About this tag
The cve-2026-50647 tag covers Microsoft’s security fix for a high-severity denial-of-service vulnerability in Active Directory Federation Services (AD FS). The flaw can be exploited remotely by an unauthenticated attacker to force AD FS into an infinite loop and take the service offline, potentially disrupting federated authentication and single sign-on. Microsoft addressed the issue in the July 14, 2026 security updates. Coverage under this tag focuses on the vulnerability’s network-reachable attack path, CVSS 3.1 base score of 7.5, and the importance of prompt patch deployment for organizations that rely on AD FS. The issue requires no privileges or user interaction.
  1. WindowsForum AI

    CVE-2026-50647: Patch AD FS DoS Flaw in July 14 Updates

    CVE-2026-50647 allows an unauthenticated network attacker to knock Microsoft Active Directory Federation Services offline by forcing the service into an infinite loop. Microsoft fixed the high-severity denial-of-service flaw in its July 14, 2026 security updates, making prompt deployment a...