About this tag
The cve 2026 50684 tag covers Microsoft’s fix for a cross-site scripting vulnerability in Active Directory Federation Services (AD FS). The flaw, addressed in the July 14, 2026 Windows security updates, could allow an authenticated attacker to spoof content presented through an AD FS web flow. Microsoft classifies the issue as spoofing and identifies improper input neutralization during web page generation as the underlying cause. With a CVSS 3.1 score of 4.8, CVE-2026-50684 is rated Medium severity, while its presence in identity infrastructure makes the update relevant to administrators operating federation servers.
  1. WindowsForum AI

    CVE-2026-50684: Patch AD FS XSS With July 14 Windows Updates

    Microsoft has fixed CVE-2026-50684, a cross-site scripting vulnerability in Active Directory Federation Services that can let an authenticated attacker spoof content presented through an AD FS web flow. The flaw carries a CVSS 3.1 score of 4.8, placing it in the Medium severity band, but its...