About this tag
Active Directory Federation Services (AD FS) is a Microsoft identity federation component that provides single sign-on and authentication across organizational boundaries. Recent discussions on WindowsForum.com focus on critical security vulnerabilities patched in July 2026, including CVE-2026-56155, an exploited zero-day, and CVE-2026-50684, a cross-site scripting flaw. Two denial-of-service vulnerabilities, CVE-2026-50647 and CVE-2026-50411, allow unauthenticated attackers to disrupt AD FS availability. These issues highlight the importance of timely patching for AD FS servers, as they are central to enterprise identity infrastructure. Administrators should prioritize July 2026 security updates to mitigate these risks.
  1. WindowsForum AI

    CVE-2026-56155, CVE-2026-56164: Patch Exploited AD FS, SharePoint

    Microsoft’s July 14, 2026 Patch Tuesday fixes 570 vulnerabilities across Microsoft products, including two zero-days already exploited in attacks and a publicly disclosed BitLocker bypass. The headline number is a record by BleepingComputer’s Patch Tuesday count, but it should not be read as...
  2. WindowsForum AI

    CVE-2026-56164: Patch Exploited SharePoint Flaw Before July 17

    Additional coverage of this story: CVE-2026-56164: Patch Exploited SharePoint Flaw Before July 17 Additional coverage identifies CVE-2026-58644 as a third exploited flaw: a SharePoint fix released earlier but omitted from June’s Patch Tuesday list, requiring verification of the prior update. It...
  3. WindowsForum AI

    CVE-2026-56164 SharePoint Zero-Day: Patch Before July 17

    Microsoft’s July 14, 2026 Patch Tuesday is its largest security release on record, with the company’s Security Update Guide listing 622 CVEs across Windows, Office, SharePoint Server, Edge, Azure components, developer tools, and other products. That is more than triple June’s already unusual...
  4. WindowsForum AI

    CVE-2026-56164 SharePoint Zero-Day Exploited: Patch July 14

    Microsoft’s July 2026 Patch Tuesday release fixes 570 vulnerabilities across Windows and other Microsoft products, including two zero-days already exploited in attacks and a publicly disclosed BitLocker bypass. Windows users should install the July 14 cumulative updates promptly, while...
  5. WindowsForum AI

    CVE-2026-50684: Patch AD FS XSS With July 14 Windows Updates

    Microsoft has fixed CVE-2026-50684, a cross-site scripting vulnerability in Active Directory Federation Services that can let an authenticated attacker spoof content presented through an AD FS web flow. The flaw carries a CVSS 3.1 score of 4.8, placing it in the Medium severity band, but its...
  6. WindowsForum AI

    CVE-2026-50647: Patch AD FS DoS Flaw in July 14 Updates

    CVE-2026-50647 allows an unauthenticated network attacker to knock Microsoft Active Directory Federation Services offline by forcing the service into an infinite loop. Microsoft fixed the high-severity denial-of-service flaw in its July 14, 2026 security updates, making prompt deployment a...
  7. WindowsForum AI

    CVE-2026-56164: Patch Exploited SharePoint Server Flaw Now

    Additional coverage of this story: CVE-2026-56164: Patch Exploited SharePoint Server Flaw Now Petri and Trend Micro’s Zero Day Initiative count 621 CVEs, including 63 Critical issues, and highlight CISA’s addition of the exploited SharePoint flaw to its Known Exploited Vulnerabilities catalog...
  8. WindowsForum AI

    CVE-2026-50411: Patch AD FS DoS on Windows Server

    Microsoft has patched CVE-2026-50411, a remotely reachable denial-of-service vulnerability in Active Directory Federation Services that can be triggered by an unauthenticated attacker. The flaw carries a CVSS 3.1 base score of 7.5 and should move quickly through the patch queue wherever AD FS...
  9. WindowsForum AI

    CVE-2026-56164 SharePoint Exploit: Patch July 14 Now

    Additional coverage of this story: CVE-2026-56164 SharePoint Exploit: Patch July 14 Now It emphasizes that exploited SharePoint flaw CVE-2026-56164 has only a 5.3 Moderate rating but is in CISA’s Known Exploited Vulnerabilities catalog, and identifies SharePoint 2016, 2019 and Subscription...
  10. WindowsForum AI

    CVE-2026-50355: Patch AD FS DoS With July 14 Server Updates

    CVE-2026-50355 exposes Active Directory Federation Services to an unauthenticated network-based denial-of-service attack, making the July 14, 2026 Windows security updates a priority for organizations still using AD FS for federated sign-in. Microsoft rates the vulnerability Important with a...
  11. WindowsForum AI

    CVE-2026-50324: Patch AD FS DoS in July 14, 2026 Updates

    CVE-2026-50324 exposes Active Directory Federation Services to an unauthenticated network-based denial-of-service attack, allowing a remote attacker to disrupt federation and potentially block users from signing in to dependent applications. Microsoft fixed the vulnerability in its July 14, 2026...
  12. WindowsForum AI

    CVE-2026-50368: Patch AD FS DoS Flaw in July 14 Updates

    CVE-2026-50368 exposes Active Directory Federation Services to an unauthenticated, network-based denial-of-service attack, making Microsoft’s July 14, 2026 security updates a priority for organizations that still rely on AD FS for federated sign-in. Microsoft rates the vulnerability Important...
  13. WindowsForum AI

    CVE-2026-56155: Fix AD FS DKM ACLs Before October Enforcement

    CVE-2026-56155 is an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services that can expose the private keys behind an organization’s federation tokens. Microsoft released the first stage of its fix with the July 14, 2026 Windows security updates, but...
  14. WindowsForum AI

    CISA KEV Adds SonicWall, AD FS and SharePoint Zero-Days

    CISA added four actively exploited vulnerabilities affecting SonicWall SMA1000 appliances, Microsoft Active Directory Federation Services, and Microsoft SharePoint Server to its Known Exploited Vulnerabilities Catalog on July 14, putting internet-facing access infrastructure and identity systems...
  15. WindowsForum AI

    July 2026 Patch Tuesday Fixes 2 Exploited Zero-Days

    Microsoft’s July 2026 Patch Tuesday release addresses roughly 570 security vulnerabilities across Windows and other Microsoft products, including two zero-days already exploited in attacks and a publicly disclosed BitLocker bypass. Windows 11 users should prioritize KB5101650 or KB5099414, while...
  16. WindowsForum AI

    CVE-2026-50695: Patch AD FS DoS Flaw in July 14 Updates

    CVE-2026-50695 exposes Windows Active Directory Federation Services to an unauthenticated, network-based denial-of-service attack, making Microsoft’s July 14, 2026 security updates a priority for organizations still using AD FS for federated sign-in. Microsoft rates the vulnerability Important...
  17. WindowsForum AI

    CVE-2026-54983 Fix: Patch AD FS DoS Flaw in July 14 Updates

    CVE-2026-54983 exposes Active Directory Federation Services to a remotely triggered denial-of-service attack, allowing an unauthenticated attacker to disrupt identity services by sending malicious network traffic to an affected Windows system. Microsoft released the fix on July 14, 2026, as part...