← Back to CVE List
Vulnerability Intelligence Report
.NET Security Feature Bypass Vulnerability

CVE-2026-50528

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

No Active Exploit Signals
CVSS Base Score
8.2
HIGH
Exploitability:3.9
Impact Score:4.3
EPSS Probability:0.56%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-863 ↗CWE-863: Incorrect Authorization
CWE-302 ↗CWE-302: Authentication Bypass by Assumed-Immutable Data
CWE-636 ↗CWE-636: Not Failing Securely ('Failing Open')

Affected Products & Versions

Vendor Product Affected Versions
Microsoft .NET 10.0 10.0.0 < 10.0.10 (affected)
Microsoft .NET 8.0 8.0.0 < 8.0.29 (affected)
Microsoft .NET 9.0 9.0.0 < 9.0.18 (affected)
Microsoft Microsoft Visual Studio 2022 version 17.12 17.12.0 < 17.12.22 (affected)
Microsoft Microsoft Visual Studio 2022 version 17.14 17.14.0 < 17.14.36 (affected)
Microsoft Microsoft Visual Studio 2026 version 18.7 18.0 < 18.7.4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.563%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2026-06-04T19:00:41
Published2026-07-14T19:29:56
Patch Date2026-07-14
Last Updated2026-09-17T22:32:02

LINK COPIED TO CLIPBOARD