PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58649 Microsoft CVE debrief

A .NET Information Disclosure Vulnerability exists due to an origin validation error, allowing unauthorized attackers to disclose information over a network. This vulnerability affects multiple .NET versions, including .NET 8.0, .NET 9.0, .NET 10.0, .NET 11.0, and Microsoft Visual Studio versions, including Microsoft Visual Studio 2022 version 17.14 and Microsoft Visual Studio 2026 version 18.9. Microsoft has released patches for this vulnerability. Defenders should assess exposure and apply patches to prevent information disclosure. The CVE record and NVD detail page provide information on the vulnerability, its impact, and affected versions.

Vendor
Microsoft
Product
.NET 10.0
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-08
Original CVE updated
2026-10-08
Advisory published
2026-09-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for .NET and Microsoft Visual Studio deployments should assess exposure and apply patches to prevent information disclosure.

Why it matters

CVE-2026-58649 is a .NET Information Disclosure Vulnerability that allows unauthorized attackers to disclose information over a network. Defenders responsible for .NET and Microsoft Visual Studio deployments should assess exposure and apply patches to prevent information disclosure.

  • Verify inventory of .NET and Microsoft Visual Studio versions for exposure
  • Apply patches to prevent information disclosure
  • Monitor for unauthorized access to sensitive information

Technical summary

An origin validation error in .NET allows an unauthorized attacker to disclose information over a network. Affected versions include .NET 8.0, .NET 9.0, .NET 10.0, .NET 11.0, Microsoft Visual Studio 2022 version 17.14, and Microsoft Visual Studio 2026 version 18.9.

Defensive priority

Apply patches for affected .NET and Microsoft Visual Studio versions to prevent information disclosure.

Recommended defensive actions

  • Apply patches for affected .NET 8.0, .NET 9.0, .NET 10.0, and .NET 11.0 versions
  • Apply patches for affected Microsoft Visual Studio 2022 version 17.14 and Microsoft Visual Studio 2026 version 18.9
  • Verify inventory of .NET and Microsoft Visual Studio versions for exposure

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, its impact, and affected versions. Microsoft has released a patch for this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58649 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58649

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58649 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58649

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • .NET Information Disclosure Vulnerability

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/58xxx/CVE-2026-58649.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58649

    Supplemental source - vendor-advisory, patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.