PatchSiren cyber security CVE debrief
CVE-2026-57108 Microsoft CVE debrief
A high-severity vulnerability, CVE-2026-57108, was found in .NET Core, allowing an unauthorized attacker to deny service over a network via a type confusion exploit. This vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. It affects .NET Core versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6. Users of these versions should apply patches to prevent potential denial-of-service attacks. The vulnerability allows an attacker to exploit a type confusion weakness in .NET Core, potentially leading to service denial over a network. The CVE record was published on 2026-07-14T18:18:35.150Z and last modified on 2026-07-20T17:14:03.263Z.
- Vendor
- Microsoft
- Product
- .NET 10.0
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-22
Who should care
Users of .NET Core, particularly versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6, should apply patches to prevent potential denial-of-service attacks. Security teams and operators managing .NET Core installations should prioritize patching to mitigate the risk of service denial.
Technical summary
CVE-2026-57108 is a type confusion vulnerability in .NET Core. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. It allows an attacker to deny service over a network. The vulnerability affects .NET Core versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6. Users should verify their installations and apply patches as necessary.
Defensive priority
High priority should be given to patching .NET Core installations to prevent potential denial-of-service attacks. Security teams should review the vulnerability details and apply patches as necessary.
Recommended defensive actions
- Apply patches for affected .NET Core versions
- Inventory and update .NET Core installations
- Monitor for potential denial-of-service attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-14T18:18:35.150Z and last modified on 2026-07-20T17:14:03.263Z. The NVD entry is currently Analyzed. The vulnerability affects .NET Core versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6. Users should verify their installations and apply patches as necessary. The CVE details are based on information from official sources, but the impact and scope may vary depending on specific environments and configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-57108 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-57108
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-57108 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-57108
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57108
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.