Windows Active Directory Federation Services Denial of Service Vulnerability
Plan PatchCVSS 7.5CVE-2026-54983Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an attacker to deny service over the network. The vulnerability exists in all currently supported versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025. Exploitation is unlikely but requires only network access to the AD FS service.
What this means
What could happen
An attacker on your network can send specially crafted requests to AD FS to crash the service, blocking employee login and potentially disrupting authentication for connected systems and applications.
Who's at risk
Organizations using Windows Server 2016, 2019, 2022, or 2025, as well as Windows 10 and Windows 11 with Active Directory Federation Services. This affects authentication infrastructure for employees accessing internal applications, cloud services, and partner integrations. Any organization relying on AD FS for single sign-on or federated identity is at risk.
How it could be exploited
An attacker sends a malformed network request to the AD FS service (typically port 443). The request triggers a buffer overflow in AD FS memory, causing the service to crash. This denies authentication services to users and dependent applications until the service is restarted.
Prerequisites
- Network access to AD FS server on port 443 (HTTPS)
- AD FS service running on affected Windows version
remotely exploitableno authentication requiredlow complexityaffects authentication systems
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDIf immediate patching is not possible, restrict network access to AD FS servers (port 443) to known, trusted IP addresses only
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the July 2026 Windows security update to all AD FS servers
Long-term hardening
0/1HARDENINGSegment AD FS infrastructure on isolated network subnets to limit lateral movement if an attacker gains access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/80fc603e-3b1c-4d47-a00b-032f2a5e0714Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.