Active Directory Denial of Service Vulnerability
Plan PatchCVSS 7.1CVE-2026-50682Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Out-of-bounds read vulnerability in Windows Active Directory allows an authenticated attacker to cause a denial of service by crashing the Active Directory service on domain controllers. Exploitation requires valid AD credentials and network access to a domain controller.
What this means
What could happen
An authenticated attacker on your network could crash Active Directory, preventing users from logging in or accessing networked resources and potentially disrupting automated processes that depend on AD authentication.
Who's at risk
Organizations running Windows Server 2022, Windows Server 2025, or Windows 10/11 as domain controllers or member servers. This affects any business that relies on Active Directory for user authentication, including utilities, manufacturing facilities, and buildings automation systems that depend on AD for access control and automated process authentication.
How it could be exploited
An attacker with valid Active Directory credentials sends a specially crafted network request to a domain controller, triggering an out-of-bounds memory read that causes the Active Directory service to stop responding. This requires the attacker to already have network access and valid credentials (such as a compromised employee account or service account).
Prerequisites
- Valid Active Directory credentials (user or service account)
- Network access to a domain controller on port 389 (LDAP) or 636 (LDAPS)
- Authenticated session to Active Directory
Requires valid credentialsRemotely exploitableCauses denial of serviceAffects authentication infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Jul Windows security update to all domain controllers and member servers
HARDENINGRestrict network access to domain controllers to only necessary systems; implement firewall rules to limit LDAP traffic to authorized subnets
Long-term hardening
0/1HARDENINGAudit Active Directory user and service accounts to identify and disable unused or suspicious credentials
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/c2eecac2-eb6a-4b63-8a75-072778434841Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.