AD FS DKM container — the object holding the key that protects your token-signing certificate. The July patch ships the fix in audit mode, so read access to a Golden SAML enabler stays open until you flip a registry key or October arrives.