VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR Warns of Multiple Microsoft .NET Flaws

routine vulnerability technology

CERT-FR advisory lists 12 .NET vulnerabilities across .NET Framework and .NET 8/9/10 that enable remote code execution, privilege escalation, and denial of service.

CERT-FR published an advisory detailing multiple vulnerabilities affecting Microsoft .NET, spanning both the legacy .NET Framework (3.5, 4.6.2 through 4.8.1) and the modern cross-platform .NET runtime (versions 8.0, 9.0, and 10.0) across Windows, Linux, and macOS. The flaws collectively enable a range of impacts including remote code execution, privilege escalation, remote denial of service, security bypass, and confidentiality breaches, though the advisory does not indicate any of the twelve associated CVEs are currently being exploited in the wild.

The breadth of affected products—covering nearly every actively supported .NET version and platform—means the practical exposure is significant across enterprise environments running .NET-based applications, web services, and desktop software. Microsoft released patches for all listed CVEs on August 11, 2026, and CERT-FR's guidance is to apply the vendor updates referenced in the official Microsoft Security Response Center bulletins for each CVE.

As a routine vendor patch advisory without confirmed active exploitation, this represents standard patch-management hygiene rather than an urgent incident, though organizations running .NET should prioritize testing and deploying the fixes given the RCE and privilege-escalation impacts among the flaws.

Mentioned in this report

Vulnerabilities CVE-2026-58641CVE-2026-62871CVE-2026-62872CVE-2026-62886CVE-2026-62897CVE-2026-62898CVE-2026-62899CVE-2026-62900CVE-2026-62901CVE-2026-62902CVE-2026-62909CVE-2026-65810CVE-2026-70354

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1002

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free