CVE-2026-50684
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
نوع الضعف
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
المنتجات المتأثرة
- microsoft windows_10_1607
- microsoft windows_10_1809
- microsoft windows_server_2012
- microsoft windows_server_2016
- microsoft windows_server_2019
- microsoft windows_server_2022
- microsoft windows_server_2025
المراجع
اكتشف الثغرة قبل أن يكتشفها المهاجم.
سجّل الدخول عبر GitHub وشغّل أول تدقيق لك في أقل من دقيقة. الخطة المجانية لا تتطلب بطاقة ائتمان.