CVE-2026-50324: Windows Active Directory Federation Services Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Other sources
Windows Active Directory Federation Services Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9020Patch KB5099538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23291Patch KB5099444 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9339Patch KB5099535 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5386Patch KB5099540 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8983 & 3.0.30729.8978Patch KB5100984 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8983 & 3.0.30729.8978Patch KB5100985 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168Patch KB5101014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0Patch KB5101004 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0Patch KB5101003 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0Patch KB5100998 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0Patch KB5101001 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0Patch KB5101000 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0Patch KB5101005 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4143.0Patch KB5100991 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0Patch KB5099535 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.4143.0Patch KB5100990 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0Patch KB5100989 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0Patch KB5101006 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0Patch KB5101010 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0Patch KB5101008 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4803.0Patch KB5101011 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4803.0Patch KB5101009 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.4803.0Patch KB5101007 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.9340.0Patch KB5101002
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50324?
CVE-2026-50324 has a medium severity rating of 5.9.
What does CVE-2026-50324 do?
CVE-2026-50324 allows an unauthorized attacker to perform a denial of service attack on Windows Active Directory Federation Services.
Which software is affected by CVE-2026-50324?
CVE-2026-50324 affects various versions of Microsoft Windows Server and Windows 10, including Microsoft .NET Framework.
How do I fix CVE-2026-50324?
To mitigate CVE-2026-50324, users should apply the latest security updates provided by Microsoft.
What is the exploitability of CVE-2026-50324?
CVE-2026-50324 has an attack vector of network and can be exploited without authentication.