CVE-2026-23666: Microsoft .NET Framework

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.

Affected products

  • Microsoft .NET Framework: version 3.5 only; version 4.7.2 only; version 4.8 only; version 4.8.1 only; version 4.6.2 only; version 4.7 only; …

Published 2026-04-14. Last modified 2026-07-15.