CVE-2026-26127
High CVSS 7.5Published 2026-03-10 ยท last changed 2026-06-17
The fix
Microsoft fixes this in updatesKB5081276, KB5081278. The fixed build differs per Windows version, so the row that matters is the one matching the machine you are looking at.
| Windows version | Fixed in build | Update | Released |
|---|---|---|---|
| .NET 10.0 installed on Windows | 10.0.4 | KB5081276 | 2026-09-17 |
| .NET 9.0 installed on Windows | 9.0.14 | KB5081278 | 2026-09-17 |
Having the KB is not the same as knowing whether a machine has it. Windows updates supersede each other, so the update you installed often covers a fix that shipped in an earlier one. Paste your build into the patch checker and it walks that chain for you.
What it is
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
Sources
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H