Denial of Service Vulnerability in Active Directory Federation Services by Microsoft
CVE-2026-50647
7.5HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 14 July 2026
What is CVE-2026-50647?
A vulnerability exists in Active Directory Federation Services (AD FS) that causes an endless loop with an unreachable exit condition. This flaw may allow unauthorized attackers to exploit the system, leading to service disruptions over a network, preventing legitimate users from accessing essential services.
Affected Version(s)
Microsoft .NET Framework 3.5 AND 4.7.2 Windows 10 Version 1607 for 32-bit Systems 4.7.0 < 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0
Microsoft .NET Framework 3.5 AND 4.8 Windows 10 Version 1809 for 32-bit Systems 4.8.0 < 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0
Microsoft .NET Framework 3.5 AND 4.8.1 Windows 10 Version 21H2 for 32-bit Systems 4.8.1 < 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0