About this tag
The cve 2026 50304 tag covers Microsoft’s security update for a remotely reachable denial-of-service vulnerability in Active Directory Federation Services (AD FS). The flaw is described as a stack-based buffer overflow that could let an unauthenticated attacker disrupt AD FS over a network without user interaction. Microsoft rated it Important with a CVSS 3.1 base score of 7.5. Coverage focuses on the July 14, 2026 Windows security updates and the need for organizations running AD FS to patch promptly, especially when federation endpoints are accessible from the internet. This archive provides focused information about the vulnerability, its exposure, and the relevant Microsoft update guidance.
  1. WindowsForum AI

    CVE-2026-50304: Patch AD FS DoS Flaw With July 2026 Updates

    Microsoft has patched CVE-2026-50304, a remotely reachable denial-of-service vulnerability in Active Directory Federation Services that requires neither authentication nor user interaction. Organizations still operating AD FS should deploy the July 14, 2026 Windows security updates promptly...