Windows Active Directory Federation Services Denial of Service Vulnerability

Plan PatchCVSS 7.5CVE-2026-50695Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

What this means
What could happen
An attacker can crash AD FS services, preventing users and systems from authenticating through your federation infrastructure. This stops single sign-on across your organization and may block access to critical systems and applications.
Who's at risk
Any organization running Active Directory Federation Services on Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 should apply this patch immediately. This affects IT departments using AD FS for single sign-on, identity management, and federation with partner organizations or cloud services like Microsoft 365.
How it could be exploited
An attacker sends a specially crafted network request to the AD FS service port. The malformed input overflows a stack buffer in the service, causing it to crash and become unavailable.
Prerequisites
  • Network access to the AD FS service port (default 443 or 80)
  • No authentication required
Remotely exploitableNo authentication requiredLow complexityAffects critical authentication services
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to AD FS service ports (443/tcp and 80/tcp) to only authorized federation servers and trusted networks using your firewall or network access controls
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the July 2026 Windows security update to all Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems running AD FS
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate AD FS servers from untrusted networks and direct Internet access
API: /api/v1/advisories/4e88a5ef-9049-4198-99d7-731f7bc8290e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Active Directory Federation Services Denial of Service Vulnerability | CVSS 7.5 - OTPulse