Net Microsoft Net

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Net.

Recent Microsoft Net Security Advisories

Advisory Title Published
CVE-2026-87573 Chromium CVE-2026-87573: Improper input validation in Network September 15, 2026
CVE-2026-87557 Chromium CVE-2026-87557: Missing authorization in LocalNetworkAccess September 15, 2026
CVE-2026-87539 Chromium CVE-2026-87539: Observable discrepancy in Network September 15, 2026
CVE-2026-87499 Chromium CVE-2026-87499: Incorrect authorization in Network September 15, 2026
CVE-2026-87447 Chromium CVE-2026-87447: Incorrect authorization in Network September 15, 2026
CVE-2026-76022 Chromium CVE-2026-76022: Buffer overflow in Network September 12, 2026
CVE-2026-85043 Chromium CVE-2026-85043: Incomplete cleanup in Network September 11, 2026
CVE-2026-69587 CVE-2026-69587 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability September 8, 2026
CVE-2026-72982 CVE-2026-72982 Windows Netlogon Remote Code Execution Vulnerability September 8, 2026
CVE-2026-72983 CVE-2026-72983 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability September 8, 2026

By the Year

In 2026 there have been 60 vulnerabilities in Microsoft Net with an average score of 7.4 out of ten. Last year, in 2025 Net had 8 security vulnerabilities published. That is, 52 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.08.




Year Vulnerabilities Average Score
2026 60 7.42
2025 8 7.34
2024 21 7.57
2023 34 7.46
2022 12 7.01
2021 8 6.76
2020 5 5.00

It may take a day or so for new Net vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Net Security Vulnerabilities

Sep 2026: .NET Elevation of Privilege Vulnerability
CVE-2026-69806 7 - High - September 08, 2026

Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.

Information Disclosure

Sep 2026: .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2026-71328 8.8 - High - September 08, 2026

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: ASP.NET Core Denial of Service Vulnerability
CVE-2026-69304 5.9 - Medium - September 08, 2026

Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Data Amplification

Sep 2026: .NET Information Disclosure Vulnerability
CVE-2026-58649 6.5 - Medium - September 08, 2026

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

Origin Validation Error

Sep 2026: .NET and Visual Studio Elevation of Privilege Vulnerability
CVE-2026-69439 8.8 - High - September 08, 2026

Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Heap-based Buffer Overflow

Sep 2026: .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2026-69522 8.8 - High - September 08, 2026

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Aug 2026: Microsoft QUIC Information Disclosure Vulnerability
CVE-2026-62898 7.5 - High - August 11, 2026

Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

Dangling pointer

Aug 2026: .NET Core Remote Code Execution Vulnerability
CVE-2026-70354 7.8 - High - August 11, 2026

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

Memory Corruption

Aug 2026: .NET Framework Elevation of Privilege Vulnerability
CVE-2026-65810 7.8 - High - August 11, 2026

Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.

Relative Path Traversal

Aug 2026: .NET Elevation of Privilege Vulnerability
CVE-2026-62886 7.8 - High - August 11, 2026

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

Integer Overflow or Wraparound

Aug 2026: .NET Framework Elevation of Privilege Vulnerability
CVE-2026-62872 8.8 - High - August 11, 2026

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

AuthZ

Aug 2026: .NET Elevation of Privilege Vulnerability
CVE-2026-62871 7.8 - High - August 11, 2026

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

Memory Corruption

Aug 2026: .NET Elevation of Privilege Vulnerability
CVE-2026-58641 7.8 - High - August 11, 2026

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

Integer Overflow or Wraparound

Aug 2026: .NET Elevation of Privilege Vulnerability
CVE-2026-62909 7.8 - High - August 11, 2026

Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.

Unchecked Return Value

Aug 2026: .NET Information Disclosure Vulnerability
CVE-2026-62902 6.5 - Medium - August 11, 2026

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

Inclusion of Functionality from Untrusted Control Sphere

Aug 2026: .NET Denial of Service Vulnerability
CVE-2026-62901 7.5 - High - August 11, 2026

Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.

Unchecked Input for Loop Condition

Aug 2026: .NET Information Disclosure Vulnerability
CVE-2026-62900 5.9 - Medium - August 11, 2026

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

Improper Removal of Sensitive Information Before Storage or Transfer

Aug 2026: .NET Security Feature Bypass Vulnerability
CVE-2026-62899 5.9 - Medium - August 11, 2026

Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.

HTTP Request Smuggling

Aug 2026: .NET Framework Remote Code Execution Vulnerability
CVE-2026-62897 7 - High - August 11, 2026

Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

Integer Overflow or Wraparound

Jul 2026: .NET Spoofing Vulnerability
CVE-2026-50659 6.5 - Medium - July 14, 2026

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

Output Sanitization

Jul 2026: .NET Denial of Service Vulnerability
CVE-2026-50651 7.5 - High - July 14, 2026

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Allocation of Resources Without Limits or Throttling

Jul 2026: .NET Framework Elevation of Privilege Vulnerability
CVE-2026-50650 7.8 - High - July 14, 2026

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

Code Injection

Jul 2026: .NET Remote Code Execution Vulnerability
CVE-2026-50649 7.8 - High - July 14, 2026

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

Marshaling, Unmarshaling

Jul 2026: .NET Framework Remote Code Execution Vulnerability
CVE-2026-50646 7.8 - High - July 14, 2026

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

Protection Mechanism Failure

Jul 2026: .NET Framework Denial of Service Vulnerability
CVE-2026-50648 7.5 - High - July 14, 2026

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

Allocation of Resources Without Limits or Throttling

Jul 2026: .NET Framework Denial of Service Vulnerability
CVE-2026-50527 7.5 - High - July 14, 2026

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

Stack Overflow

Jul 2026: .NET Security Feature Bypass Vulnerability
CVE-2026-50528 8.2 - High - July 14, 2026

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

AuthZ

Jul 2026: .NET Tampering Vulnerability
CVE-2026-50526 7 - High - July 14, 2026

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

insecure temporary file

Jul 2026: .NET Denial of Service Vulnerability
CVE-2026-50525 7.5 - High - July 14, 2026

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Allocation of Resources Without Limits or Throttling

Jul 2026: .NET Framework Denial of Service Vulnerability
CVE-2026-50524 7.5 - High - July 14, 2026

Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

Improper Validation of Specified Type of Input

Jul 2026: .NET Security Feature Bypass Vulnerability
CVE-2026-47304 8.1 - High - July 14, 2026

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

Improper Verification of Cryptographic Signature

Jul 2026: ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-47303 8.8 - High - July 14, 2026

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

Authentication Bypass by Assumed-Immutable Data

Jul 2026: .NET Denial of Service Vulnerability
CVE-2026-47302 7.5 - High - July 14, 2026

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Allocation of Resources Without Limits or Throttling

Jul 2026: ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-47300 8.8 - High - July 14, 2026

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

Incorrect Implementation of Authentication Algorithm

Jul 2026: .NET Denial of Service Vulnerability
CVE-2026-57108 7.5 - High - July 14, 2026

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

Object Type Confusion

Jul 2026: Active Directory Federation Server Denial of Service Vulnerability
CVE-2026-50647 7.5 - High - July 14, 2026

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

Infinite Loop

Jul 2026: Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50411 7.5 - High - July 14, 2026

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

Stack Overflow

Jul 2026: Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50355 7.5 - High - July 14, 2026

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

Stack Overflow

Jul 2026: Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50324 5.9 - Medium - July 14, 2026

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

Infinite Loop

Jul 2026: Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50368 7.5 - High - July 14, 2026

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

Stack Overflow

Jul 2026: Windows Active Directory Federation Services Denial of Service Vulnerability
CVE-2026-50304 7.5 - High - July 14, 2026

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

Stack Overflow

Jul 2026: Azure Active Directory Denial of Service Vulnerability
CVE-2026-50652 7.5 - High - July 14, 2026

Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

Marshaling, Unmarshaling

Jul 2026: Azure Active Directory Denial of Service Vulnerability
CVE-2026-50653 7.5 - High - July 14, 2026

Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

Infinite Loop

Jul 2026: ASP.NET Core Denial of Service Vulnerability
CVE-2026-56170 7.5 - High - July 14, 2026

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Allocation of Resources Without Limits or Throttling

Jun 2026: ASP.NET Core Denial of Service Vulnerability
CVE-2026-45591 7.5 - High - June 09, 2026

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Resource Exhaustion

Jun 2026: .NET Tampering Vulnerability
CVE-2026-45491 6.2 - Medium - June 09, 2026

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

insecure temporary file

Jun 2026: .NET SDK Elevation of Privilege Vulnerability
CVE-2026-45490 7.8 - High - June 09, 2026

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

AuthZ

May 2026: ASP.NET Core Denial of Service Vulnerability
CVE-2026-42899 7.5 - High - May 12, 2026

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Infinite Loop

May 2026: .NET Core Tampering Vulnerability
CVE-2026-32175 4.3 - Medium - May 12, 2026

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

Absolute Path Traversal

May 2026: .NET Elevation of Privilege Vulnerability
CVE-2026-35433 7.3 - High - May 12, 2026

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

Improper Input Validation

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Net or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

Microsoft Net
Product

subscribe