Active Directory Federation Server Spoofing Vulnerability

MonitorCVSS 4.8CVE-2026-50684Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionRequired
Summary

A cross-site scripting (XSS) vulnerability in Active Directory Federation Services allows an authorized attacker with high privileges to inject malicious code into AD FS web pages. An attacker could spoof login pages or intercept user sessions when legitimate users visit the compromised AD FS portal. The vulnerability affects Windows Server 2016, 2019, 2022, 2025, and Windows 10 (versions 1607 and 1809).

What this means
What could happen
An attacker with high-level access (such as a domain administrator or AD FS service account compromiser) could inject malicious code into AD FS pages, causing legitimate users to be redirected to fake login pages or have their sessions hijacked, potentially compromising domain credentials across your entire IT infrastructure.
Who's at risk
IT departments managing Active Directory Federation Services for single sign-on and multi-factor authentication. This affects organizations using Windows Server 2016, 2019, 2022, or 2025 as AD FS servers, particularly those relying on AD FS for user authentication to cloud or on-premises applications.
How it could be exploited
An attacker with elevated privileges in Active Directory injects malicious JavaScript into AD FS web pages through an XSS vulnerability. When users or administrators visit the compromised AD FS portal, the injected code executes in their browsers, allowing the attacker to steal credentials, session tokens, or redirect them to spoofed login pages.
Prerequisites
  • High-level Active Directory privileges (e.g., domain admin or AD FS service account compromise)
  • User interaction required - a legitimate user must visit the compromised AD FS page
Requires high-level credentials to exploitUser interaction requiredLow exploit probability (0.4% EPSS)Affects identity and access management infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/7
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9339 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 systems to the corresponding patched builds (1607, 1809)
Long-term hardening
0/2
HARDENINGRestrict administrative access to AD FS servers and limit who can modify AD FS configurations
HARDENINGMonitor AD FS admin logs for unauthorized configuration changes or suspicious login activity
API: /api/v1/advisories/0342286d-c54a-4a14-bf92-0510459e07b6

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.