CVE-2026-50355: AD FS Denial of Service Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50355 is a Denial of Service vulnerability affecting Windows Active Directory Federation Services (AD FS), a widely used authentication and identity federation component in Microsoft and Azure environments. The latest update revises product information in the software update table, representing an informational change rather than a new patch or changed severity. Organisations relying on AD FS for federated identity — including hybrid Azure AD deployments — should review their exposure to service disruption. ...

16 July 2025 · ZX Cloud Security

CVE-2026-50368: AD FS Denial of Service Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50368 is a Denial of Service vulnerability affecting Windows Active Directory Federation Services (AD FS), a critical identity federation component widely used in hybrid Azure environments. An attacker exploiting this flaw could disrupt authentication services, potentially locking users out of applications and cloud resources. This update revises product information in the advisory but does not change the underlying severity or remediation guidance. Security Architect’s Take: Review your AD FS deployments — particularly those federated with Azure AD/Entra ID — and confirm that the relevant patches are applied. Consider whether redundant AD FS nodes and health monitoring are in place to mitigate availability impact while patching is scheduled. ...

16 July 2025 · ZX Cloud Security

CVE-2026-50411: Windows AD FS DoS Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50411 is a Denial of Service vulnerability affecting Windows Active Directory Federation Services (AD FS), a widely used identity federation component in Microsoft environments. An attacker exploiting this flaw could disrupt authentication services, potentially locking users out of applications and resources that rely on AD FS for federated identity. Microsoft has issued an informational update to the affected software table, indicating no change to severity or patch status. ...

16 July 2025 · ZX Cloud Security

CVE-2026-50647: AD FS Denial of Service Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50647 is a Denial of Service vulnerability affecting Microsoft’s Active Directory Federation Services (AD FS). A successful exploit could allow an attacker to disrupt authentication services, potentially rendering federated identity and single sign-on capabilities unavailable. This is particularly significant for organisations relying on AD FS for hybrid identity scenarios connecting on-premises environments to Azure and Microsoft 365. Security Architect’s Take: Review your AD FS infrastructure and apply the relevant patches listed in the updated Software Update table immediately; additionally, consider whether your architecture can shift federated authentication workloads to Azure AD (Entra ID) native authentication to reduce reliance on AD FS as an attack surface. ...

16 July 2025 · ZX Cloud Security

CVE-2026-50652: Azure Active Directory DoS Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50652 is a Denial of Service vulnerability affecting Azure Active Directory (now Microsoft Entra ID), which organisations rely on for identity and access management across cloud and hybrid environments. A successful exploit could disrupt authentication services, potentially locking users and applications out of critical resources. Microsoft has issued an update to the affected software table, though the core advisory details remain unchanged. Security Architect’s Take: Review your Azure AD / Entra ID resilience posture — ensure you have fallback authentication paths and monitor for unusual sign-in failures or token issuance errors that could indicate exploitation. Apply any patches listed in the updated Software Update table promptly and validate that conditional access policies remain intact post-update. ...

16 July 2025 · ZX Cloud Security

CVE-2026-50653: Azure Active Directory DoS Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50653 is a Denial of Service vulnerability affecting Azure Active Directory (now Microsoft Entra ID), which handles authentication and access control for millions of Microsoft cloud services. A successful exploit could disrupt sign-in and identity services, potentially locking users out of Azure workloads. The advisory has been updated with revised product information, though no changes to severity or remediation guidance have been made. ...

16 July 2025 · ZX Cloud Security

CVE-2026-56171: Windows RDP Info Disclosure Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-56171 is an information disclosure vulnerability in Windows Remote Desktop Protocol (RDP) that allows an unauthenticated attacker to intercept or expose private data transmitted over a network connection. The flaw stems from improper handling of sensitive information, meaning personal or confidential data could be accessed without any valid credentials. RDP is widely used to manage Windows-based cloud virtual machines, making this a significant risk for Azure and hybrid environments. ...

16 July 2025 · ZX Cloud Security

CVE-2026-58598 Windows Backup Service Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A race condition vulnerability in the Windows Backup Service allows a locally authenticated attacker to gain elevated privileges on affected systems. The flaw arises from improper synchronisation when multiple processes access a shared resource concurrently. While local access is required, successful exploitation could grant an attacker SYSTEM-level privileges, making it a useful component in a broader attack chain. Security Architect’s Take: Prioritise patching Windows endpoints and Azure VMs running affected Windows versions, particularly those exposed to multiple users or running workloads with lower-privileged accounts. Review your VM patching cadence in Azure Update Manager and ensure backup service exposure is minimised through least-privilege configurations. ...

16 July 2025 · ZX Cloud Security

CVE-2026-58643: Windows Admin Center XSS Spoofing Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-58643 is a cross-site scripting (XSS) vulnerability in Windows Admin Center, Microsoft’s browser-based server management tool. It allows an unauthenticated attacker on the network to inject malicious scripts into the web interface, potentially spoofing content or hijacking administrator sessions. Given that Windows Admin Center is commonly used to manage critical server infrastructure, exploitation could lead to privilege escalation or unauthorised administrative access. Security Architect’s Take: Restrict access to Windows Admin Center to trusted networks or VPN-only connections immediately, and apply Microsoft’s patch as a priority. Review gateway role deployments exposed to broader network segments and consider enabling multi-factor authentication on all admin portal access. ...

16 July 2025 · ZX Cloud Security

n8n JWT Issuer Flaw Allows Account Takeover

🟠 High | Source: The Hacker News n8n’s Enterprise workflow automation platform contains a flaw where JWT-based logins are matched to local users using only the ‘sub’ (subject) claim, without validating the ‘iss’ (issuer) claim. This means a valid token from one trusted identity provider can be used to authenticate as a completely different user registered under a separate issuer. An attacker with a legitimate account on one connected identity provider could potentially log in as any other user on the same n8n instance. ...

16 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options