CVE-2026-58529: Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
Published Jul 14, 2026
·Updated
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
Other sources
Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
— Microsoft
Affected Software
5 affected componentsFixes available
Microsoft Active Directory Federation Services (AD FS)
Microsoft Windows 11=26H1
10.0.28000.2525
Microsoft Windows 11=26H1
10.0.28000.2525
Microsoft Windows 11 26h1<10.0.28000.2525
Microsoft Windows 11 26h1<10.0.28000.2525
Remediation
Event History
Jul 14, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this vulnerability?
The attacker must be authorized and can exploit the issue over the network. No user interaction is required.
2
What is the potential impact of successful exploitation?
Successful exploitation can disclose information. The supplied severity vector indicates high confidentiality impact, no integrity impact, and low availability impact.
3
Is a fix available?
Yes. A patch is available for this vulnerability.