Junglewise Threat Intelligence

CVE-2026-50324: Microsoft AD FS infinite loop denial of service

CVE-2026-50324 · Severity: medium · CVSS 5.9 · Published 2026-07-14

Executive brief

Microsoft Active Directory Federation Services (AD FS), a tool used to provide single sign-on access to applications, is vulnerable to a denial-of-service attack. An unauthorized attacker can remotely trigger a software loop that never ends, causing the service to become unresponsive. This could prevent legitimate users from logging into corporate applications and services, disrupting business operations.

Technical details

A denial-of-service vulnerability exists in Microsoft Active Directory Federation Services (AD FS) due to a loop with an unreachable exit condition (CWE-835). An unauthenticated attacker can exploit this over the network by sending specially crafted requests that trigger an infinite loop within the AD FS process. While the attack complexity is rated as high, a successful exploit results in a complete loss of availability for the federation service. Microsoft has released security updates for various versions of Windows and Windows Server to address this issue.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2012 R2 6.3.9600.0 to 6.3.9600.23291
  • Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
  • Microsoft Windows Server 2025
  • Microsoft Active Directory Federation Services (AD FS)

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats