PatchSiren cyber security CVE debrief
CVE-2026-70354 Microsoft CVE debrief
The CVE-2026-70354 vulnerability is an out-of-bounds write issue in .NET that allows an unauthorized attacker to execute code locally. This issue affects multiple .NET and .NET Framework versions across various Windows operating systems and Visual Studio versions. The vulnerability has a CVSS score of 7.8 and is considered High severity. Affected products include .NET 10.0, .NET 8.0, .NET 9.0, Microsoft .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, 4.8.1, Microsoft Visual Studio 2022 version 17.14, and Microsoft Visual Studio 2026 version 18.8. The vulnerability details are based on the official CVE Program record, NVD vulnerability detail, and a source reference from vendor.
- Vendor
- Microsoft
- Product
- .NET 10.0
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for .NET and .NET Framework deployments, particularly those managing Windows systems with .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1 installed, should assess their exposure and apply security updates. This includes administrators of Windows 10, Windows Server 2016, Windows Server 2019, and Windows Server 2022, as well as developers using Visual Studio 2022 and 2026.
Why it matters
CVE-2026-70354 is a High-severity vulnerability in .NET and .NET Framework that allows unauthorized local code execution. Defenders managing .NET deployments should assess exposure, prioritize patching, and consider compensating controls.
- Defenders need to verify .NET and .NET Framework versions in their environment and apply patches to prevent local code execution.
- Exposure exists in various Windows and Visual Studio versions; verifying inventory is crucial.
- Remediation requires updating affected .NET and .NET Framework versions to 10.0.11, 8.0.30, 9.0.19 or later.
- The vulnerability's impact requires compensating controls like restricted local access and enhanced monitoring.
Technical summary
The CVE-2026-70354 vulnerability is caused by an out-of-bounds write in .NET, which can allow an unauthorized attacker to execute code locally. Affected products include .NET 10.0, .NET 8.0, .NET 9.0, Microsoft .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, 4.8.1, Microsoft Visual Studio 2022 version 17.14, and Microsoft Visual Studio 2026 version 18.8. The vulnerability has a CVSS score of 7.8 and is considered High severity.
Defensive priority
High
Recommended defensive actions
- Review and apply the security updates provided by Microsoft for affected .NET and .NET Framework versions.
- Assess exposure of .NET and .NET Framework versions in your environment, focusing on versions prior to 10.0.11, 8.0.30, and 9.0.19.
- Inventory and verify the versions of .NET, .NET Framework, and Visual Studio in use, particularly versions of .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1.
- Consider compensating controls such as restricting local access to sensitive systems and enhancing monitoring for suspicious local activity.
Evidence notes
The vulnerability details are based on the official CVE Program record, NVD vulnerability detail, and a source reference from Microsoft's MSRC update guide.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-70354 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-70354
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-70354 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70354
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
.NET Core Remote Code Execution Vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/70xxx/CVE-2026-70354.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70354
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.