Jul 2026: .NET Spoofing Vulnerability
CVE-2026-50659 Published on July 14, 2026
.NET Spoofing Vulnerability
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Weakness Type
What is an Output Sanitization Vulnerability?
The software prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
CVE-2026-50659 has been classified to as an Output Sanitization vulnerability or weakness.
Products Associated with CVE-2026-50659
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-50659 are published in these products:
Affected Versions
Microsoft .NET 10.0:- Version 10.0.0 and below 10.0.10 is affected.
- Version 8.0.0 and below 8.0.29 is affected.
- Version 9.0.0 and below 9.0.18 is affected.
- Version 3.5.0 and below 2.0.50727.8983 & 3.0.30729.8978 is affected.
- Version 4.7.0 and below 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0 is affected.
- Version 4.8.0 and below 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0 is affected.
- Version 4.8.1 and below 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0 is affected.
- Version 4.7.0 and below 4.7.4143.0 is affected.
- Version 4.8.0 and below 4.8.4803.0 is affected.
- Version 4.8.0.0 and below 4.8.9340.0 is affected.
- Version 17.12.0 and below 17.12.22 is affected.
- Version 17.14.0 and below 17.14.36 is affected.
- Version 18.0 and below 18.7.4 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.