CVE-2026-50651
Artur Stetsko discovered that the .NET did not properly validate authentication data. An attacker could possibly use this issue to elevate privileges. (CVE-2026-47300) Levi Broderick discovered that .NET did not properly handle XML encryption during parsing. An attacker could possibly use this issue to consume excessive resources, resulting in a denial of service. (CVE-2026-47302) Pham Quang Minh discovered that .NET did not properly parse authentication data. An attacker could possibly use this issue to bypass authentication and elevate privileges. (CVE-2026-47303) Levi Broderick discovered that .NET did not properly verify cryptographic signatures during XML encryption. An attacker could possibly use this issue to bypass security features over a network and access encrypted data. (CVE-2026-47304) It was discovered that .NET did not properly validate input during TLS handshakes. An attacker could possibly use this issue to cause .NET to crash, resulting in a denial of service. (CVE-2026-50524) Levi Broderick discovered that .NET did not properly handle resource allocation during XML encryption. An attacker could possibly use this issue to consume excessive resources, resulting in a denial of service. (CVE-2026-50525) Siwei Li discovered that .NET did not properly handle link resolution before file access during the container image build process. A local attacker could possibly use this issue to inject resources that could be incorporated into container images built by other users on the same machine. (CVE-2026-50526) Levi Broderick discovered that .NET did not properly handle memory while performing XML encryption. An attacker could possibly use this issue to cause .NET to crash, resulting in a denial of service. (CVE-2026-50527) Henrique Pereira discovered that .NET did not properly handle authorization checks during TLS/SSL connections. An attacker could possibly use this issue to bypass authorization checks during secure communications. (CVE-2026-50528) It was d
CSIRTS triage
- What
- Multiple vulnerabilities in .NET could allow privilege escalation, denial of service, authentication bypass, and information disclosure.
- Who is affected
- Users of .NET are affected, particularly those using vulnerable features.
- Urgency
- Remediation is critical as these vulnerabilities could be exploited, though exploitation status is not confirmed.
- Action
- Update .NET to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-50651
Get an email if CVE-2026-50651 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.84% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
Advisory coverage (7)
- high[NEW] [high] Microsoft DeveloperTools: Multiple vulnerabilitiescert-bund · 2026-07-23
- highGHSA-wp74-jgxh-gv4q: Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerabilityghsa · 2026-07-20
- unknownUSN-8553-1: .NET vulnerabilitiesubuntu · 2026-07-15
- unknownMultiple vulnerabilities in Microsoft .Net (July 15, 2026)cert-fr-avis · 2026-07-15
- highCVE-2026-50651: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker t…nvd · 2026-07-14
- unknownNCSC-2026-0235 [1.00] [M/H] Vulnerabilities fixed in Microsoft Developer Toolsncsc-nl · 2026-07-14
- highCVE-2026-50651: .NET Denial of Service Vulnerabilitymsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-50651)