CVE-2026-26127HighCVSS 7.5
.NET Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
🎯 Affected products8
- .NET 10.0 installed on Linux
- .NET 10.0 installed on Mac OS
- .NET 10.0 installed on Windows
- .NET 9.0 installed on Linux
- .NET 9.0 installed on Mac OS
- .NET 9.0 installed on Windows
- Microsoft.Bcl.Memory 10.0
- Microsoft.Bcl.Memory 9.0
✅ Remediation
Security Update — fixed build 10.0.4 KB5081276 (Security Update) — fixed build 10.0.4 KB5081278 (Security Update) — fixed build 9.0.14 Security Update — fixed build 9.0.14
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26127
- patchhttps://www.nuget.org/packages/Microsoft.Bcl.Memory#versions-body-tab
- patchhttps://dotnet.microsoft.com/download/dotnet/10.0
- referencehttps://support.microsoft.com/help/5081276
- patchhttps://dotnet.microsoft.com/en-us/download/dotnet/9.0
- referencehttps://support.microsoft.com/help/5081278