CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8641-1: .NET vulnerabilities

unknownCVE-2026-62899CVE-2026-62900CVE-2026-62901CVE-2026-62909
Miha Zupan discovered that .NET did not properly interpret certain HTTP requests. An attacker could possibly use this issue to perform request smuggling and bypass a security feature. (CVE-2026-62899) Ivan Demchuk discovered that .NET did not properly handle the removal of sensitive information before storage or transfer. An attacker could possibly use this issue to disclose sensitive information. (CVE-2026-62900) Kevin Gosse discovered that .NET did not properly check an input for a loop condition. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-62901) Kevin Gosse discovered that .NET did not properly perform error checking when securing shared resources used for diagnostics IPC. An attacker could possibly use this issue to elevate privileges. (CVE-2026-62909)

CSIRTS triage

What
Multiple vulnerabilities in .NET including HTTP request smuggling, sensitive information disclosure, loop condition bypass, and privileged IPC error handling.
Who is affected
All .NET deployments using the affected versions.
Urgency
Unknown severity but spans multiple vulnerability classes affecting request handling, privilege escalation, and denial-of-service.
Action
Apply .NET security patches addressing CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, and CVE-2026-62909.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch .NET

Get an email when a new .NET advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-18
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8641-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-62899coverage & exploitation statusNVD · CVE.org
CVE-2026-62900coverage & exploitation statusNVD · CVE.org
CVE-2026-62901coverage & exploitation statusNVD · CVE.org
CVE-2026-62909coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices