Active Directory Federation Server Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-50647Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
An infinite loop condition in Active Directory Federation Services (AD FS) allows an unauthenticated attacker to trigger a denial of service over the network. The vulnerability affects Windows Server versions running AD FS (2016, 2019, 2022, 2025) and related .NET Framework components across multiple Windows 10 and Windows 11 versions.
What this means
What could happen
An attacker could make your AD FS server unresponsive, preventing users from authenticating through federated identity services and potentially disrupting access to critical applications and systems that rely on AD FS for login.
Who's at risk
This affects IT infrastructure teams running Active Directory Federation Services on Windows Server 2016, 2019, 2022, or 2025. Organizations using AD FS for single sign-on (SSO), federated identity, or multi-tenant authentication systems should prioritize patching. Windows 10 and Windows 11 workstations with the affected .NET Framework versions are also in scope if they interact with AD FS services.
How it could be exploited
An attacker sends a specially crafted network request to the AD FS service (port 443 typically) that triggers an infinite loop in the server process. This consumes CPU resources and causes the service to become unresponsive to legitimate authentication requests.
Prerequisites
- Network connectivity to the AD FS server on port 443 (or configured HTTPS port)
- AD FS service must be running and exposed to the attacker's network segment
Remotely exploitableNo authentication requiredAffects identity and authentication infrastructureAffects multiple Windows Server versions
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (63)
63 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDRestrict network access to AD FS servers (port 443) to only trusted identity provider networks and authorized client subnets using firewall rules
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply the July 2026 Windows security update to all Windows Server systems running AD FS (2016, 2019, 2022, 2025)
HOTFIXUpdate all .NET Framework components to the specified fixed versions across Windows 10 and Windows 11 systems
Long-term hardening
0/1HARDENINGVerify AD FS service is not unnecessarily exposed on untrusted network segments or the Internet
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/40b63c7f-0c47-4486-8891-c726a34a97b4Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.