CVE-2026-50653: Microsoft .NET Framework

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

Affected products

  • Microsoft .NET Framework: version 3.5 only; version 4.8.1 only; version 4.6.2 only; version 4.7 only; version 4.7.1 only; version 4.7.2 only; …
  • Microsoft Azure Active Directory: affected versions not specified

Published 2026-07-14. Last modified 2026-07-24.