Jul 2026: Azure Active Directory Denial of Service Vulnerability
CVE-2026-50653 Published on July 14, 2026
Azure Active Directory Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
Weakness Types
What is an Infinite Loop Vulnerability?
The program contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop. If the loop can be influenced by an attacker, this weakness could allow attackers to consume excessive resources such as CPU or memory.
CVE-2026-50653 has been classified to as an Infinite Loop vulnerability or weakness.
What is a Resource Exhaustion Vulnerability?
The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVE-2026-50653 has been classified to as a Resource Exhaustion vulnerability or weakness.
Products Associated with CVE-2026-50653
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Azure Active Directory:- Version 2021 and below 8.19.2 is affected.
- Version 3.5.0 and below 2.0.50727.9182 & 3.0.30729.9168 is affected.
- Version 4.7.0 and below 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0 is affected.
- Version 4.8.0 and below 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0 is affected.
- Version 4.8.1 and below 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0 is affected.
- Version 4.7.0 and below 4.7.4143.0 is affected.
- Version 4.8.0 and below 4.8.4803.0 is affected.
- Version 4.8.0.0 and below 4.8.9340.0 is affected.