HIGH
Azure Active Directory Denial of Service Vulnerability
Published Jul 14, 2026
7.5
HIGHCVSS 3.1
EPSS 1.73%
Description
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
Affected products
-
- Version 2021StatusaffectedConstraints<5.7.1
- Version
-
- Version 3.5.0StatusaffectedConstraints<2.0.50727.9182 & 3.0.30729.9168
- Version
-
- Version 4.7.0StatusaffectedConstraints<2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0
- Version
-
- Version 4.8.0StatusaffectedConstraints<2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0
- Version
-
- Version 4.8.1StatusaffectedConstraints<2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0
- Version
-
- Version 4.7.0StatusaffectedConstraints<4.7.4143.0
- Version
-
- Version 4.8.0StatusaffectedConstraints<4.8.4803.0
- Version
-
- Version 4.8.0.0StatusaffectedConstraints<4.8.9340.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Azure Active Directory | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8.1 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 4.8 | n/a |
| ||||||
| Microsoft | Microsoft .NET Framework 4.8.1 | n/a |
|
Configuration 1
AND
- 3.5
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- r2
- n/a
- n/a
- n/a
Configuration 2
AND
- 4.8.1
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 3
AND
- 4.6.2
Running on/with
OR
- n/a
- r2
Configuration 4
AND
- 4.7
Running on/with
OR
- n/a
- r2
Configuration 5
AND
- 4.7.1
Running on/with
OR
- n/a
- r2
Configuration 6
AND
- 4.7.2
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- r2
- n/a
- n/a
Configuration 7
AND
- 4.8
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- r2
- n/a
- n/a
- n/a
Configuration 8
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50652 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50652 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Jul 14, 2026
Updated Sep 25, 2026
Reserved Jun 5, 2026
Link CVE-2026-50652
CISA Vulnrichment
Updated Jul 14, 2026