Active Directory Federation Services (AD FS) Denial of Service Vulnerability
MonitorCVSS 5.9CVE-2026-72978Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
Active Directory Federation Services (AD FS) does not properly limit or throttle resource allocation, allowing an unauthenticated attacker to send crafted requests that consume excessive resources and cause denial of service. The vulnerability affects Windows 10 (versions 1607, 1809) and Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
An attacker could send network requests to AD FS that consume server resources, making authentication services unavailable and potentially disrupting plant operations that depend on centralized credential management.
Who's at risk
Water utilities and municipal electric utilities that run Windows Server (2016, 2019, 2022, 2025) as domain controllers or AD FS servers should prioritize this. Any organization using Windows 10 or Windows Server for centralized authentication. Smaller utilities that use AD FS to control access to SCADA workstations or historian servers should pay attention.
How it could be exploited
An attacker with network access to the AD FS server (typically port 443) sends specially crafted requests that cause AD FS to allocate memory or CPU without proper limits. The server becomes unresponsive to legitimate authentication requests, denying service to users and systems that rely on AD FS for login.
Prerequisites
- Network access to AD FS server on port 443 (HTTPS)
- No credentials or authentication required
remotely exploitableno authentication requiredaffects centralized identity service
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDRestrict network access to AD FS servers (port 443) to only authorized client networks and administrative systems using firewall rules
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply the September 2026 security update to all affected Windows Server systems running AD FS
HARDENINGMonitor AD FS event logs for signs of denial of service attacks (excessive authentication failures or resource exhaustion)
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate AD FS servers from untrusted network segments
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b6b6afb9-d1a5-4c01-95e4-70e2ae4511f4Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.