Known vulnerabilities in Microsoft .NET Framework

Vendor: Microsoft
Software CPE: cpe:2.3:a:microsoft:microsoft_net_framework:*:*:*:*:*:*:*:*
Total vulnerabilities: 107
Public exploits: 17
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Microsoft .NET Framework Microsoft .NET Framework is affected by 107 known vulnerabilities: 2 critical, 46 high, 35 medium, 24 low Critical High Medium Low

Vulnerabilities (107)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU138288 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-50653
CWE-835 Medium
No
No
2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0 17.07.2026 SB2026071737
#VU138287 - Deserialization of Untrusted Data
CVE-2026-50652
CWE-502 Medium
No
No
2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0 17.07.2026 SB2026071737
#VU138086 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-50650
CWE-94 Low
No
No
2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 17.07.2026 SB2026071706
#VU138084 - Allocation of Resources Without Limits or Throttling
CVE-2026-50648
CWE-770 Medium
No
No
2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 17.07.2026 SB2026071706
SB20260721104
#VU138082 - Protection Mechanism Failure
CVE-2026-50646
CWE-693 Low
No
No
2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 17.07.2026 SB2026071706
#VU138080 - Stack-based buffer overflow
CVE-2026-50527
CWE-121 Medium
No
No
2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 17.07.2026 SB2026071706
SB20260721104
#VU137927 - Allocation of Resources Without Limits or Throttling
CVE-2026-47302
CWE-770 Medium
No
No
2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0, 10.0.6 17.07.2026 SB2026071701
SB20260721104
#VU134477 - Resource exhaustion
CVE-2026-45591
CWE-400 Medium
No
No
10.0.9 12.06.2026 SB2026061277
SB2026061283
SB2026061284
and 10 more
#VU134336 - Use After Free
CVE-2026-42985
CWE-416 High
No
No
1.2.7214.0, 2.0.1193.0 11.06.2026 SB2026061139
#VU134335 - Use After Free
CVE-2026-44801
CWE-416 High
No
No
1.2.7214.0, 2.0.1193.0 11.06.2026 SB2026061139
#VU134334 - Heap-based Buffer Overflow
CVE-2026-44799
CWE-122 High
No
No
1.2.7214.0, 2.0.1193.0 11.06.2026 SB2026061139
#VU134333 - Heap-based Buffer Overflow
CVE-2026-42992
CWE-122 High
No
No
2.0.1193.0 11.06.2026 SB2026061139
#VU134332 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-42913
CWE-362 High
No
No
1.2.7214.0 11.06.2026 SB2026061139
#VU134331 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-42909
CWE-362 High
No
No
1.2.7214.0, 2.0.1193.0 11.06.2026 SB2026061139
#VU134327 - Heap-based Buffer Overflow
CVE-2026-47289
CWE-122 High
No
No
2.0.1193.0 11.06.2026 SB2026061139
#VU134295 - Out-of-bounds read
CVE-2026-42908
CWE-125 Medium
No
No
2.0.1193.0 11.06.2026 SB2026061116
#VU134294 - Out-of-bounds read
CVE-2026-45639
CWE-125 Medium
No
No
1.2.7214.0, 2.0.1193.0 11.06.2026 SB2026061116
#VU134117 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-45491
CWE-59 Low
No
No
10.0.9 09.06.2026 SB2026060968
SB2026061283
SB2026061284
and 10 more
#VU134116 - Improper Authorization
CVE-2026-45490
CWE-285 Low
No
No
10.0.9 09.06.2026 SB2026060967
SB20260619133
SB20260619134
and 3 more
#VU131324 - Heap-based Buffer Overflow
CVE-2026-32177
CWE-122 Low
No
No
4.8.9334.0 and 4.8.4802.0 13.05.2026 SB2026051358
SB2026051478
SB2026051479
and 7 more


Showing elements 1 - 20 out of 107