CVE-2026-72978: Active Directory Federation Services (AD FS) Denial of Service Vulnerability
Active Directory Federation Services (AD FS) Denial of Service Vulnerability
Other sources
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23397Patch KB5123066 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9512Patch KB5123099 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26349Patch KB5123065 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33438Patch KB5122871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5622Patch KB5122882 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9245Patch KB5122876
Event History
Frequently Asked Questions
Which systems should be prioritized for review?
Organizations running Microsoft Active Directory Federation Services (AD FS) on the listed Microsoft Windows 10, Windows Server 2012, 2012 R2, 2016, 2019, 2022, or 2025 platforms should prioritize review.
Does an attacker need credentials or user interaction?
No privileges and no user interaction are required. The attacker must be able to reach the affected service over the network, and exploitation is rated as high complexity.
What is the expected security impact?
The reported impact is limited to availability: an attacker may deny service. No confidentiality or integrity impact is indicated.