Executive brief
Active Directory Federation Services (AD FS) is Microsoft's identity and federation service used by enterprises to manage authentication and access across networks. An attacker without authorization can exhaust server resources and cause the service to become unavailable to legitimate users, disrupting authentication for applications and systems that depend on AD FS.
Technical details
This vulnerability is a resource exhaustion / denial-of-service flaw in AD FS caused by insufficient rate limiting or resource allocation controls. An unauthenticated attacker can send malicious requests over the network to trigger excessive resource consumption (memory, CPU, or connections), exhausting server capacity and rendering the service unavailable. The vulnerability requires network access to the AD FS service but does not require prior authentication. No patch information is specified in the advisory details provided.
Affected products
- Microsoft Active Directory Federation Services
Timeline
- 2026-09-08: disclosed