CVE-2026-50324: Windows Active Directory Federation Services Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
CSIRTS triage
- What
- Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
- Who is affected
- Deployments of Active Directory Federation Services.
- Urgency
- Remediation is important due to medium severity and potential for denial of service.
- Action
- Apply the latest security patch for Active Directory Federation Services.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Active Directory Federation Services
Get an email when a new Active Directory Federation Services advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50324
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-503240.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-50324 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Windows Active Directory
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-54115: Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to el…nvd · 2026-07-14
- highCVE-2026-50682: Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service o…nvd · 2026-07-14
- highCVE-2026-55001: Improper certificate validation in Windows Active Directory allows an authorized attacker to e…nvd · 2026-07-14
- highCVE-2026-54119: Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an u…nvd · 2026-07-14
- highCVE-2026-50368: Windows Active Directory Federation Services Denial of Service Vulnerabilitymsrc · 2026-07-14
- highCVE-2026-50355: Windows Active Directory Federation Services Denial of Service Vulnerabilitymsrc · 2026-07-14
More from Microsoft Security Response Center
- highCVE-2026-42900: Microsoft Windows App Store Elevation of Privilege Vulnerability2026-07-14
- mediumCVE-2026-55003: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability2026-07-14
- highCVE-2026-57992: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability2026-07-14
- unknownCVE-2026-13867: Chromium: CVE-2026-13867 Inappropriate implementation in Geolocation2026-07-14
- mediumCVE-2026-59926: Mistune: XSS via unescaped class option in Admonition directive2026-07-14