PatchSiren cyber security CVE debrief
CVE-2026-57108 Microsoft CVE debrief
A high-severity vulnerability, CVE-2026-57108, was found in .NET Core, allowing an unauthorized attacker to deny service over a network via a type confusion exploit. This vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. It affects .NET Core versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6. Users of these versions should apply patches to prevent potential denial-of-service attacks. The vulnerability allows an attacker to exploit a type confusion weakness in .NET Core, potentially leading to service denial over a network. The CVE record was published on 2026-07-14T18:18:35.150Z and last modified on 2026-07-20T17:14:03.263Z.
- Vendor
- Microsoft
- Product
- .NET 10.0
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-20
Who should care
Users of .NET Core, particularly versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6, should apply patches to prevent potential denial-of-service attacks. Security teams and operators managing .NET Core installations should prioritize patching to mitigate the risk of service denial.
Technical summary
CVE-2026-57108 is a type confusion vulnerability in .NET Core. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. It allows an attacker to deny service over a network. The vulnerability affects .NET Core versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6. Users should verify their installations and apply patches as necessary.
Defensive priority
High priority should be given to patching .NET Core installations to prevent potential denial-of-service attacks. Security teams should review the vulnerability details and apply patches as necessary.
Recommended defensive actions
- Apply patches for affected .NET Core versions
- Inventory and update .NET Core installations
- Monitor for potential denial-of-service attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-14T18:18:35.150Z and last modified on 2026-07-20T17:14:03.263Z. The NVD entry is currently Analyzed. The vulnerability affects .NET Core versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6. Users should verify their installations and apply patches as necessary. The CVE details are based on information from official sources, but the impact and scope may vary depending on specific environments and configurations.
Official resources
-
CVE-2026-57108 CVE record
CVE.org
-
CVE-2026-57108 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:18:35.150Z and has not been modified since then. The NVD entry is currently Analyzed.