Active Directory Federation Server Spoofing Vulnerability
MonitorCVSS 4.8CVE-2026-50684Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionRequired
Summary
A cross-site scripting (XSS) vulnerability in Active Directory Federation Services allows an authorized attacker with high privileges to inject malicious code into AD FS web pages. An attacker could spoof login pages or intercept user sessions when legitimate users visit the compromised AD FS portal. The vulnerability affects Windows Server 2016, 2019, 2022, 2025, and Windows 10 (versions 1607 and 1809).
What this means
What could happen
An attacker with high-level access (such as a domain administrator or AD FS service account compromiser) could inject malicious code into AD FS pages, causing legitimate users to be redirected to fake login pages or have their sessions hijacked, potentially compromising domain credentials across your entire IT infrastructure.
Who's at risk
IT departments managing Active Directory Federation Services for single sign-on and multi-factor authentication. This affects organizations using Windows Server 2016, 2019, 2022, or 2025 as AD FS servers, particularly those relying on AD FS for user authentication to cloud or on-premises applications.
How it could be exploited
An attacker with elevated privileges in Active Directory injects malicious JavaScript into AD FS web pages through an XSS vulnerability. When users or administrators visit the compromised AD FS portal, the injected code executes in their browsers, allowing the attacker to steal credentials, session tokens, or redirect them to spoofed login pages.
Prerequisites
- High-level Active Directory privileges (e.g., domain admin or AD FS service account compromise)
- User interaction required - a legitimate user must visit the compromised AD FS page
Requires high-level credentials to exploitUser interaction requiredLow exploit probability (0.4% EPSS)Affects identity and access management infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/7
Schedule — requires maintenance window
0/5Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9339 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 systems to the corresponding patched builds (1607, 1809)
Long-term hardening
0/2HARDENINGRestrict administrative access to AD FS servers and limit who can modify AD FS configurations
HARDENINGMonitor AD FS admin logs for unauthorized configuration changes or suspicious login activity
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0342286d-c54a-4a14-bf92-0510459e07b6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.