Junglewise Threat Intelligence

CVE-2026-72978: Microsoft Active Directory Federation Services resource exhaustion denial of service

CVE-2026-72978 · Severity: medium · CVSS 5.9 · Published 2026-09-08

Executive brief

Active Directory Federation Services (AD FS) is Microsoft's identity and federation service used by enterprises to manage authentication and access across networks. An attacker without authorization can exhaust server resources and cause the service to become unavailable to legitimate users, disrupting authentication for applications and systems that depend on AD FS.

Technical details

This vulnerability is a resource exhaustion / denial-of-service flaw in AD FS caused by insufficient rate limiting or resource allocation controls. An unauthenticated attacker can send malicious requests over the network to trigger excessive resource consumption (memory, CPU, or connections), exhausting server capacity and rendering the service unavailable. The vulnerability requires network access to the AD FS service but does not require prior authentication. No patch information is specified in the advisory details provided.

Affected products

  • Microsoft Active Directory Federation Services

Timeline

  • 2026-09-08: disclosed

References

Related threats