PatchSiren cyber security CVE debrief
CVE-2026-50528 Microsoft CVE debrief
CVE-2026-50528 is a high-severity vulnerability in .NET that allows unauthorized attackers to bypass a security feature over a network. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. Microsoft .NET versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6 are affected. Additionally, Microsoft Visual Studio 2022 versions 17.12.0 to 17.12.22 and 17.14.0 to 17.14.36, as well as Visual Studio 2026 version 18.7.0 to 18.7.4, are also vulnerable. The vulnerability is caused by incorrect authorization in .NET, allowing unauthorized attackers to bypass a security feature over a network.
- Vendor
- Microsoft
- Product
- .NET 10.0
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-22
Who should care
Organizations using affected versions of .NET or Microsoft Visual Studio should prioritize patching this vulnerability to prevent potential attacks. This includes reviewing and updating inventory of .NET and Visual Studio installations, implementing compensating controls to monitor and detect potential attacks, and verifying and enforcing secure configurations for .NET and Visual Studio.
Technical summary
The vulnerability is caused by incorrect authorization in .NET, allowing unauthorized attackers to bypass a security feature over a network. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N. The weakness types associated with this vulnerability are CWE-302, CWE-636, and CWE-863. The vulnerability affects Microsoft .NET versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6, as well as Microsoft Visual Studio 2022 versions 17.12.0 to 17.12.22 and 17.14.0 to 17.14.36, and Visual Studio 2026 version 18.7.0 to 18.7.4.
Defensive priority
High
Recommended defensive actions
- Apply patches for affected .NET and Microsoft Visual Studio versions
- Review and update inventory of .NET and Visual Studio installations
- Implement compensating controls to monitor and detect potential attacks
- Verify and enforce secure configurations for .NET and Visual Studio
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-14T20:17:37.533Z and was last modified on 2026-07-22T21:17:41.353Z. The NVD entry is currently Analyzed. The vulnerability affects Microsoft .NET versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6, as well as Microsoft Visual Studio 2022 versions 17.12.0 to 17.12.22 and 17.14.0 to 17.14.36, and Visual Studio 2026 version 18.7.0 to 18.7.4. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N.
Official resources
-
CVE-2026-50528 CVE record
CVE.org
-
CVE-2026-50528 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T20:17:37.533Z and has not been modified since then. The NVD entry is currently Analyzed.