SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72978

MEDIUM · CVSS 5.9 EPSS 0.80%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Active Directory Federation Services (AD FS) is vulnerable due to the allocation of resources without proper limits or throttling, which can be exploited by unauthorized attackers to launch denial-of-service (DoS) attacks over the network. Organizations utilizing AD FS should prioritize this vulnerability to mitigate potential service disruptions and ensure the availability of their authentication services.

CVE
CVE-2026-72978
Severity
MEDIUM
CVSS
5.9
EPSS
0.80%

Original NVD Description

Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.