PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-50528 Microsoft CVE debrief

CVE-2026-50528 is a high-severity vulnerability in .NET that allows unauthorized attackers to bypass a security feature over a network. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. Microsoft .NET versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6 are affected. Additionally, Microsoft Visual Studio 2022 versions 17.12.0 to 17.12.22 and 17.14.0 to 17.14.36, as well as Visual Studio 2026 version 18.7.0 to 18.7.4, are also vulnerable. The vulnerability is caused by incorrect authorization in .NET, allowing unauthorized attackers to bypass a security feature over a network.

Vendor
Microsoft
Product
.NET 10.0
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-22
Advisory published
2026-07-14
Advisory updated
2026-07-22

Who should care

Organizations using affected versions of .NET or Microsoft Visual Studio should prioritize patching this vulnerability to prevent potential attacks. This includes reviewing and updating inventory of .NET and Visual Studio installations, implementing compensating controls to monitor and detect potential attacks, and verifying and enforcing secure configurations for .NET and Visual Studio.

Technical summary

The vulnerability is caused by incorrect authorization in .NET, allowing unauthorized attackers to bypass a security feature over a network. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N. The weakness types associated with this vulnerability are CWE-302, CWE-636, and CWE-863. The vulnerability affects Microsoft .NET versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6, as well as Microsoft Visual Studio 2022 versions 17.12.0 to 17.12.22 and 17.14.0 to 17.14.36, and Visual Studio 2026 version 18.7.0 to 18.7.4.

Defensive priority

High

Recommended defensive actions

  • Apply patches for affected .NET and Microsoft Visual Studio versions
  • Review and update inventory of .NET and Visual Studio installations
  • Implement compensating controls to monitor and detect potential attacks
  • Verify and enforce secure configurations for .NET and Visual Studio
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record was published on 2026-07-14T20:17:37.533Z and was last modified on 2026-07-22T21:17:41.353Z. The NVD entry is currently Analyzed. The vulnerability affects Microsoft .NET versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6, as well as Microsoft Visual Studio 2022 versions 17.12.0 to 17.12.22 and 17.14.0 to 17.14.36, and Visual Studio 2026 version 18.7.0 to 18.7.4. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-50528 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-50528

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-50528 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50528

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.