logo

Microsoft .NET 0-Day Vulnerability Enables Denial-of-Service Attacks

ID: f960ae33-8046-5bc7-975f-4b13a125d43a

STIX ID: report--f960ae33-8046-5bc7-975f-4b13a125d43a

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2026-03-11

Date Updated: 2026-04-21

Author: Abinaya

...
...

A newly disclosed .NET out-of-bounds read vulnerability (CVE-2026-26127, CVSS 7.5) allows unauthenticated remote attackers to trigger a denial-of-service against .NET 9.0/10.0 and Microsoft.Bcl.Memory on Windows, macOS, and Linux; Microsoft has released patches (9.0.14 and 10.0.4) and urges immediate updates, and while no active exploitation is reported the public disclosure raises future risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.