CVE-2026-26127: Microsoft .net
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
Affected products
- Microsoft .net: from 10.0.0, before 10.0.4 (fixed in 10.0.4); from 9.0.0, before 9.0.14 (fixed in 9.0.14)
- Microsoft Bcl.memory: from 9.0.0, before 9.0.14 (fixed in 9.0.14); from 10.0.0, before 10.0.4 (fixed in 10.0.4)
Published 2026-03-10. Last modified 2026-06-17.