Description
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
Published: 2026-07-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Active Directory Federation Services component of Windows 11 allows an out‑of‑bounds read that could expose sensitive information to an attacker with legitimate credentials. The defect is described as a memory safety issue (CWE‑125) that permits disclosure of confidential data over the network, potentially violating confidentiality without compromising integrity or availability. If exploited, the attacker could obtain sensitive system state information that may aid in further intrusions.

Affected Systems

Microsoft Windows 11 version 26H1 is the only product explicitly identified as vulnerable. The issue resides within the A.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating a high severity, but its EPSS score is below 1 %, pointing to a low probability of widespread exploitation. It is not listed in the CISA KEV catalog. The attack requires an attacker who already holds authorized access to the environment, as the out‑of‑bounds read can only be triggered from within the ADFS process. The impact is limited to information disclosure rather than code execution or denial of service.

Generated by OpenCVE AI on July 31, 2026 at 06:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the official Microsoft security update for Windows 11 26H1 that addresses the ADFS out‑of‑bounds read flaw.
  • Restrict ADFS service access to only users on those accounts.
  • Activate and review ADFS and security logs for anomalous authentication requests or abnormal data exposure patterns.

Generated by OpenCVE AI on July 31, 2026 at 06:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
Title Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 11 26h1
Weaknesses CWE-125
CPEs cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:59:12.527Z

Reserved: 2026-07-01T04:33:41.869Z

Link: CVE-2026-58529

cve-icon Vulnrichment

Updated: 2026-07-14T17:45:26.344Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:15:04Z

Weaknesses