Active Directory Federation Services (AD FS) Denial of Service Vulnerability

MonitorCVSS 5.9CVE-2026-72978Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

Active Directory Federation Services (AD FS) does not properly limit or throttle resource allocation, allowing an unauthenticated attacker to send crafted requests that consume excessive resources and cause denial of service. The vulnerability affects Windows 10 (versions 1607, 1809) and Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker could send network requests to AD FS that consume server resources, making authentication services unavailable and potentially disrupting plant operations that depend on centralized credential management.
Who's at risk
Water utilities and municipal electric utilities that run Windows Server (2016, 2019, 2022, 2025) as domain controllers or AD FS servers should prioritize this. Any organization using Windows 10 or Windows Server for centralized authentication. Smaller utilities that use AD FS to control access to SCADA workstations or historian servers should pay attention.
How it could be exploited
An attacker with network access to the AD FS server (typically port 443) sends specially crafted requests that cause AD FS to allocate memory or CPU without proper limits. The server becomes unresponsive to legitimate authentication requests, denying service to users and systems that rely on AD FS for login.
Prerequisites
  • Network access to AD FS server on port 443 (HTTPS)
  • No credentials or authentication required
remotely exploitableno authentication requiredaffects centralized identity service
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5622
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows Server 2025All versionsBuild 10.0.26100.33438
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict network access to AD FS servers (port 443) to only authorized client networks and administrative systems using firewall rules
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the September 2026 security update to all affected Windows Server systems running AD FS
HARDENINGMonitor AD FS event logs for signs of denial of service attacks (excessive authentication failures or resource exhaustion)
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate AD FS servers from untrusted network segments
API: /api/v1/advisories/b6b6afb9-d1a5-4c01-95e4-70e2ae4511f4

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.