Microsoft .NET patches six new CVEs
ANSSI advisory details six .NET and ASP.NET Core vulnerabilities enabling RCE, privilege escalation, DoS, and data leaks; patch to fixed versions.
ANSSI (CERT-FR) issued an advisory covering six vulnerabilities in Microsoft .NET affecting .NET Framework 3.5/4.6.2-4.8.1, .NET 8.0/9.0/10.0/11.0 (RC1), and ASP.NET Core across Windows, Linux, and macOS. The flaws collectively allow remote code execution, privilege escalation, remote denial of service, and confidentiality breaches, though the advisory does not specify which CVE maps to which impact individually. No exploitation in the wild is mentioned; this is a routine vendor patch bulletin.
Affected versions span a wide range of .NET releases across all three major operating systems, indicating broad exposure for any organization running .NET-based applications or services. Microsoft published fixes on September 8, 2026, and ANSSI directs administrators to the official Microsoft Security Response Center bulletins for patch details. No proof-of-concept exploit code, IOCs, or threat actor attribution are included in this advisory; it is a standard vulnerability disclosure requiring timely patch management.
Defenders should prioritize applying the vendor-supplied updates to bring installations to the fixed versions listed (e.g., .NET 8.0.130/8.0.424, 9.0.120/9.0.317, 10.0.111/10.0.400, ASP.NET Core 8.0.31/9.0.20/10.0.12, and corresponding .NET Framework updates). Given the range of impacts including RCE and privilege escalation, patching should be treated as a priority for internet-facing or otherwise exposed .NET/ASP.NET Core services.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1146
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free