ZeroHour

CVE-2026-72978

large

Unauthenticated DoS in Microsoft Active Directory Federation Services (AD FS)

CVSS 3.1
5.9 medium
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-72978 is an unauthenticated denial-of-service flaw in Microsoft Active Directory Federation Services (AD FS) caused by allocation of resources without limits or throttling (CWE-770). An attacker triggers it by sending network requests that cause the AD FS service to allocate resources without bound, exhausting capacity; the high attack-complexity score (AC:H) indicates the exhaustion condition is not reliably achieved on every attempt. A successful attack yields availability impact only (A:H) — the federation service can be knocked offline, interrupting sign-in/SSO for users who depend on it, with no confidentiality or integrity impact. Organizations running AD FS — typically enterprises using federated authentication with Microsoft 365/Entra ID on Windows Server — are affected. There is currently no evidence of exploitation (not in CISA KEV, no public PoC), EPSS puts the 30-day exploitation probability at 0.8%, and the fix shipped in Microsoft's September 2026 Patch Tuesday, which resolved 966 flaws including 2 zero-days.

What to do: Apply the September 2026 Microsoft security updates to all AD FS federation servers, including primary and secondary farm members and any internet-facing Web Application Proxy (WAP) endpoints if deployed. Prioritize patching AD FS endpoints exposed to untrusted networks, since the flaw is triggerable by an unauthenticated network attacker. As an interim mitigation, enforce rate limiting or throttling of unauthenticated requests to AD FS sign-in endpoints at the load balancer or firewall.

Affected
Microsoft Active Directory Federation Services (AD FS)
Estimated exposure
largetens of thousands of AD FS servers/farms worldwide (deployment-pattern estimate; farms commonly run multiple servers) — No install counts appear in the source data, but AD FS remains a widely deployed federated-identity role in hybrid Microsoft 365/Entra ID environments and public internet scans have historically surfaced tens of thousands of exposed AD FS…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1