Microsoft .NET 0-Day Vulnerability Enables Denial-of-Service Attacks
ID: f960ae33-8046-5bc7-975f-4b13a125d43a
STIX ID: report--f960ae33-8046-5bc7-975f-4b13a125d43a
Feed Name: cybersecurityNews.com
Threat Score
A newly disclosed .NET out-of-bounds read vulnerability (CVE-2026-26127, CVSS 7.5) allows unauthenticated remote attackers to trigger a denial-of-service against .NET 9.0/10.0 and Microsoft.Bcl.Memory on Windows, macOS, and Linux; Microsoft has released patches (9.0.14 and 10.0.4) and urges immediate updates, and while no active exploitation is reported the public disclosure raises future risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
