Jul 2026: Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50324 Published on July 14, 2026

Windows Active Directory Federation Services Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

Vendor Advisory NVD

Weakness Type

What is an Infinite Loop Vulnerability?

The program contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop. If the loop can be influenced by an attacker, this weakness could allow attackers to consume excessive resources such as CPU or memory.

CVE-2026-50324 has been classified to as an Infinite Loop vulnerability or weakness.


Products Associated with CVE-2026-50324

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 
 
 
 
 

Affected Versions

Microsoft .NET Framework 3.5 AND 4.7.2: Microsoft .NET Framework 3.5 AND 4.8: Microsoft .NET Framework 3.5 AND 4.8.1: Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2: Microsoft .NET Framework 4.8: Microsoft .NET Framework 4.8.1: Microsoft Windows 10 Version 1607: Microsoft Windows 10 Version 1809: Microsoft Windows Server 2012 R2: Microsoft Windows Server 2012 R2 (Server Core installation): Microsoft Windows Server 2016: Microsoft Windows Server 2016 (Server Core installation): Microsoft Windows Server 2019: Microsoft Windows Server 2019 (Server Core installation): Microsoft Windows Server 2022: Microsoft Windows Server 2025: Microsoft Windows Server 2025 (Server Core installation):