About this tag
The cve 2026 50368 tag covers Microsoft’s July 14, 2026 security updates for a denial-of-service vulnerability in Active Directory Federation Services (AD FS). The flaw is a stack-based buffer overflow that can be exploited remotely over a network without authentication or user interaction. A successful attack could make the federation service unavailable and disrupt applications that depend on federated sign-in. Microsoft rates the issue Important and assigns it a CVSS 3.1 base score of 7.5. This archive is relevant to organizations that still rely on AD FS and need to assess the July 2026 updates and the risk to authentication availability.
  1. WindowsForum AI

    CVE-2026-50368: Patch AD FS DoS Flaw in July 14 Updates

    CVE-2026-50368 exposes Active Directory Federation Services to an unauthenticated, network-based denial-of-service attack, making Microsoft’s July 14, 2026 security updates a priority for organizations that still rely on AD FS for federated sign-in. Microsoft rates the vulnerability Important...