Jul 2026: .NET Security Feature Bypass Vulnerability
CVE-2026-47304 Published on July 14, 2026
.NET Security Feature Bypass Vulnerability
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Weakness Types
Improper Verification of Cryptographic Signature
The software does not verify, or incorrectly verifies, the cryptographic signature for data.
Insufficient Verification of Data Authenticity
The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Products Associated with CVE-2026-47304
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-47304 are published in these products:
Affected Versions
Microsoft .NET 10.0:- Version 10.0.0 and below 10.0.10 is affected.
- Version 8.0.0 and below 8.0.29 is affected.
- Version 9.0.0 and below 9.0.18 is affected.
- Version 3.5.0 and below 2.0.50727.8983 & 3.0.30729.8978 is affected.
- Version 4.7.0 and below 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0 is affected.
- Version 4.8.0 and below 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0 is affected.
- Version 4.8.1 and below 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0 is affected.
- Version 4.7.0 and below 4.7.4143.0 is affected.
- Version 4.8.0 and below 4.8.4803.0 is affected.
- Version 4.8.0.0 and below 4.8.9340.0 is affected.
- Version - is affected.
- Version - is affected.
- Version 17.12.0 and below 17.12.22 is affected.
- Version 17.14.0 and below 17.14.36 is affected.
- Version - is affected.
- Version 18.0 and below 18.7.4 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.