news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans Microsoft .Net (09 septembre 2026)

HighCVSS 8.8
Summary

Multiple vulnerabilities have been discovered in Microsoft .NET, including remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect various versions of .NET Framework and .NET Core, requiring immediate patching to mitigate potential risks. The CERT-FR report details specific CVEs associated with these issues, urging users to consult Microsoft's security bulletins for available updates.

Multiple vulnerabilities have been discovered in Microsoft .NET, impacting a wide range of products and versions. These vulnerabilities can lead to remote code execution, privilege escalation, and denial-of-service attacks. The CERT-FR report highlights several CVEs associated with these issues, including CVE-2026-58649, CVE-2026-69304, CVE-2026-69439, CVE-2026-69522, CVE-2026-69806, and CVE-2026-71328. Specifically, the vulnerabilities affect .NET Framework 3.5, 4.6.2/4.7/4.7.1/4.7.2, 4.8, and 4.8.1, as well as .NET Core 8.0, 9.0, and 10.0. Affected products include ASP.NET Core 8.0, 9.0, and 10.0. Users are strongly advised to refer to Microsoft's security bulletins for detailed information and available patches. The bulletin for CVE-2026-58649 can be found at: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58649, and other CVEs are linked in the original report.

Read the full article at CERT-FR