Junglewise Threat Intelligence

CVE-2026-58529: Microsoft AD FS out-of-bounds read information disclosure

CVE-2026-58529 · Severity: high · CVSS 7.1 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 26H1, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

Microsoft Active Directory Federation Services (AD FS), a component used to provide single sign-on access to applications, contains a security vulnerability. An authorized user on the network could exploit this flaw to view sensitive information that they should not have access to. This could lead to the disclosure of internal system data or user credentials, potentially aiding further attacks against the organization's identity infrastructure.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Active Directory Federation Services (AD FS). The flaw is triggered when the component improperly handles memory buffers during network requests. An attacker with basic user privileges (PR:L) can exploit this over the network without user interaction to read data beyond the intended buffer. This can result in the disclosure of sensitive information from the process memory. Microsoft has released updates to address this issue in affected versions of Windows 11.

Affected products

  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525

Timeline

  • 2026-07-14: advisory
  • 2026-07-14: disclosed

References

Related threats