# Microsoft .NET patches 17 vulnerabilities

Published: 2026-07-15 · Severity: medium
Canonical: https://vorant.io/reports/ced12905-fa1c-5e21-ade3-4b843b8c7970/microsoft-net-patches-17-vulnerabilities

> CERT-FR warns of multiple .NET and .NET Framework flaws allowing remote code execution, privilege escalation, and denial of service.

CERT-FR has issued an advisory covering seventeen vulnerabilities affecting Microsoft .NET and .NET Framework across multiple versions, including .NET 8.0, 9.0, and 10.0 on Linux and macOS, as well as .NET Framework 3.5 through 4.8.1 on Windows. The flaws collectively span several impact categories: remote code execution, privilege escalation, remote denial of service, data integrity compromise, and security policy bypass.

No exploitation in the wild is mentioned in the advisory, and no specific CVE is singled out as more severe than the others. Microsoft published corresponding security bulletins for each CVE on 14 July 2026. Organizations running affected .NET runtimes or .NET Framework installations should apply the vendor-provided patches referenced in the bulletin as a matter of routine patch management.

## Mentioned in this report

- Vulnerabilities: CVE-2026-47300, CVE-2026-47302, CVE-2026-47303, CVE-2026-50524, CVE-2026-50525, CVE-2026-50526, CVE-2026-50527, CVE-2026-50528, CVE-2026-50646, CVE-2026-50648, CVE-2026-50650, CVE-2026-50651, CVE-2026-50659, CVE-2026-56170, CVE-2026-57108

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0870

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ced12905-fa1c-5e21-ade3-4b843b8c7970/microsoft-net-patches-17-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
