Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability

Plan PatchCVSS 7.1CVE-2026-58529Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in Active Directory Federation Services (AD FS) on Windows 11 version 26H1 allows an authorized attacker to disclose sensitive information from server memory over the network. The vulnerability requires valid credentials and does not affect system availability or integrity.

What this means
What could happen
An attacker with valid credentials to your AD FS system could read sensitive information from server memory, potentially exposing authentication tokens, user credentials, or other security-related data in your directory infrastructure.
Who's at risk
Organizations running Windows 11 version 26H1 (x64 or ARM64) with Active Directory Federation Services should prioritize this update. AD FS typically serves as the identity provider for enterprise access to cloud services and federated applications, so this primarily affects IT staff managing enterprise identity infrastructure and network administrators who maintain federated authentication systems.
How it could be exploited
An attacker with valid AD FS user or service account credentials connects to the AD FS service over the network and sends a specially crafted request that triggers an out-of-bounds memory read, allowing the attacker to access information they should not have permission to see.
Prerequisites
  • Valid AD FS user or service account credentials
  • Network access to AD FS service endpoints
  • AD FS system running affected Windows 11 version 26H1 build
Requires valid credentialsLow exploit probabilityInformation disclosure only (no direct operational impact)
Exploitability
Some exploitation risk — EPSS score 1.0%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2525
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2525
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the Microsoft July 2026 security update (Build 10.0.28000.2525 or later) to all Windows 11 version 26H1 systems running AD FS
API: /api/v1/advisories/aa5565c0-d3ab-418e-ba6d-21383df486d5

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability | CVSS 7.1 - OTPulse