Jul 2026: Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50324 Published on July 14, 2026
Windows Active Directory Federation Services Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Weakness Type
What is an Infinite Loop Vulnerability?
The program contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop. If the loop can be influenced by an attacker, this weakness could allow attackers to consume excessive resources such as CPU or memory.
CVE-2026-50324 has been classified to as an Infinite Loop vulnerability or weakness.
Products Associated with CVE-2026-50324
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft .NET Framework 3.5 AND 4.7.2:- Version 4.7.0 and below 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0 is affected.
- Version 4.8.0 and below 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0 is affected.
- Version 4.8.1 and below 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0 is affected.
- Version 4.7.0 and below 4.7.4143.0 is affected.
- Version 4.8.0 and below 4.8.4803.0 is affected.
- Version 4.8.0.0 and below 4.8.9340.0 is affected.
- Version 10.0.14393.0 and below 10.0.14393.9339 is affected.
- Version 10.0.17763.0 and below 10.0.17763.9020 is affected.
- Version 6.3.9600.0 and below 6.3.9600.23291 is affected.
- Version 6.3.9600.0 and below 6.3.9600.23291 is affected.
- Version 10.0.14393.0 and below 10.0.14393.9339 is affected.
- Version 10.0.14393.0 and below 10.0.14393.9339 is affected.
- Version 10.0.17763.0 and below 10.0.17763.9020 is affected.
- Version 10.0.17763.0 and below 10.0.17763.9020 is affected.
- Version 10.0.20348.0 and below 10.0.20348.5386 is affected.
- Version 10.0.26100.0 and below 10.0.26100.33158 is affected.
- Version 10.0.26100.0 and below 10.0.26100.33158 is affected.