Origin validation error in Microsoft products - CVE-2026-58649
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an origin validation error in .NET when validating origins. A remote attacker can exploit the vulnerability to disclose sensitive information.
User interaction is required. Successful exploitation could expose developer-time hot reload data, including application metadata, intermediate language updates, debugging information, method names, string literals, and file paths.
Affected software
Visual Studio
.NET for macOS
.NET for Linux
Microsoft .NET Framework
How to mitigate CVE-2026-58649
Visual Studio - update to 17.14.40
.NET for macOS - addressed in versions 8.0.130, 8.0.424, 9.0.120, 9.0.317
.NET for Linux - addressed in versions 8.0.130, 8.0.424, 9.0.120, 9.0.317
Microsoft .NET Framework - update to 10.0.111, 10.0.400