SB20260812233 - Multiple vulnerabilities in Microsoft .NET Framework
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 12 vulnerabilities.
1) Integer overflow (CVE-ID: CVE-2026-62897)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow or wraparound in .NET Framework when processing crafted content locally. A remote attacker can trigger the integer overflow to execute arbitrary code.
User interaction is required for exploitation, and successful exploitation is complex and requires precise conditions.
2) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-62899)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security feature.
The vulnerability exists due to inconsistent interpretation of http requests in .NET when handling http requests. A remote attacker can send crafted http requests to bypass a security feature.
Successful exploitation requires the target system to be configured in a specific manner and knowledge of that setup.
3) Improper Removal of Sensitive Information Before Storage or Transfer (CVE-ID: CVE-2026-62900)
CWE-ID: CWE-212 - Improper Removal of Sensitive Information Before Storage or Transfer
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper removal of sensitive information before storage or transfer in .NET when handling data over a network. A remote attacker can access exposed data to disclose sensitive information.
Successful exploitation requires that the target system be set up in a specific manner and that the attacker have knowledge of that setup. Credentials may be disclosed.
4) Unchecked Input for Loop Condition (CVE-ID: CVE-2026-62901)
CWE-ID: CWE-606 - Unchecked Input for Loop Condition
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to unchecked input for loop condition in .NET when handling network requests. A remote attacker can send crafted input to cause a denial of service.
5) Inclusion of Functionality from Untrusted Control Sphere (CVE-ID: CVE-2026-62902)
CWE-ID: CWE-829 - Inclusion of Functionality from Untrusted Control Sphere
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information over a network.
The vulnerability exists due to inclusion of functionality from untrusted control sphere in .NET when processing untrusted functionality. A remote attacker can trigger the vulnerable behavior to disclose sensitive information over a network.
User interaction is required to exploit the issue, and successful exploitation could disclose NTLM hashes.
6) Unchecked Return Value (CVE-ID: CVE-2026-62909)
CWE-ID: CWE-252 - Unchecked Return Value
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to unchecked return value in .NET when handling exceptional conditions. A local user can trigger an uncaught exception to elevate privileges.
Successful exploitation requires the target system to be set up in a specific manner and the attacker to have knowledge of that setup.
7) Integer overflow (CVE-ID: CVE-2026-58641)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to integer overflow or wraparound in .NET when processing crafted local input. A remote attacker can trigger the integer overflow to escalate privileges.
User interaction is required, and successful exploitation could result in SYSTEM privileges.
8) Out-of-bounds write (CVE-ID: CVE-2026-62871)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code locally.
The vulnerability exists due to out-of-bounds write in .NET when a user triggers the payload in the application. A remote attacker can craft a payload to execute arbitrary code locally.
Successful exploitation could result in SYSTEM privileges. User interaction is required.
9) Incorrect authorization (CVE-ID: CVE-2026-62872)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to elevate privileges.
The vulnerability exists due to incorrect authorization in .NET Framework when handling network requests. A remote user can send crafted requests to elevate privileges.
A successful exploit would grant the rights of the user running the affected application.
10) Integer overflow (CVE-ID: CVE-2026-62886)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to integer overflow or wraparound in .NET when a user triggers the payload in the application. A remote attacker can trigger a crafted payload to escalate privileges.
Successful exploitation could result in SYSTEM privileges. User interaction is required to trigger the payload in the application.
11) Relative Path Traversal (CVE-ID: CVE-2026-65810)
CWE-ID: CWE-23 - Relative Path Traversal
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to relative path traversal in .NET Framework when processing crafted local input. A remote attacker can supply a crafted relative path to escalate privileges.
User interaction is required for exploitation.
12) Use-after-free (CVE-ID: CVE-2026-62898)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use-after-free in Microsoft QUIC when handling network requests. A remote attacker can send crafted network traffic to disclose sensitive information.
An attacker who successfully exploited this vulnerability could potentially read portions of process memory.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62897
- https://support.microsoft.com/help/5120711
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62899
- https://support.microsoft.com/help/5122106
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62900
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62901
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62902
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62909
- https://dotnet.microsoft.com/download/dotnet/10.0
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-58641
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62871
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62872
- https://support.microsoft.com/help/5120702
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62886
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-65810
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-62898