AI analysis
CVE-2026-72978 is an unauthenticated denial-of-service flaw in Microsoft Active Directory Federation Services (AD FS) caused by allocation of resources without limits or throttling (CWE-770). An attacker triggers it by sending network requests that cause the AD FS service to allocate resources without bound, exhausting capacity; the high attack-complexity score (AC:H) indicates the exhaustion condition is not reliably achieved on every attempt. A successful attack yields availability impact only (A:H) — the federation service can be knocked offline, interrupting sign-in/SSO for users who depend on it, with no confidentiality or integrity impact. Organizations running AD FS — typically enterprises using federated authentication with Microsoft 365/Entra ID on Windows Server — are affected. There is currently no evidence of exploitation (not in CISA KEV, no public PoC), EPSS puts the 30-day exploitation probability at 0.8%, and the fix shipped in Microsoft's September 2026 Patch Tuesday, which resolved 966 flaws including 2 zero-days.
What to do: Apply the September 2026 Microsoft security updates to all AD FS federation servers, including primary and secondary farm members and any internet-facing Web Application Proxy (WAP) endpoints if deployed. Prioritize patching AD FS endpoints exposed to untrusted networks, since the flaw is triggerable by an unauthenticated network attacker. As an interim mitigation, enforce rate limiting or throttling of unauthenticated requests to AD FS sign-in endpoints at the load balancer or firewall.
Affected
| Microsoft Active Directory Federation Services (AD FS) | — |
Estimated exposure
largetens of thousands of AD FS servers/farms worldwide (deployment-pattern estimate; farms commonly run multiple servers) — No install counts appear in the source data, but AD FS remains a widely deployed federated-identity role in hybrid Microsoft 365/Entra ID environments and public internet scans have historically surfaced tens of thousands of exposed AD FS…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.