PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-50528 Microsoft CVE debrief

CVE-2026-50528 is a high-severity vulnerability in .NET that allows unauthorized attackers to bypass a security feature over a network. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. Microsoft .NET versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6 are affected. Additionally, Microsoft Visual Studio 2022 versions 17.12.0 to 17.12.22 and 17.14.0 to 17.14.36, as well as Visual Studio 2026 version 18.7.0 to 18.7.4, are also vulnerable. The vulnerability is caused by incorrect authorization in .NET, allowing unauthorized attackers to bypass a security feature over a network.

Vendor
Microsoft
Product
.NET 10.0
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-22
Advisory published
2026-07-14
Advisory updated
2026-07-22

Who should care

Organizations using affected versions of .NET or Microsoft Visual Studio should prioritize patching this vulnerability to prevent potential attacks. This includes reviewing and updating inventory of .NET and Visual Studio installations, implementing compensating controls to monitor and detect potential attacks, and verifying and enforcing secure configurations for .NET and Visual Studio.

Technical summary

The vulnerability is caused by incorrect authorization in .NET, allowing unauthorized attackers to bypass a security feature over a network. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N. The weakness types associated with this vulnerability are CWE-302, CWE-636, and CWE-863. The vulnerability affects Microsoft .NET versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6, as well as Microsoft Visual Studio 2022 versions 17.12.0 to 17.12.22 and 17.14.0 to 17.14.36, and Visual Studio 2026 version 18.7.0 to 18.7.4.

Defensive priority

High

Recommended defensive actions

  • Apply patches for affected .NET and Microsoft Visual Studio versions
  • Review and update inventory of .NET and Visual Studio installations
  • Implement compensating controls to monitor and detect potential attacks
  • Verify and enforce secure configurations for .NET and Visual Studio
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record was published on 2026-07-14T20:17:37.533Z and was last modified on 2026-07-22T21:17:41.353Z. The NVD entry is currently Analyzed. The vulnerability affects Microsoft .NET versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6, as well as Microsoft Visual Studio 2022 versions 17.12.0 to 17.12.22 and 17.14.0 to 17.14.36, and Visual Studio 2026 version 18.7.0 to 18.7.4. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T20:17:37.533Z and has not been modified since then. The NVD entry is currently Analyzed.