Windows Active Directory Federation Services Denial of Service Vulnerability
A loop condition in Active Directory Federation Services (AD FS) allows an unauthorized network attacker to send specially crafted requests that cause the service to enter an infinite loop, consuming resources and becoming unresponsive. This prevents legitimate users from authenticating and accessing federated resources. Exploitation is considered less likely but the impact on authentication availability is severe. Microsoft has released patches in the July 2026 security update for all affected Windows and .NET Framework versions.
- Network access to AD FS service port (default port 443 or 80)
- No authentication required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/b7256abc-66d8-49d5-91f2-805d414bc9c1Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.