Known vulnerabilities in Microsoft .NET Framework
Vendor:
Microsoft
Software:
Microsoft .NET Framework
Software CPE:
cpe:2.3:a:microsoft:microsoft_net_framework:*:*:*:*:*:*:*:*
Website:
https://www.microsoft.com
Total vulnerabilities:
107
Public exploits:
17
Known exploited (KEV):
5
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
4.18.26030.3011
1.3.74
2.0.964
11.3.2
10.0.26100.7463
2.7.10
2.7.8
10.0.6
2.0.50727.8983 & 3.0.30729.8978
4.8.9340.0
2.0.50727.9182 & 3.0.30729.9168
2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0
2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0
4.7.4143.0
2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0
2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0
2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0
2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0
4.8.4803.0
5104034
4.18.26040.7
10.0.8
1.2.7214.0
2.0.1193.0
10.0.9
4.8.9334.0 and 4.8.4802.0
4.8.4802.0
4.8.9334.0
2.0.50727.8982 & 3.0.30729.8976
2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0
4.7.4141.0
2.0.50727.9068 & 3.0.30729.9065 & 4.7.4141.0
2.0.50727.9181 & 3.0.30729.9165 & 4.8.4801.0
2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.0
4.8.4801.0
4.5
4
2.0 SP2
1.1 SP1
2.0.50727.8981
4.8.1.09321.01
4.8.1.09320.02
4.7.04137.06
10.0.14393.8519
4.7.04137.03
4.8.04798.04
4.8.04798.02
10.0.10240.20890
4.7.04126.02
10.0.14393.7699
4.7.04126.01
4.8.04775.02
4.8.04775.01
4.8.1.09294.01
4.8.4682.0
10.0.14393.6614
10.0.10240.20402
4.8.9206.0
4.7.4076.0
3.0.50727.8975
4.7.04063.05
4.8.04667.03
4.8.09186.0
4.8.09186.01
3.0.30729.8957
4.7.04063.01
4.7.04063.02
4.8.04667.02
4.8.1
3.0 Service Pack 2
4.8
4.7.2
4.7.1
4.6.2/4.7/4.7.1
4.7
4.5.1
4.0
4.6.2
2.0
1.1
3.0
3.5
4.6.1
3.5.1
4.6
4.5.2
2.0 Service Pack 2
Vulnerabilities (107)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU138288 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2026-50653 |
CWE-835 | Medium | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0 | 17.07.2026 |
SB2026071737 |
||
| #VU138287 - Deserialization of Untrusted Data CVE-2026-50652 |
CWE-502 | Medium | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0 | 17.07.2026 |
SB2026071737 |
||
| #VU138086 - Improper Control of Generation of Code ('Code Injection') CVE-2026-50650 |
CWE-94 | Low | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 | 17.07.2026 |
SB2026071706 |
||
| #VU138084 - Allocation of Resources Without Limits or Throttling CVE-2026-50648 |
CWE-770 | Medium | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 | 17.07.2026 |
SB2026071706 SB20260721104 |
||
| #VU138082 - Protection Mechanism Failure CVE-2026-50646 |
CWE-693 | Low | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 | 17.07.2026 |
SB2026071706 |
||
| #VU138080 - Stack-based buffer overflow CVE-2026-50527 |
CWE-121 | Medium | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0 | 17.07.2026 |
SB2026071706 SB20260721104 |
||
| #VU137927 - Allocation of Resources Without Limits or Throttling CVE-2026-47302 |
CWE-770 | Medium | 2.0.50727.8983 & 3.0.30729.8978, 2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0, 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0, 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0, 4.7.4143.0, 4.8.4803.0, 4.8.9340.0, 10.0.6 | 17.07.2026 |
SB2026071701 SB20260721104 |
||
| #VU134477 - Resource exhaustion CVE-2026-45591 |
CWE-400 | Medium | 10.0.9 | 12.06.2026 |
SB2026061277 SB2026061283 SB2026061284 and 10 more |
||
| #VU134336 - Use After Free CVE-2026-42985 |
CWE-416 | High | 1.2.7214.0, 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134335 - Use After Free CVE-2026-44801 |
CWE-416 | High | 1.2.7214.0, 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134334 - Heap-based Buffer Overflow CVE-2026-44799 |
CWE-122 | High | 1.2.7214.0, 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134333 - Heap-based Buffer Overflow CVE-2026-42992 |
CWE-122 | High | 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134332 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2026-42913 |
CWE-362 | High | 1.2.7214.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134331 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2026-42909 |
CWE-362 | High | 1.2.7214.0, 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134327 - Heap-based Buffer Overflow CVE-2026-47289 |
CWE-122 | High | 2.0.1193.0 | 11.06.2026 |
SB2026061139 |
||
| #VU134295 - Out-of-bounds read CVE-2026-42908 |
CWE-125 | Medium | 2.0.1193.0 | 11.06.2026 |
SB2026061116 |
||
| #VU134294 - Out-of-bounds read CVE-2026-45639 |
CWE-125 | Medium | 1.2.7214.0, 2.0.1193.0 | 11.06.2026 |
SB2026061116 |
||
| #VU134117 - Improper Link Resolution Before File Access ('Link Following') CVE-2026-45491 |
CWE-59 | Low | 10.0.9 | 09.06.2026 |
SB2026060968 SB2026061283 SB2026061284 and 10 more |
||
| #VU134116 - Improper Authorization CVE-2026-45490 |
CWE-285 | Low | 10.0.9 | 09.06.2026 |
SB2026060967 SB20260619133 SB20260619134 and 3 more |
||
| #VU131324 - Heap-based Buffer Overflow CVE-2026-32177 |
CWE-122 | Low | 4.8.9334.0 and 4.8.4802.0 | 13.05.2026 |
SB2026051358 SB2026051478 SB2026051479 and 7 more |
Showing elements 1 - 20 out of 107