Windows Active Directory Federation Services Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-50368Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Stack-based buffer overflow in Active Directory Federation Services on Windows Server 2016, 2019, 2022, 2025, and Windows 10/11 with .NET Framework 3.5, 4.7.2, 4.8, and 4.8.1. An unauthorized attacker can send a specially crafted network request to crash the AD FS service, causing denial of service. No credentials or user interaction required.
What this means
What could happen
A stack-based buffer overflow in Active Directory Federation Services can be exploited remotely to crash the service, making it unavailable to users and stopping authentication for federated systems. If AD FS is critical to your identity infrastructure, this denial of service could disrupt network access across your entire organization.
Who's at risk
Windows Server administrators and identity teams should prioritize this. It affects Windows Server 2016, 2019, 2022, and 2025 systems running Active Directory Federation Services. Organizations using AD FS for single sign-on or federated authentication are at direct risk. The vulnerability also touches .NET Framework 3.5, 4.7.2, 4.8, and 4.8.1 across multiple Windows 10 and Windows 11 versions.
How it could be exploited
An attacker on the network sends a specially crafted request to an AD FS server (typically port 443 or 80). The malformed input triggers a buffer overflow in memory, causing the AD FS service to crash. The attacker needs no credentials and can repeat this to keep the service down.
Prerequisites
- Network access to the AD FS server (typically port 443 HTTPS or port 80 HTTP)
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects critical identity service
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (53)
53 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the July 2026 security update for your Windows Server and .NET Framework versions
Long-term hardening
0/2HARDENINGRestrict network access to AD FS servers to trusted administrative networks and identity providers only
HARDENINGMonitor AD FS service logs for unexpected crashes or denial of service attempts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/4d6e7f49-38be-42dd-8e8f-7c4d18eff3b6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.