Microsoft .NET patches 17 vulnerabilities
CERT-FR warns of multiple .NET and .NET Framework flaws allowing remote code execution, privilege escalation, and denial of service.
CERT-FR has issued an advisory covering seventeen vulnerabilities affecting Microsoft .NET and .NET Framework across multiple versions, including .NET 8.0, 9.0, and 10.0 on Linux and macOS, as well as .NET Framework 3.5 through 4.8.1 on Windows. The flaws collectively span several impact categories: remote code execution, privilege escalation, remote denial of service, data integrity compromise, and security policy bypass.
No exploitation in the wild is mentioned in the advisory, and no specific CVE is singled out as more severe than the others. Microsoft published corresponding security bulletins for each CVE on 14 July 2026. Organizations running affected .NET runtimes or .NET Framework installations should apply the vendor-provided patches referenced in the bulletin as a matter of routine patch management.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0870
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free