CVE-2026-32175: Microsoft .net

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET Core properly handles files.

Affected products

  • Microsoft .net: from 8.0.0, before 8.0.27 (fixed in 8.0.27); from 9.0.0, before 9.0.16 (fixed in 9.0.16)
  • Microsoft Visual Studio 2022: from 17.12.0, before 17.12.20 (fixed in 17.12.20); from 17.14.0, before 17.14.32 (fixed in 17.14.32)
  • Microsoft Visual Studio 2026: from 18.5.0, before 18.5.3 (fixed in 18.5.3)

Published 2026-05-12. Last modified 2026-06-18.