Windows Active Directory Federation Services Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-50411Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Stack-based buffer overflow vulnerability in Active Directory Federation Services (AD FS) allows an unauthenticated attacker to send a malformed network request that triggers a denial of service condition. The vulnerability affects Windows Server 2016, 2019, 2022, and 2025, as well as Windows 10 and 11 systems running AD FS or supporting components. The impact is service availability; an attacker cannot execute code, access data, or bypass authentication with this vulnerability.
What this means
What could happen
An attacker could crash or disrupt Active Directory Federation Services, preventing authentication for users who rely on federated identity. This impacts any organization using AD FS for single sign-on or access to cloud services, though it does not compromise data or allow unauthorized access.
Who's at risk
Organizations that use Active Directory Federation Services for user authentication and single sign-on, particularly those managing hybrid cloud identity scenarios. This affects Windows Server 2016, 2019, 2022, and 2025 installations running AD FS, as well as Windows 10 and Windows 11 systems with .NET Framework components that support federated authentication scenarios.
How it could be exploited
An attacker with network access to the AD FS server could send a specially crafted request that triggers a buffer overflow, causing the service to crash and become unavailable. This requires sending malformed data over the network to the AD FS endpoint; no credentials or special configuration are needed.
Prerequisites
- Network access to the AD FS server (typically port 443 or 80, depending on configuration)
- No credentials required
Remotely exploitableNo authentication requiredLow complexityAffects authentication infrastructure
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (65)
65 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDMonitor AD FS event logs for unexpected crashes or service restarts, which may indicate exploitation attempts
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft July 2026 security update to bring Windows and .NET Framework components to their latest patched versions
Long-term hardening
0/1HARDENINGReview AD FS server network exposure and restrict inbound access to AD FS ports to only trusted networks and clients that require federation
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/27810e1f-42d0-4997-85ef-95c68e5670d5Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.