CVE-2026-32226: Microsoft .NET Framework

Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.

Affected products

  • Microsoft .NET Framework: version 3.5 only; version 4.7.2 only; version 4.8 only; version 4.8.1 only

Published 2026-04-14. Last modified 2026-07-25.