Windows Active Directory Federation Services Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-50355Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to cause a denial of service over the network. The vulnerability exists in how ADFS processes certain network requests, causing the service to crash or become unresponsive.

What this means
What could happen
An attacker on your network could crash the Active Directory Federation Services, making single sign-on and identity authentication unavailable for users and potentially affecting any systems that rely on ADFS for access control.
Who's at risk
Windows IT administrators and facilities managing Active Directory Federation Services for single sign-on and user authentication. This includes mid-size utilities and municipalities running Windows Server 2016, 2019, 2022, or 2025 with ADFS configured, as well as Windows 10 and 11 clients if ADFS is deployed on them. If your organization uses ADFS to manage login credentials for OT operator workstations or engineering access, this is a priority concern.
How it could be exploited
An attacker sends a specially crafted network request to the ADFS service. The malformed input triggers a buffer overflow in the request processing code, causing ADFS to crash or hang. The attacker does not need credentials or special system access—only network connectivity to the ADFS server.
Prerequisites
  • Network access to the ADFS service port (typically 443/HTTPS on port 443 or custom ports)
  • No authentication required
remotely exploitableno authentication requiredlow complexityaffects identity and access control
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (53)
53 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Do now
0/2
WORKAROUNDRestrict network access to the ADFS service port to authorized administrative and user access only using firewall rules; block access from untrusted networks and segments
HARDENINGMonitor ADFS service logs and Windows Event Viewer for unexpected crashes or service restarts, which may indicate exploitation attempts
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Microsoft security update to all affected Windows Server and Windows 10/11 systems running Active Directory Federation Services
API: /api/v1/advisories/16c03ccd-8f13-4eb7-83fd-8834ecdf44ab

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Active Directory Federation Services Denial of Service Vulnerability | CVSS 7.5 - OTPulse