Windows Active Directory Federation Services Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-50304Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. Exploitation is assessed as unlikely. Apply the July 2026 security update.
What this means
What could happen
An attacker on your network could send crafted requests to Active Directory Federation Services (ADFS), causing it to crash and blocking all federated authentication. This prevents users from logging in to any systems that depend on ADFS for identity services.
Who's at risk
Organizations running Active Directory Federation Services on Windows Server 2016, 2019, 2022, or 2025 should prioritize this update. ADFS is critical infrastructure at utilities, water authorities, and any organization using federated identity for secure access control. Any interruption blocks user authentication across the enterprise.
How it could be exploited
An attacker reachable from the network sends specially crafted packets to the ADFS service port, triggering a buffer overflow in memory. The overflow crashes the service process, denying access to all authentication traffic until the service is manually restarted.
Prerequisites
- Network reachability to ADFS service port (typically 443 or 9200)
- No authentication required to trigger the vulnerability
remotely exploitableno authentication requiredaffects identity/access control systemslow complexity attack
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (53)
53 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/2WORKAROUNDRestrict network access to ADFS ports (443, 9200) to only authorized internal networks and partner federation servers
HARDENINGMonitor ADFS service logs and system event logs for unexpected crashes or service restarts
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply July 2026 Windows security update to Windows Server 2016, 2019, 2022, or 2025 hosting ADFS
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/16cf3adf-0aec-4454-ade8-8370add4209aGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.