CVE-2026-26127: Microsoft .net

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.

Affected products

  • Microsoft .net: from 10.0.0, before 10.0.4 (fixed in 10.0.4); from 9.0.0, before 9.0.14 (fixed in 9.0.14)
  • Microsoft Bcl.memory: from 9.0.0, before 9.0.14 (fixed in 9.0.14); from 10.0.0, before 10.0.4 (fixed in 10.0.4)

Published 2026-03-10. Last modified 2026-06-17.