Junglewise Threat Intelligence

CVE-2026-50368: Microsoft Active Directory Federation Services stack overflow denial of service

CVE-2026-50368 · Severity: high · CVSS 7.5 · Published 2026-07-14

Executive brief

A vulnerability in Microsoft's identity management service, Active Directory Federation Services (AD FS), could allow an attacker to crash the service remotely. AD FS is used by organizations to provide single sign-on access to applications and systems; if this service is disabled, users may be unable to log in to critical business tools. This attack can be carried out over the network without needing any valid user credentials.

Technical details

A stack-based buffer overflow (CWE-121) exists in Microsoft Active Directory Federation Services (AD FS). The vulnerability is triggered when the service processes specially crafted network requests, leading to memory corruption on the stack. An unauthenticated attacker can exploit this over the network (AV:N) with low complexity (AC:L) to crash the AD FS service, resulting in a complete loss of availability for authentication services. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 Version 1607 / 1809 Multiple versions prior to July 2026 updates
  • Microsoft Windows Server 2012 / 2012 R2 / 2016 / 2019 Multiple versions prior to July 2026 updates
  • Microsoft Active Directory Federation Services (AD FS)

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory: Microsoft released security updates for this vulnerability.

References

Related threats