CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8553-1: .NET vulnerabilities

unknownCVE-2026-47300CVE-2026-47302CVE-2026-47303CVE-2026-47304CVE-2026-50524CVE-2026-50525
Artur Stetsko discovered that the .NET did not properly validate authentication data. An attacker could possibly use this issue to elevate privileges. (CVE-2026-47300) Levi Broderick discovered that .NET did not properly handle XML encryption during parsing. An attacker could possibly use this issue to consume excessive resources, resulting in a denial of service. (CVE-2026-47302) Pham Quang Minh discovered that .NET did not properly parse authentication data. An attacker could possibly use this issue to bypass authentication and elevate privileges. (CVE-2026-47303) Levi Broderick discovered that .NET did not properly verify cryptographic signatures during XML encryption. An attacker could possibly use this issue to bypass security features over a network and access encrypted data. (CVE-2026-47304) It was discovered that .NET did not properly validate input during TLS handshakes. An attacker could possibly use this issue to cause .NET to crash, resulting in a denial of service. (CVE-2026-50524) Levi Broderick discovered that .NET did not properly handle resource allocation during XML encryption. An attacker could possibly use this issue to consume excessive resources, resulting in a denial of service. (CVE-2026-50525) Siwei Li discovered that .NET did not properly handle link resolution before file access during the container image build process. A local attacker could possibly use this issue to inject resources that could be incorporated into container images built by other users on the same machine. (CVE-2026-50526) Levi Broderick discovered that .NET did not properly handle memory while performing XML encryption. An attacker could possibly use this issue to cause .NET to crash, resulting in a denial of service. (CVE-2026-50527) Henrique Pereira discovered that .NET did not properly handle authorization checks during TLS/SSL connections. An attacker could possibly use this issue to bypass authorization checks during secure communications. (CVE-2026-50528) It was d

CSIRTS triage

What
Multiple vulnerabilities in .NET could allow privilege escalation, denial of service, authentication bypass, and information disclosure.
Who is affected
Users of .NET are affected, particularly those using vulnerable features.
Urgency
Remediation is critical as these vulnerabilities could be exploited, though exploitation status is not confirmed.
Action
Update .NET to the latest version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch .NET

Get an email when a new .NET advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-07-15
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8553-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-47300coverage & exploitation statusNVD · CVE.org
CVE-2026-47302coverage & exploitation statusNVD · CVE.org
CVE-2026-47303coverage & exploitation statusNVD · CVE.org
CVE-2026-47304coverage & exploitation statusNVD · CVE.org
CVE-2026-50524coverage & exploitation statusNVD · CVE.org
CVE-2026-50525coverage & exploitation statusNVD · CVE.org
CVE-2026-50526coverage & exploitation statusNVD · CVE.org
CVE-2026-50527coverage & exploitation statusNVD · CVE.org
CVE-2026-50528coverage & exploitation statusNVD · CVE.org
CVE-2026-50648coverage & exploitation statusNVD · CVE.org
CVE-2026-50651coverage & exploitation statusNVD · CVE.org
CVE-2026-50659coverage & exploitation statusNVD · CVE.org
CVE-2026-57108coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices