CVE-2025-26646: Microsoft .net

High severity, CVSS 8.0. EPSS: 1.3% chance of exploitation in the next 30 days.

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

Affected products

  • Microsoft .net: from 9.0.0, before 9.0.5 (fixed in 9.0.5); from 8.0.0, before 8.0.16 (fixed in 8.0.16)
  • Microsoft Build Tools: before 17.13.7 (fixed in 17.13.7)
  • Microsoft Visual Studio 2022: from 17.8.0, before 17.8.21 (fixed in 17.8.21); from 17.10.0, before 17.10.15 (fixed in 17.10.15); from 17.12.0, before 17.12.8 (fixed in 17.12.8); from 17.13.0, before 17.13.7 (fixed in 17.13.7)

Published 2025-05-13. Last modified 2026-06-17.