Windows Active Directory Federation Services Denial of Service Vulnerability

MonitorCVSS 5.9CVE-2026-50324Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A loop condition in Active Directory Federation Services (AD FS) allows an unauthorized network attacker to send specially crafted requests that cause the service to enter an infinite loop, consuming resources and becoming unresponsive. This prevents legitimate users from authenticating and accessing federated resources. Exploitation is considered less likely but the impact on authentication availability is severe. Microsoft has released patches in the July 2026 security update for all affected Windows and .NET Framework versions.

What this means
What could happen
An attacker on the network can send specially crafted requests to Active Directory Federation Services, causing it to enter an infinite loop and become unresponsive, disrupting authentication and single sign-on services for your organization.
Who's at risk
Organizations operating Windows Server 2016, 2019, 2022, or 2025 with Active Directory Federation Services enabled, or Windows 10/11 client systems with AD FS components. Affects any organization using AD FS for single sign-on, identity federation, or multi-factor authentication.
How it could be exploited
An attacker sends malformed network requests to the AD FS service port. The service enters an infinite loop processing the request, consuming CPU and becoming unresponsive. No authentication is required; the attacker only needs network reachability to the AD FS server.
Prerequisites
  • Network access to AD FS service port (default port 443 or 80)
  • No authentication required
remotely exploitableno authentication requiredlow complexityaffects authentication infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (53)
53 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict network access to AD FS service ports (typically 443/HTTPS and 80/HTTP) to only authorized client networks and federated partners
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

HOTFIXApply July 2026 security update to Windows Server (2016, 2019, 2022, or 2025) and Windows 10/11 systems running AD FS
HOTFIXUpdate .NET Framework to patched version matching your Windows version (e.g., .NET 4.8 build 4.8.4803.0 or later, .NET 4.8.1 build 4.8.9339.0 or later)
HARDENINGMonitor AD FS service availability and CPU utilization for signs of denial of service attacks; configure alerts for high CPU on AD FS processes
API: /api/v1/advisories/b7256abc-66d8-49d5-91f2-805d414bc9c1

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Active Directory Federation Services Denial of Service Vulnerability | CVSS 5.9 - OTPulse