Known vulnerabilities in Microsoft .NET Framework
Vendor:
Microsoft
Software:
Microsoft .NET Framework
Software CPE:
cpe:2.3:a:microsoft:microsoft_net_framework:*:*:*:*:*:*:*:*
Website:
https://www.microsoft.com
Total vulnerabilities:
114
Public exploits:
17
Known exploited (KEV):
5
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.0.50727.8984 & 3.0.30729.8980
2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0
2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0
4.7.4144.0
2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0
2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0
4.8.4805.0
2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0
2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0
10.0.11
2.0.1309.0
4.18.26030.3011
1.3.74
2.0.964
11.3.2
10.0.26100.7463
2.7.10
2.7.8
10.0.6
2.0.50727.8983 & 3.0.30729.8978
4.8.9340.0
2.0.50727.9182 & 3.0.30729.9168
2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0
2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0
4.7.4143.0
2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0
2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0
2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0
2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0
4.8.4803.0
5104034
4.18.26040.7
10.0.8
1.2.7214.0
2.0.1193.0
10.0.9
4.8.9334.0 and 4.8.4802.0
4.8.4802.0
4.8.9334.0
2.0.50727.8982 & 3.0.30729.8976
2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0
4.7.4141.0
2.0.50727.9068 & 3.0.30729.9065 & 4.7.4141.0
2.0.50727.9181 & 3.0.30729.9165 & 4.8.4801.0
2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.0
4.8.4801.0
4.5
4
2.0 SP2
1.1 SP1
2.0.50727.8981
4.8.1.09321.01
4.8.1.09320.02
4.7.04137.06
10.0.14393.8519
4.7.04137.03
4.8.04798.04
4.8.04798.02
10.0.10240.20890
4.7.04126.02
10.0.14393.7699
4.7.04126.01
4.8.04775.02
4.8.04775.01
4.8.1.09294.01
4.8.4682.0
10.0.14393.6614
10.0.10240.20402
4.8.9206.0
4.7.4076.0
3.0.50727.8975
4.7.04063.05
4.8.04667.03
4.8.09186.0
4.8.09186.01
3.0.30729.8957
4.7.04063.01
4.7.04063.02
4.8.04667.02
4.8.1
3.0 Service Pack 2
4.8
4.7.2
4.7.1
4.6.2/4.7/4.7.1
4.7
4.5.1
4.0
4.6.2
2.0
1.1
3.0
3.5
4.6.1
3.5.1
4.6
4.5.2
2.0 Service Pack 2
Vulnerabilities (114)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU142006 - Use After Free CVE-2026-62898 |
CWE-416 | Medium | 10.0.11 | 12.08.2026 |
SB20260812233 SB2026081416 SB2026081417 and 4 more |
||
| #VU141984 - Relative Path Traversal CVE-2026-65810 |
CWE-23 | High | 2.0.50727.8984 & 3.0.30729.8980, 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0, 4.7.4144.0, 4.8.4805.0 | 12.08.2026 |
SB20260812233 |
||
| #VU141930 - Integer overflow CVE-2026-62886 |
CWE-190 | High | 10.0.11 | 12.08.2026 |
SB20260812233 SB2026081416 SB2026081417 and 4 more |
||
| #VU141925 - Incorrect Authorization CVE-2026-62872 |
CWE-863 | Low | 2.0.50727.8984 & 3.0.30729.8980, 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0, 4.7.4144.0, 4.8.4805.0 | 12.08.2026 |
SB20260812233 |
||
| #VU141795 - Unchecked Return Value CVE-2026-62909 |
CWE-252 | Low | 10.0.11 | 12.08.2026 |
SB20260812233 SB2026081360 SB2026081364 and 11 more |
||
| #VU141789 - Integer overflow CVE-2026-62897 |
CWE-190 | Medium | 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0, 10.0.11 | 12.08.2026 |
SB20260812233 SB2026081416 SB2026081417 and 4 more |
||
| #VU141498 - Out-of-bounds write CVE-2026-70354 |
CWE-787 | High | 2.0.50727.8984 & 3.0.30729.8980, 2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0, 2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0, 2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0, 4.7.4144.0, 4.8.4805.0, 10.0.11 | 11.08.2026 |
SB2026081155 SB2026081416 SB2026081417 and 4 more |
||
| #VU138288 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2026-50653 |
CWE-835 | Medium | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0 | 17.07.2026 |
SB2026071737 |
||
| #VU138287 - Deserialization of Untrusted Data CVE-2026-50652 |
CWE-502 | Medium | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0 | 17.07.2026 |
SB2026071737 |
||
| #VU138086 - Improper Control of Generation of Code ('Code Injection') CVE-2026-50650 |
CWE-94 | Low | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 | 17.07.2026 |
SB2026071706 SB2026082404 SB2026082405 |
||
| #VU138084 - Allocation of Resources Without Limits or Throttling CVE-2026-50648 |
CWE-770 | Medium | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 | 17.07.2026 |
SB2026071706 SB20260721104 SB2026082404 and 1 more |
||
| #VU138082 - Protection Mechanism Failure CVE-2026-50646 |
CWE-693 | Low | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 | 17.07.2026 |
SB2026071706 SB2026082404 SB2026082405 |
||
| #VU138080 - Stack-based buffer overflow CVE-2026-50527 |
CWE-121 | Medium | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 | 17.07.2026 |
SB2026071706 SB20260721104 SB2026082404 and 1 more |
||
| #VU137927 - Allocation of Resources Without Limits or Throttling CVE-2026-47302 |
CWE-770 | Medium | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0, 10.0.6 | 17.07.2026 |
SB2026071701 SB20260721104 SB2026082404 and 1 more |
||
| #VU134477 - Resource exhaustion CVE-2026-45591 |
CWE-400 | Medium | 10.0.9 | 12.06.2026 |
SB2026061277 SB2026061283 SB2026061284 and 10 more |
||
| #VU134336 - Use After Free CVE-2026-42985 |
CWE-416 | High | 1.2.7214.0, 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134335 - Use After Free CVE-2026-44801 |
CWE-416 | High | 1.2.7214.0, 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134334 - Heap-based Buffer Overflow CVE-2026-44799 |
CWE-122 | High | 1.2.7214.0, 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134333 - Heap-based Buffer Overflow CVE-2026-42992 |
CWE-122 | High | 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134327 - Heap-based Buffer Overflow CVE-2026-47289 |
CWE-122 | High | 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
Showing elements 1 - 20 out of 114